SPV Reddy

Venkat Reddy Sreepuram
ABOUT ME

Security Enthusiast, Speaker and Penetration Testing Engineer with 7 years of experience in handling Vulnerability Assessment and Penetration Testing on Web Applications, Mobile Applications, API's, Networks, Wireless Security and thick clients.Experience in PHP and Wordpress Development. Delivered talks in multiple Conferences, Workshops, Chapter meets and Webinars covering 5000+ members. Reported Critical Vulnerabilities in more than 25 Government websites leaking sensitive information of users and helped them to patch them. Experienced professional in handling SAST (Static Application Security Testing), DAST (Dynamic Application Security Testing), End to End Product Security Operations and Penetration Testing. Good Knowledge on Software Defined Radio (SDR) Exploitation, Radio Frequency Identification Devices(RFID) and FRID tags.





  • picture
  •  
  • picture
  •  
  • picture
  • picture
  • picture
MY PROFESSIONAL CERTIFICATIONS

offensive Security

   ●  Offensive Security Certified Professional (OSCP)

  • picture
  •  

Information Systems Audit and Control Association (ISACA)

   ●  Certified Information Security Manager (CISM)

  • picture
  •  

EC - COUNCIL

   ●  Certified Ethical Hacker(CEHv9)

  • picture

   ●  EC-Council Certified Security Analyst (ECSAv9)

  • picture

SYNACK

   ●  Synack Red Team Member (SRT)

  • picture
PROFESSIONAL SKILLS

Web Application Security

Android Application Security

iOS Application Security

Network Security

API & WebSockets Security

Wireless Security

Software Defined Radio Security

DevSecOps Implementation

Vulnerability Management

Corporate Security Trainings

PHP & WordPress Development

Public Speaking

WORK EXPERIENCE AND JOB RESPONSIBILITIES

CISCO SYSTEMS (March 2016 - Present)

  • Working as Product Security Engineer in CISCO Systems from March 2016 Handling Vulnerability Assessment and Penetration Testing for more than 60 unique applications.

  • Leading a Team of 2 Members and scheduling Security Assessments and responsible for Security Delivery.

  • Good knowledge on various Security standards,methodology and compliances like OWASP TOP10, SANS 25, PTES, OSSTM, PCI-DSS.

  • Experience in performing application security assessments and Penetration Testing on Web Applications, Mobile Applications, API’s and Web Sockets.

  • Interact with Internal Development teams and help them for bug fixing.

  • Had good experience on Vulnerability Assessment, Penetration Testing, SAST (Static Application Security Testing) and DAST (Dynamic Application Security Testing) tools.

  • Perform Vulnerability Assessment and Penetration Testing on Web Applications, WAP Portals, API’s, Mobile Applications periodically and help dev teams to fix the issues.

  • Provide Security Trainings to Internal Development Teams on secure coding to avoiding vulnerabilities.

  • Good knowledge on exploiting RFID and NFC devices.

  • Interact with third party Security Firms and revalidate the issues raised by them on products.

  • Knowledge on PHP Development and used to develop dashboards for tracking vulnerabilities raised in Manual and Automated Assessments.

  • Created a Checklist for WebApplication Pentest covering more than 100 Vulnerabilities and execute them while penetration testing along with OWASP TOP 10.

  • Designed a Security Score card and released it as Open Source,where any company can evaluate score of their product which generates rating automatically.

  • Developed a dashboard for tracking all the Vulnerabilities raised in the Vulnerability Assessment and Penetration Testing bug fixing and scheduling the periodical scans.

SECURITY TOOLS EXPERTISE AT

Commercial/Pro Vulnerability Scanners


Acunetix, Qualys Guard, BurpSuite Pro, 
IBM AppScan, Teenable Nessuss, Veracode

Open Source Vulnerability Scanners


OWASP ZAP, IronWASP, SSLLabs, MobSF, WPScan,
 Nikto, SQLMap, Open Vas, Vega SubGraph

Exploitation Tools


Metasploit Framework, Santoku OS, BurpSuite Pro,
 Xposed Framework, Xenotix,  Hackbar, Hydra

Information Gathering Tools


Nmap, Zenmap, Wapalyzer, Exploit DB, 
Sparta Tool, maltego

Enumerating Tools


Dirbuster, Recon-ng, Sublist3r

Reverse Engineering Tools


ApkTool, Dex2Jar, JD-GUI

PROJECTS I WORKED & VULNERABILITIES REPORTED IN BUG BOUNTY PROGRAMME

MY TALKS AND PRESENTATIONS

INDIAN CYBER CONFERENCE - Sep 29 2018 (Sri Vidhyanikethan - Tirupathi)

   ●  Mobile Spyware

   ●  Mobile Ransomware

NATIONAL CYBER SAFETY AND SECURITY STANDARDS - June 24 2018 (RRMCH - Banglore)

   ●  Panel Discussion Member

   ●  Real Time Cyber Attacks & Preventive Measures

NATIONAL CYBER DEFENSE RESEARCH CENTRE - June 23 2018 (RRMCH - Banglore)

   ●  Web Application Attacks

   ●  Mobile Ransomware

   ●  Secure SDLC in Product Based Companies

NATIONAL CYBER SAFETY AND SECURITY STANDARDS - Feb 25 2018 (Anna University - Chennai)

   ●  Mobile Applicaiton Security Tools & Methodologies

   ●  Exploiting API Security Flaws in Mobile Apps

Open Web Application Security Project(OWASP HYD CHAPTER) - Feb 03 2018 (CoMakeIT - Hyderabad)

   ●  Mobile Application Penetration Testing

   ●  Demo on Exploiting Mobile Applicaiton Flaws

NATIONAL INFORMATION SECURITY SUMMIT - Sep 25 2017 (Amity University - LUCKNOW)

   ●  Implementing Security Automation (DevSecOps)

   ●  Introduction:-Carrier in Cyber Security for noobs

HACKERS DAY INTERNATIONAL INFOSEC CONFERENCE(CHAPTER MEET) - April 13 2017 (Hyderabad)

   ●  Penetration Testing Methologies and Tools

   ●  Bypassing Web Application Firewall

TRAINININGS TO INTERNAL DEVELOPMENT TEAMS

WEBINARS & Streaming

MY JOURNEY
2011 (Intermediate 1st year) Research on Hardware and Networking

2012 (Intermediate 2nd Year) Started C,C++,HTML & PHP Development

2013 (B.Tech 1st Year) Started Cyber Sec & Developed Malware
2014 (B.Tech 2nd Year) Started Delivering Cyber Security Trainings
2015 (B.Tech 3rd Year) Research on MATLAB and CBIR Systems

2016 (B.Tech 4th Year) Joined IMIMobile(CISCO) as Product Security Engineer

2017 Develop Mobile App and Security Testing
2018 Azure,AWS and DevSecOps Implementation

2019 Deep knowledge on Cyber Security Domains
Docker and Kubernetes and Blueprism
2020 Software Defined Radio Hacking, Drones, Bluetooth Hacking, RFID and NFC Security Arduino Programming other topics.
2021

Knowledge on Risk Management,
Secure program Development.
Cleared my CISM Certification.

2022

Moved out from CISCO Systems

Connect Me

Venkat Reddy Sreepuram

Telegram

+123456-40313

WhatsApp

+123456-40313

Email

Email: innnnj@mail.com & spvredd@ncdrc.res.in



Connect me on Social Network