Ashish Yadav
Ashish Yadav
Summary:
Proactive Security Analyst at Cybrotech Digiventure Pvt. Ltd., bringing over a year of
experience in cybersecurity. Skilled in vulnerability assessment, penetration testing, mobile
and cloud security. Demonstrated ability in firewall setup and defining security rules.
Experienced in implementing ISO 27001:2022 policies to ensure robust security measures
and data protection.
Skills:
Penetration Testing [Burpsuite, Nessus, Acunetix, nuclei, nmap, Metasploit, Mobsf,
Frida, jadx, Apktool, checkra1n, Owaspzap, Genymotion & etc.]
Network protocols
Reporting and documentation
Network Security
Mobile application Security
EDR (Threat-spike)
Log analysis
Incident Response
Team collaboration
Infrastructure Security
ISO27001:2022
Experience:
Cybrotech Digiventure Pvt. Ltd. | Delhi
Security Analyst:
Duration: 10-May-2023 to Present
Led vulnerability scans, penetration tests, and conducted both automation and manual
testing using automated tools, generating comprehensive reports on findings.
Conducted regular tests on web and mobile applications, as well as network
infrastructure, to pinpoint security weaknesses.
Executed cloud testing procedures to evaluate the security of cloud-based systems and
applications.
Conducted digital forensic analysis on various digital assets such as videos and emails,
aiding in incident response and investigations.
Collaborated with diverse teams to communicate security risks effectively and
implement robust solutions.
Implemented ISO 27001:2022 policies, ensuring organizational compliance and
elevating security standards.
Projects:
Firewall Installation Project:
Successfully designed and implemented firewall solutions to enhance network
security and protect sensitive data.
EdTech Project:
Contributed to the security architecture and risk assessment of an educational
technology platform, ensuring the confidentiality and integrity of student data.
E-commerce Project:
Implemented security measures to safeguard customer information and prevent
unauthorized access in an e-commerce application.
Banking Projects:
Provided security consultation and conducted risk assessments for banking systems to
mitigate potential threats and vulnerabilities.
Digital Forensics Project:
Conducted forensic analysis of videos, emails, and logs to support incident response
efforts and forensic investigations.
Logs Analysis Project:
Analyzed system logs to detect and investigate security incidents, enabling proactive
threat detection and response.
ISO 27001:2022 Implementation Project:
Led the implementation of ISO 27001:2022 policies and procedures, ensuring
alignment with international standards and enhancing the organization's security
posture.
Education:
CERTIFICATIONS:
CEH (EC-COUNCIL)
CHFI (EC-COUNCIL)
Website Hacking Techniques (Code Red)
SQL Injection Attacks (Code Red)
Network Security Associate
Android Bug Bounty Hunting: Hunt Like a Rat (Code Red)