Shanmukh Reddy
Senior Consultant, Technology Risk Consulting @KPMG Canada
Signup · Get unlimited contacts
WORK HISTORY
Senior Consultant, Technology Risk Consulting @KPMG Canada
Vancouver, BC, CA
EDUCATION
New York Institute of Technology - Vancouver
M.S, Cybersecurity
Indian Institute of Information Technology, SriCity
Bachelor of Technology - BTech, Electronics and Communications Engineering
Amity University Online
Post Graduate Diploma in Public Accounting
ABOUT SHANMUKH REDDY
A Cyber Security Professional with core security experience in IT Risk Management, SOC-2 Type-II & ISO 27001:2013 Audits, Compliance management and other Information Security domains. Areas of expertise : Web Application and Mobile Security 1. Experienced in Web Application and Mobile device vulnerability analysis, Web and Mobile application assessment and identifying potential risk areas. Performing security research into top threats for platform and technology. Analyze and assess the security of the device architecture and applications as well as monitor platform and OS (e.g. Android). Vulnerability Assessment and Penetration Testing 1. Automated and manual Penetration Testing of Infrastructure and Applications. Proficient in different security frameworks and standards (such as OWASP concepts and testing methodologies) 3. Experienced in Network Vulnerability Assessment tools Nessus, Qualysguard, Foundstone (automated) scanners. Platform Hardening and VA on demand using deep stick assessment methods. Technologies & Tools Network PT - NMAP, Nessus, Metasploit, Nikto, Metasploit, KaliLinux etc. Web Security Testing - BurpSuite Pro, OWASP ZAP proxy, Acunetix, Netsparker. Mobile Security Testing - MOBSF, Multiple IOS/Andriod testing tools Information Security Risk Governance and Implementation 1. Created Information Security Policy Manual aligned to ISO 27001:2013. Created and implemented Risk Assessment Methodology for entire ISMS Program. Created Risk Treatment Plan and methods for the various risks identified in the Risk Assessment. Designing the various IS related Policies and procedures. Designing and preparing the Statement of Applicability. Participated in designing the Security Architecture and formulating the Risk Mitigation Strategy. Designing and conducting Information Security Awareness programs. Security review of IT Infrastructure and IS operations in accordance with ISO 27001, at Operational office and Data center. Assessment of IS controls for RFP compliance. Review of Business Continuity Management Plan for the entire program. Assessment of the physical and environmental controls at operational office, data center and communication rooms. Review of the Security Incidents. Preparation of the Audit findings report and mitigation plans. Review of the Disaster Recovery Plan.
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.