Vicky Fernandes
Product Security Engineer @Allstate Northern Ireland
Signup · Get unlimited contacts
WORK HISTORY
Product Security Engineer @Allstate Northern Ireland
Belfast, GB
Collaborate closely with application development and platform teams to implement software security measures tailored to the specific risks the organisation faces.• Conduct Threat Modelling and provide advisory services on application security.• Provide comprehensive training to developers on secure application development practices and offer guidance on developing web-based training for continuous awareness.• Safeguard Information Security by scanning Sensitive data using tools such as OWASAP SEDATED, and software composition reviews using tools such as WhiteSource (Mend.io).• Perform SAST code reviews using Fortify and DAST reviews using Contrast to ensure adherence to secure coding practices and industry standards in software development.• Possess in-depth knowledge of the OWASP Top 10 to understand the mitigation of common web application security risks.• Perform secure application development activities using programming languages such as ReactJS, Java and Python.• Initiate and operate independently as a self-starter, while effectively collaborating with team members and stakeholders.• Possess preferred familiarity with DevSecOps, CI/CD and tools such as Metasploit, Burp Suite, Docker, Jenkins, or similar applications, and proficiently utilize these tools for conducting security testing and vulnerability assessments.
EDUCATION
Fatima High School
Secondary School Certificate (S.S.C), High School/Secondary Certificate Programs
Don Bosco Institute of Technology (D.B.I.T)
Bachelor of Engineering (B.E.), Information Technology
Fatima Junior College
Higher Secondary Certificate (H.S.C), Science
Cardiff University / Prifysgol Caerdydd
Master of Science - MS, Cyber Security
SKILLS
ABOUT VICKY FERNANDES
A Cybersecurity professional having more than 9 years of work experience in IT infrastructure and Cybersecurity.Good knowledge about DevSecOps, CI/CD Pipeline, Cloud, Vulnerability Assessment, Penetration Testing, Network Security, Configuration audits, Web and Mobile application security assessments, PCI ASV scans using security testing tools such as Kali Linux tools, Metasploit, Nessus Professional, Qualys and Netsparker. Also have a sound understanding of security standards and compliance frameworks such as OWASP Top 10, SANS, PCI-DSS, NIST, ISO 27001 and GDPR.Having renowned certifications such as Red Hat Certified System Administrator (RHCSA) and EC-Council certifications such as Certified Ethical Hacker (CEH), Computer Hacking Forensic Investigator (CHFI) and EC-Council Security Analyst (ECSA).Core subjects studied in MSc in Cybersecurity include Vulnerability Assessment, Penetration Testing, Malware Analysis, Risk Management, Business Continuity Management, Cyber Forensics, and Cybersecurity Operations
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.