Andrew Jones

Andrew Jones

Lead Security Engineer @H&R Block

Kansas City, MO, US
EMAILS
a••••••••@hrblock.com
MOBILE NUMBERS
+91 *********19

Signup · Get unlimited contacts

WORK HISTORY

Jan 2024 — Present

Lead Security Engineer @H&R Block

View department →

Kansas City, MO, US

EDUCATION

2008 — 2011

Nettur Technical Training Foundation

Diploma, Computer Science

2007 — 2008

Seventh Day Adventist Higher Secondary School

ICSE

2011 — 2015

Karnataka State Open University

Bachelor of Technology (BTech), Computer Engineering

ABOUT ANDREW JONES

Experienced in Application Security and Application Development.Built an Application Security team from ground up and lead the team to deliver SAST, DAST, SCA, API Security testing, Internal and External Penetration Testing, Configuration Reviews, Security Champion Program and Bug Bounty Program.Established processes for the Application Security functions. Lead the transformation of adapting towards DevSecOps by injecting security into every phases of DevOps like secrets management, Static code scans, dependency checker and CI/CD pipeline security scans.Expert in delivering the vulnerability readout calls to provide walkthroughs over the identified security issues and help development team with necessary fixes based on the technology stack.Familiar with all the stages of SDLC with good exposure to Agile environment. Excellent communication and presentation skills.Proficient in understanding application level vulnerabilities like XSS, SQL Injection, CSRF, SSRF, OWASP Top 10 & SANS Top 25, and also providing solutions for remediation of these vulnerabilities.Good understanding of security frameworks which includes BSIMM, OWASP ASVS, NIST, ISMS, ISO 27001.Hands on experience using vulnerability scanners like Nmap, Nessus, Burp Suite, OWASP Zap, Wireshark.Experience in Web Application Penetration testing using Burp Suite, API Security Testing with Postman.Carried out Static Vulnerability Assessment & Penetration testing for various internet/intranet facing web applications and provided mitigation to the identified vulnerabilities.Good understanding on implementation of DevOps model with AzureDevOps.Good hands on experience with Sonatype tool to scan and identify the vulnerabilities in third partydependencies. Experience in mentoring/grooming the team members.

This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.

Andrew Jones — Email, Phone Number & Contact Info | Unifers