Aiming towards secure digital world.
Aktualisiert am 13.10.2025
Profil
Freiberufler / Selbstständiger
Remote-Arbeit
Verfügbar ab: 20.10.2025
Verfügbar zu: 100%
davon vor Ort: 100%
GRC
Vulnerability Management
Penetrationstest
Qualys
SAST
DAST
English
C1
German
A2

Einsatzorte

Einsatzorte

Deutschland, Österreich
möglich

Projekte

Projekte

2 years 1 month
2023-08 - 2025-08

best practices for AI security standards

WORKING STUDENT INFORMATION SECURITY
WORKING STUDENT INFORMATION SECURITY

Achievements

  • Found High Vulnerability on the Porsche Shop web application (Bug Hunting)
  • Found High Vulnerability on Heidelberg University's web application (Broken Object Level Authorisation)


Responsibilities

  • Worked on best practices for AI security standards, referencing OWASP Top 10 LLM and ISO 42001 AI Management System.
  • Strengthened the application security posture by creating security profiles, integrating Threat Modelling (STRIDE), Application Security requirement assessments, Compliance, Cloud assessments, and Vulnerability/Risk Management processes.
  • Adapted ISO 27001: 2022 frameworks to specific business needs for the leasing department, enhancing governance and compliance while supporting operational efficiency.
  • Successfully implemented necessary compliance measures, focusing on aligning operations with the Digital Operational Resilience Act (DORA).
  • Optimized Governance, Risk, and Compliance for web applications, ensuring adherence to standards and best practices.
  • Streamlined vulnerability management processes using Qualys VMDR, collaborating with application teams to reduce the identified vulnerabilities.

MERCEDES-BENZ AG HQ ? STUTTGART, GERMANY
2 years 5 months
2020-09 - 2023-01

Vulnerability Assessment and Mitigation through PCI Compliance

INFORMATION SECURITY CONSULTANT
INFORMATION SECURITY CONSULTANT

Achievements

  • Saved 15000$ for the client by finding a Critical Vulnerability RCE on the client's live estate.
  • Saved 10000$ reporting a High Vulnerability, i.e. Improper session management on client payment sites.
  • Pat on the back, Reward for 2021 ? Coforge
  • Collaborator Reward For 2022 ? Coforge


Responsibilities

  • Lead Vulnerability Assessment and Mitigation through PCI Compliance, Tier-1, and Tier-4 internal and external applications, and network annual pen tests, reducing risks by 67%.
  • Performed Release scans associated with the Secure SDLC ecosystem.
  • Managed end-to-end vulnerability assessment lifecycle, utilising Qualys WAS and Network Scans to inform Asset Tagging, Asset Management, and Risk Management strategies, resulting in a 13% decrease in overall vulnerabilities.
  • Assessed web applications and APIs for vulnerabilities using open-source and professional tools (OWASP Zap, Metasploit, BURP Suite and Nmap) and prepared technical reports of the findings. Successfully reported numerous Critical and High vulnerabilities around the web application.
  • Conducted SFTP and FTP Penetration testing.
  • Completed Static Application Testing (SAST) using Veracode for various applications.
  • Conducted configuration review for Windows OS and Linux OS to meet Business Hardening standards (CIS Benchmark).
  • Contributed innovative ideas to the team in conducting security operations, leveraging SPLUNK for Threat Analysis, Real-Time Incident Monitoring, and streamlined Incident Response.
  • Mitigated vulnerabilities identified via Endpoint Detection and Response (EDR) platforms, leveraging Microsoft Defender and Crowdstrike Falcon to enhance endpoint security posture, reducing vulnerabilities by 6%.
  • Developed and implemented a ServiceNow (SNOW) workflow that streamlined Security Operations, resolving over 600 tickets and significantly improving SLA adherence and operational efficiency.


Initiatives

  • Introduced Brand Protection, reducing more than 75% of unused open ports.
  • Collaborated with client (DNATA) to create a Security Governance model for both the security team and application/infra team to agree on workflow and SLAs, including work structure, reporting format, processes, documentation (SOPs), etc.
  • Developed processes to introduce and implement new tools (POCs for Qualys scanning) and techniques to perform ongoing security assessments of the environment.
  • Developed an auto-report generator using Power Automator for the team.

COFORGE TECHNOLOGIES (IAG - BRITISH AIRWAYS IBERIA AIRLINES, EMIRATES - DNATA) ? GREATER NOIDA, INDIA

Aus- und Weiterbildung

Aus- und Weiterbildung

2 years 5 months
2023-04 - 2025-08

MASTERS IN DATA AND COMPUTER SCIENCE

Heidelberg University
Heidelberg University
  • Automatic Feedback Classification using LLAMA (Thesis)
  • Advanced Cryptography
  • Advanced IT Security
  • Polyps Detection in Colonoscopy using SwinE-Net
  • Developed an LLM on medical records
  • Entrepreneurial Skills
  • Soft Skills Business English
1 month
2024-08 - 2024-08

ISO 42001:2023 AI Management System

Intertek
Intertek
1 month
2023-01 - 2023-01

CQI-IRCA Certified ISO 27001:2022 Lead Auditor ISMS

Intertek
Intertek
1 month
2022-10 - 2022-10

Certified Ethical Hacker (CEH)

EC-Council
EC-Council
1 month
2022-09 - 2022-09

AZ-500, Azure Security Engineer Associate

Microsoft
Microsoft
1 year 4 months
2021-06 - 2022-09

POST GRADUATE DIPLOMA IN OPERATION MANAGEMENT

Indira Gandhi National Open University
Indira Gandhi National Open University
1 month
2022-07 - 2022-07

API Security Architect

API Academy
API Academy
1 month
2021-05 - 2021-05

Qualys Security Specialist

Qualys
Qualys
1 month
2021-02 - 2021-02

Principle of Secure Coding

Coursera
Coursera
3 years 11 months
2016-08 - 2020-06

BACHELORS IN TECHNOLOGY

Swami Keshwanand Institute of Technology, Management and Gramothan (RTU)
Swami Keshwanand Institute of Technology, Management and Gramothan (RTU)
1 year
2014-05 - 2015-04

SECONDARY EDUCATION

St. Francis Inter College
St. Francis Inter College

Kompetenzen

Kompetenzen

Top-Skills

GRC Vulnerability Management Penetrationstest Qualys SAST DAST

Produkte / Standards / Erfahrungen / Methoden

ABOUT MYSELF

I am an Information Security professional who recently completed my Master's in Data and Computer Science at Heidelberg University. I have experience in Governance, Risk Management, Compliance, Vulnerability Assessment, Penetration Testing, and Application Security, having identified critical vulnerabilities for clients such as British Airways. Certified in multiple security standards, I excel in aligning best security practices with industry regulations and developing innovative solutions to protect digital assets.


Technical Skills

Microsoft Office Kali Linux C++ Python NMAP Qualys Metasploit Configuration Review Nessus API Testing Burp Suite Splunk Falcon CrowdStrike Web Application Testing Network Testing MS Defender 


Frameworks

ISO 42001 International cyber frameworks (ISO 27xxx, NIST & PCI DSS standards) Zero Trust Architecture Risk Management NIST SP 800-53 GDPR CIS NIST 2.0 DORA OWASP 


Cloud Platform

Microsoft AZURE

Einsatzorte

Einsatzorte

Deutschland, Österreich
möglich

Projekte

Projekte

2 years 1 month
2023-08 - 2025-08

best practices for AI security standards

WORKING STUDENT INFORMATION SECURITY
WORKING STUDENT INFORMATION SECURITY

Achievements

  • Found High Vulnerability on the Porsche Shop web application (Bug Hunting)
  • Found High Vulnerability on Heidelberg University's web application (Broken Object Level Authorisation)


Responsibilities

  • Worked on best practices for AI security standards, referencing OWASP Top 10 LLM and ISO 42001 AI Management System.
  • Strengthened the application security posture by creating security profiles, integrating Threat Modelling (STRIDE), Application Security requirement assessments, Compliance, Cloud assessments, and Vulnerability/Risk Management processes.
  • Adapted ISO 27001: 2022 frameworks to specific business needs for the leasing department, enhancing governance and compliance while supporting operational efficiency.
  • Successfully implemented necessary compliance measures, focusing on aligning operations with the Digital Operational Resilience Act (DORA).
  • Optimized Governance, Risk, and Compliance for web applications, ensuring adherence to standards and best practices.
  • Streamlined vulnerability management processes using Qualys VMDR, collaborating with application teams to reduce the identified vulnerabilities.

MERCEDES-BENZ AG HQ ? STUTTGART, GERMANY
2 years 5 months
2020-09 - 2023-01

Vulnerability Assessment and Mitigation through PCI Compliance

INFORMATION SECURITY CONSULTANT
INFORMATION SECURITY CONSULTANT

Achievements

  • Saved 15000$ for the client by finding a Critical Vulnerability RCE on the client's live estate.
  • Saved 10000$ reporting a High Vulnerability, i.e. Improper session management on client payment sites.
  • Pat on the back, Reward for 2021 ? Coforge
  • Collaborator Reward For 2022 ? Coforge


Responsibilities

  • Lead Vulnerability Assessment and Mitigation through PCI Compliance, Tier-1, and Tier-4 internal and external applications, and network annual pen tests, reducing risks by 67%.
  • Performed Release scans associated with the Secure SDLC ecosystem.
  • Managed end-to-end vulnerability assessment lifecycle, utilising Qualys WAS and Network Scans to inform Asset Tagging, Asset Management, and Risk Management strategies, resulting in a 13% decrease in overall vulnerabilities.
  • Assessed web applications and APIs for vulnerabilities using open-source and professional tools (OWASP Zap, Metasploit, BURP Suite and Nmap) and prepared technical reports of the findings. Successfully reported numerous Critical and High vulnerabilities around the web application.
  • Conducted SFTP and FTP Penetration testing.
  • Completed Static Application Testing (SAST) using Veracode for various applications.
  • Conducted configuration review for Windows OS and Linux OS to meet Business Hardening standards (CIS Benchmark).
  • Contributed innovative ideas to the team in conducting security operations, leveraging SPLUNK for Threat Analysis, Real-Time Incident Monitoring, and streamlined Incident Response.
  • Mitigated vulnerabilities identified via Endpoint Detection and Response (EDR) platforms, leveraging Microsoft Defender and Crowdstrike Falcon to enhance endpoint security posture, reducing vulnerabilities by 6%.
  • Developed and implemented a ServiceNow (SNOW) workflow that streamlined Security Operations, resolving over 600 tickets and significantly improving SLA adherence and operational efficiency.


Initiatives

  • Introduced Brand Protection, reducing more than 75% of unused open ports.
  • Collaborated with client (DNATA) to create a Security Governance model for both the security team and application/infra team to agree on workflow and SLAs, including work structure, reporting format, processes, documentation (SOPs), etc.
  • Developed processes to introduce and implement new tools (POCs for Qualys scanning) and techniques to perform ongoing security assessments of the environment.
  • Developed an auto-report generator using Power Automator for the team.

COFORGE TECHNOLOGIES (IAG - BRITISH AIRWAYS IBERIA AIRLINES, EMIRATES - DNATA) ? GREATER NOIDA, INDIA

Aus- und Weiterbildung

Aus- und Weiterbildung

2 years 5 months
2023-04 - 2025-08

MASTERS IN DATA AND COMPUTER SCIENCE

Heidelberg University
Heidelberg University
  • Automatic Feedback Classification using LLAMA (Thesis)
  • Advanced Cryptography
  • Advanced IT Security
  • Polyps Detection in Colonoscopy using SwinE-Net
  • Developed an LLM on medical records
  • Entrepreneurial Skills
  • Soft Skills Business English
1 month
2024-08 - 2024-08

ISO 42001:2023 AI Management System

Intertek
Intertek
1 month
2023-01 - 2023-01

CQI-IRCA Certified ISO 27001:2022 Lead Auditor ISMS

Intertek
Intertek
1 month
2022-10 - 2022-10

Certified Ethical Hacker (CEH)

EC-Council
EC-Council
1 month
2022-09 - 2022-09

AZ-500, Azure Security Engineer Associate

Microsoft
Microsoft
1 year 4 months
2021-06 - 2022-09

POST GRADUATE DIPLOMA IN OPERATION MANAGEMENT

Indira Gandhi National Open University
Indira Gandhi National Open University
1 month
2022-07 - 2022-07

API Security Architect

API Academy
API Academy
1 month
2021-05 - 2021-05

Qualys Security Specialist

Qualys
Qualys
1 month
2021-02 - 2021-02

Principle of Secure Coding

Coursera
Coursera
3 years 11 months
2016-08 - 2020-06

BACHELORS IN TECHNOLOGY

Swami Keshwanand Institute of Technology, Management and Gramothan (RTU)
Swami Keshwanand Institute of Technology, Management and Gramothan (RTU)
1 year
2014-05 - 2015-04

SECONDARY EDUCATION

St. Francis Inter College
St. Francis Inter College

Kompetenzen

Kompetenzen

Top-Skills

GRC Vulnerability Management Penetrationstest Qualys SAST DAST

Produkte / Standards / Erfahrungen / Methoden

ABOUT MYSELF

I am an Information Security professional who recently completed my Master's in Data and Computer Science at Heidelberg University. I have experience in Governance, Risk Management, Compliance, Vulnerability Assessment, Penetration Testing, and Application Security, having identified critical vulnerabilities for clients such as British Airways. Certified in multiple security standards, I excel in aligning best security practices with industry regulations and developing innovative solutions to protect digital assets.


Technical Skills

Microsoft Office Kali Linux C++ Python NMAP Qualys Metasploit Configuration Review Nessus API Testing Burp Suite Splunk Falcon CrowdStrike Web Application Testing Network Testing MS Defender 


Frameworks

ISO 42001 International cyber frameworks (ISO 27xxx, NIST & PCI DSS standards) Zero Trust Architecture Risk Management NIST SP 800-53 GDPR CIS NIST 2.0 DORA OWASP 


Cloud Platform

Microsoft AZURE

Vertrauen Sie auf Randstad

Im Bereich Freelancing
Im Bereich Arbeitnehmerüberlassung / Personalvermittlung

Fragen?

Rufen Sie uns an +49 89 500316-300 oder schreiben Sie uns:

Das Freelancer-Portal

Direktester geht's nicht! Ganz einfach Freelancer finden und direkt Kontakt aufnehmen.