John Smith is using Brazen Careerist to share ideas. Join now to become a member and start networking with John Smith and other professionals just like you. Learn more.
Senior Computer Security Consultant /Senior Penetration Tester.
With over 6 years experience as a penetration tester, I now find more of my work to be consultancy based. Advising customers of security risks, and pointing them to solutions that may either benefit them or reduce their risk of a compromise from foes domestic and foreign.
Specialties:
Report writing, & consultancy. Security Testing: Web applications, Infrastructure (internal & external); Exploitation; Breakout testing: Kiosks, Citrix; Wireless reviews: 802.11a/b/g/x, Bluetooth; VoIP & telephony; Build Reviews: Linux, Windows, AIX, Apache, IIS, DB2, Websphere, Firewalls; Social engineering. Enterprise applications: Oracle, SAP, Sharepoint. Network Design; System Administration; IDS/IPS: Snort, tripwire, log management; Content filtering: squid, dansguardian.
Worked on many penetration assessments for big blue chip companies within the FTSE 250, financial institutions, marketing companies and local governments. My skills are not limited to the more popular infrastructure and web application tests, as a pioneer within the security industry I spend a lot of time researching "fringe" projects, providing support and valued input to many projects, little of which surface in the worlds media. I have a wide experience of many operating systems, architectural designs, databases, and programming languages.
In the past I performed a lot of reverse engineering work, locating network bugs in popular proprietary products.
Picked up an interest in wireless technologies, and have picked up a good background on 802.11a/b/g and Bluetooth, and RFID hacking. The technology might be new, but occasionally suffer from 20 year old bugs in other older technologies.