Foundations of Information Assurance, Network Security Practices, Security Risk Management & Assessment, Computer System Security, IT Governance Risk & Compliance, Wireless & Mobile Network Security
I
Institute of Engineering and Technology DAVV
August 2016 - May 2020
Work Experience
B
Bloomberg LP
Product Security Intern
New York City, NY, United States, 10075
May 2023 - August 2023
company
Bloomberg LP
title
Product Security Intern
overview
• Collaborated with developers for secure code reviews using SAST tools Fortify and Checkmarx to identify vulnerabilities in code such as XML eXternal Entity injection (XXE), SQL injection, cross-site scripting (XSS), path manipulation, etc.
• Performed grey box penetration testing using Burp Suite and identified vulnerabilities such as Improper Access Control, Identification and Authentication failure, Improper Session Handling, etc., and provided security recommendations.
• Built CI/CD Jenkins pipeline for security automation testing processes using cmake and proprietary tools.
• Implemented OAuth 2.0 authentication protocol for Single Sign On (SSO) to access different applications seamlessly.