08 Sep
|
Timespro
|
Mumbai
Compliance and Governance
Compliance Standards:
Ensure adherence to GDPR, HIPAA, PCI DSS, and other standards.
Maintain audit trails with AWS CloudTrail and Bitbucket Activity Logs.
Vulnerability Assessment, Penetration Testing (VAPT), and Hardening
Assessments: Perform regular vulnerability assessments on AWS resources using tools like AWS Inspector, Nessus, or Qualys.
Service Hardening: Apply AWS best practices to secure services like EC2, RDS, and S3.
Encryption: Implement encryption in transit and at rest using AWS KMS and SSL/TLS.
Infrastructure Security
Cloud Security:
Use AWS services (Security Hub, GuardDuty, CloudTrail) and GCP tools (Security Command Center, IAM) to harden cloud settings.
Automate infrastructure deployment with Terraform or AWS CloudFormation, ensuring security best practices.
Scan IaC using Checkov, Terrascan, or AWS Config Rules.
Application Security
SAST and DAST:
Perform SAST during development to identify vulnerabilities early.
Conduct DAST in staging or production using tools like Burp Suite, OWASP ZAP, or AppScan.
Android Security:
Test Android apps using tools like MobSF, QARK, or Drozer.
Ensure compliance with OWASP MSTG standards.
Ethical Hacking and Ransomware Testing
Ransomware Simulation: Simulate ransomware attacks to test recovery capabilities and data resiliency.
Ethical Hacking: Perform ethical hacking exercises to assess system vulnerabilities and identify potential breaches
Threat Analysis Threat Modeling:
Conduct regular threat analysis to evaluate potential risks to cloud infrastructure and applications.
Create and maintain threat models for applications, services, and infrastructure to identify attack vectors and mitigation strategies.
Use tools like Microsoft Threat Modeling Tool, OWASP Threat Dragon, or custom modeling techniques to identify and prioritize risks.
Code Scanning:
Use Bitbucket Code Insights for integrated security scan results in PRs.
Moni
📌 Devsecops Mumbai
🏢 Timespro
📍 Mumbai