Security Analyst Gunnison Consulting Group
Conduct manual security vulnerability assessments for Administrative Office of US Courts (AO)
• Scheduled Security Assessment Test Plans to be completed on assigned host/appliance within different branch
of AO to be completed within scheduled time frame
• Prepare vulnerability reports for AO with suggestions for remediation and explanation of findings
• Performed analysis involving OWASP Top 10 Vulnerability Assessment of various internet-facing web
applications and Web services
• Executed daily vulnerability assessments, threat assessment, mitigation, and reporting activities
• Actively searched for potential security issues and security gaps that are beyond the ability of detection by any
security scanner tool
• Conducted penetration tests on systems and applications using automated and manual techniques with tools
such as Core Impact, Metasploit, Burpsuite, Kali Linux, Acunetix, Nmap, and many other open-source tools as
needed
• Manually inspect HTTP requests/headers/responses using Burp Suite as Proxy
• Identify weaknesses in controls that can be used in attack/exploit by manually conducting security assessment
checks