Pallavi Kishor Dhamal
Information Security | MS in Cybersecurity
- Role
- Cyber Security Consultant at Combined Life Insurance
- Location
- Edison, NJ, US
- LinkedIn followers
- 500 followers
About Pallavi Kishor Dhamal
Accomplished IT professional with overall’ 7 years of hands-on experience in the insurance domain, specializing in managing diverse client needs and conducting dynamic and static information security assessments for web applications and APIs. Proven track record of implementing effective security measures that enhance organizational resilience. Demonstrated expertise in identifying, assessing, and managing risks associated with information security. Skillful in evaluating vulnerabilities and threats, leveraging advanced analytical skills to develop tailored risk mitigation strategies that protect sensitive information. Adept in performing thorough security investigations and root cause analyses to identify vulnerabilities within third-party vendors. Proficient in triaging and prioritizing vulnerability alerts from various sources, ensuring timely assessments using tools such as Qualys and Burp Suite Pro. Well-versed in employing security best practices and methodologies such as OWASP Top 10, DAST, and SAST to fortify web applications against potential threats. Familiar with regulatory compliance requirements, including GDPR, HIPAA, and PCI DSS, ensuring adherence to industry standards. Proven ability to collaborate with cross-functional teams, effectively communicating high-risk areas to both technical and non-technical stakeholders. Skilled in providing technical support and guidance to enhance understanding of security issues and their importance. Passionate about staying abreast of emerging cyber threats and evolving security technologies. Actively participates in knowledge-sharing initiatives and mentoring programs to foster a culture of learning and awareness within the organization. Strong focus on risk management, and data privacy, ensuring a solid expertise to complement practical skills. Carry out gap analysis, risk assessment, and risk mitigation plan creation. Experienced in working within Agile environments, demonstrating strong client engagement skills and effective project management to ensure seamless communication, timely delivery, and alignment with business goals. Proven ability to manage and prioritize multiple projects simultaneously, even under tight deadlines and changing priorities.
Experience
Cyber Security Consultant
Aug 2023 — Present · NJ, US
Execute hands-on penetration tests targeting web applications, with a specific focus on OWASP Top 10 vulnerabilities such as SQL injection, cross-site scripting (XSS), and broken authentication.Coordinate on-site vulnerability assessments to ensure full coverage of both web applications and APIs, identifying high-priority security risks that require immediate resolution.Conducted thorough security testing of APIs and services, ensuring robust data integrity and effective authorization controls to safeguard sensitive information.Utilize advanced features of Burp Suite Pro to map application vulnerabilities, simulate attack scenarios, and uncover hidden security flaws not detected by automated tools.Effectively communicated complex technical concepts to diverse audiences, including technology teams, leadership, and non-technical business users, fostering understanding and collaboration.Create comprehensive security reports that outline gaps, associated risks, severity levels, and recommendations for remediation, ensuring both developers and stakeholders understand the issues.Classify vulnerabilities using the Common Vulnerability Scoring System (CVSS) to prioritize mitigation efforts based on potential impact.Maintain compliance with regulatory frameworks like HIPAA, ISO 27001, and NIST CSF, ensuring the company meets industry standards for data privacy and security.Assess the security of APIs and web services using tools like Postman and SOAP UI, ensuring vulnerabilities are detected and mitigated before releases.Track remediation efforts using ticketing systems, ensuring timely resolution and verifying the effectiveness of applied fixes before closing the tickets.Promote a culture of security awareness within the organization by sharing insights, best practices, and lessons learned from testing and assessments.Lead security discussions during sprint meetings and provide guidance to developers and IT teams on integrating security into their workflows.
Education
Stevens Institute of Technology
Master of Science - MS
2022 — 2023
Vidyalankar Institute of Technology, Mumbai
Bachelor of Engineering - BE
2013 — 2016
Vivekanand Education Society's Polytechnic
Diploma of Education
2010 — 2013
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.