Penetration Tester

$ / mo

Category:

Protect and Defend

Specialty area:

Vulnerability Assessment and Management

Сountry:

Ukraine

City:

Kharkiv

Employment options:

Part-Time

Work & Experience:
Noncommercial university project / Back-end developer
Kharkiv National University of Radioelectronics
11/2022 - 01/2023, Kharkiv
Together with a classmate have created light version of mobile application for Taxi.
My task was to write a server for application.
~ Technologies: Node.js, Express.js, Mongoose, Web-Socket, Socket.io

TryHackMe
MHtryhackme
Rank - In the top 9%
Rooms Complete - 13
LvL - 5

Project Manager
CyberPeople
07/2023 - Present,
Part-time work. Team management and coordination. Visualization of company
processes.
~ Technologies: Microsoft Office, Trello, Draw.io, Thunderbird + Mail Merge

ICE-CTF
Kharkiv National University of Radioelectronics
07/15/2023
I took part in the CTF from the university as part of a team of 4 people.
Our team scored 140 points - 6th place, (first 4 positions 150 points each)
Knowledges:
K0001

Knowledge of computer networking concepts and protocols, and network security methodologies.

K0002

Knowledge of risk management processes (e.g., methods for assessing and mitigating risk).

K0004

Knowledge of cybersecurity and privacy principles.

K0005

Knowledge of cyber threats an`d vulnerabilities.

K0009

Knowledge of application vulnerabilities.

K0044

Knowledge of cybersecurity and privacy principles and organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).

K0061

Knowledge of how traffic flows across the network (e.g., Transmission Control Protocol [TCP] and Internet Protocol [IP], Open System Interconnection Model [OSI], Information Technology Infrastructure Library, current version [ITIL]).

K0068

Knowledge of programming language structures and logic.

K0139

Knowledge of interpreted and compiled computer languages.

K0162

Knowledge of cyber attackers (e.g., script kiddies, insider threat, non-nation state sponsored, and nation sponsored).

K0177

Knowledge of cyber attack stages (e.g., reconnaissance, scanning, enumeration, gaining access, escalation of privileges, maintaining access, network exploitation, covering tracks).

K0206

Knowledge of ethical hacking principles and techniques.

K0224

Knowledge of system administration concepts for operating systems such as but not limited to Unix/Linux, IOS, Android, and Windows operating systems.

K0301

Knowledge of packet-level analysis using appropriate tools (e.g., Wireshark, tcpdump).

K0332

Knowledge of network protocols such as TCP/IP, Dynamic Host Configuration, Domain Name System (DNS), and directory services.

K0342

Knowledge of penetration testing principles, tools, and techniques.

K0624

Knowledge of Application Security Risks (e.g. Open Web Application Security Project Top 10 list)

Skills:
S0051

Skill in the use of penetration testing tools and techniques.

S0081

Skill in using network analysis tools to identify vulnerabilities. (e.g., fuzzing, nmap, etc.).

S0137

Skill in conducting application vulnerability assessments.

Abilities:
Licenses & certifications: