0% found this document useful (0 votes)
102 views3 pages

Cybersecurity Expertise and Career Overview

Uploaded by

ahmedpashak303
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
102 views3 pages

Cybersecurity Expertise and Career Overview

Uploaded by

ahmedpashak303
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

DIVYA JAIN

+91-9972999930 jaidivya25991@[Link] [Link]/author/?a=9480 [Link]/in/divya-jain-104b870/

SANS (AECS) Trained | OSCP | CEH | CDAC | Senior Cybersecurity Engineer | Offensive Security | CISSP (Pursuing)

Dedicated Cybersecurity Professional with over 9.5 years of proven expertise, I am on the lookout for Cyber Security Architect role in
Hardware, Software IoT, and ICS environments. Currently preparing for the prestigious CISSP certification, further enriching my skill
set and commitment to excellence.

TECHNICAL SKILLS

 Application Security (Web & Mobile-IoT Android Apps, Web Services, APIs, Thick & Thin Clients, Embedded Application
Security): Burp suite Pro, Nikto, Fiddler, SoapUI, Postman, Mobsf, jd-gui, APKtool, Sysinternal Suites, PS Suite, dnspy, PE
Security, AFL++

 Cloud Penetration Testing (AWS), Docker & Container Security: AWS Inspector, PACU, ScoutSuite, cloudsplaining, AWS
Security Hub, Configuration Review for the docker configuration, Container services, Exploitations like Container jumps,
credential recovery etc.

 Network, Infrastructure, ICS/SCADA Penetration Testing: Plcscanner, Scapy, Wireshark, Nessus, Nmap, Metasploit
framework, Mimikatz, Wireshark, TCPDump, Snort, Iptables

 Active directory: Power View, Bloodhound and Sysinternal tools, Mimikatz, Pass-the-hash type of attacks.

 Firmware, Hardware Security, Reverse Engineering & Forensics: JTAG, SPI, UART: Fuzz Testing Binwalk, FMK, Immunity
Debugger, AccessData, WinHEX, Steganography, RAM analysis (DumpIT, Volatility), Regdecoder (Registry Analysis), FAT,
EMBA, Fiddler, JTAGulator, CAN-utils, CAN Protocol Fuzzer, Jlink etc. Code Fuzzing using AFL++.

 Wireless Penetration Testing: Air-crack, Air-mon, Gerix. Protocols: WPA, WEP.

 Product Security Representative: SAST/DAST, Threat Modelling for 2 products. Reviewing the threats

 OS Hardening and Compliance Testing: Center of Internet Security (CIS) Benchmarking, Nessus, or CIS-CAT pro assessor

 Coding, Scripting and Manual Code Reviews: C#, python, Bash, and PowerShell for Scripting, Checkmarx, SonarQube for
code reviews

 Operating Systems: Kali, SIFT, ControlThings, Windows, NetHunter.

TRAINING, CERTIFICATES & ACHIEVEMENTS


Certificates
 CISSP (Pursuing)
 Offensive Security Certified Professional (OSCP) from Offensive Security.
 Certified Ethical Hacker (CEH v9) from EC-Council
 Assessing and Exploiting Control Systems from SANS Institute
 Pro Hacker on Hack the Box
Trainings
 Cloud (AWS) Penetration Testing (nullcon)
 Penetration & Fuzz Testing of Embedded Devices
 Breaking and Pwning of Active Directory(nullcon)
 Wi-Fi Penetration Testing using airmon-ng, aircrack-ng suite and Gerix WEP/WPA
 Information Security and Cyber Forensics conducted by Cyber Cure Solutions, New Delhi (2012).

Internal
DIVYA JAIN
+91-9972999930 jaidivya25991@[Link] [Link]/author/?a=9480 [Link]/in/divya-jain-104b870/

 AWS Security, Docker & Container Security, DevSecOps Basics trainings from PentesterAcademy
 Certified Automotive Cyber Security Professional (CACSP).
Awards
 Got Swag/Rewards from Dutch Government, individual bounty programs and listed in Hall of Fames.
 1st Winner for CTF held across GE modalities. Received an award for “Process Execution” amidst Covid from GE
 3rd CTF Winner (sole team member) for embedded security on ESP32 kit in Continental Automotive, Received the
Spot award for the same.
 Got spotlight award for responsible disclosure within Cytiva (GE Lifesciences).
Exploit-db/ CVEs
 CVEs published for Public CMSs ([Link]
 CVE-2018-11445, CVE-2018-11442, CVE-2018-11535. CVE-2018-11444, CVE-2018-11443, CVE-2018-11242

PROFESSIONAL EXPERIENCE
Continental Automotive India
Senior Cyber Security Engineer (Product Owner, STC) [June 2023 – Present]

 1st in-house Hardware (JTAG/SPI/UART) Testing, Firmware Security & Fuzz Testing (CAN, LIN, CAN-DB). Code
Fuzzing, Embedded Application Security.
 Product owner, and Location Team lead for Security Test Centre. Have been involved in setting up a Security Test
Centre (STC), Bengaluru, starting from Processes, tooling, test Bench setups to Automations for ethernet security
(99% of time reduction).
 Have been guiding and leading projects with a team of 4. Handling GW, TCUs, Different type of hardware and IoT
based products.

Cytiva Opco Danaher India (Formerly GE Healthcare Biopharma)


Product Cyber Security Engineer II [Aug 2019 – May 2023]

 Security Testing for 60+ Lifesciences products/instruments.


 Leading Projects & Built the team and Cyber security pillar from scratch with development of Security Assessment
Procedure Documents, Baseline Questionnaire for OS Hardening, Automated the process for OS hardening using
PowerShell, developed test cases, Developer's Awareness training, developed a first VAPT Reporting template.
 Security Assessments and Configuration Reviews for Web, Cloud, API, Thick Client, Dockers/Containers, Network
Components, AD Infra, PLC, Microcontrollers, SCADA (Platforms like Ignition) i.e., PLCs, industrial switches and
routers, industrial protocols (Ethernet/IP, OPC, Modbus, ProfiNet etc.,), Wireless, USB enabled, Driver Security and
Physical Security. Attacks including protocol reversing, Packet replay attack, Memory forensics, DLL
injection/hijacking, reverse engineering, tamper protection, and integrity checks. Memory forensics, Firmware
extractions (filesystem Extractions for squashfs, initramfs
 PSR Activities: Threat modelling review, SAST/DAST, Code Review, Code Signing (Certificate Handling), Compliance
and composition analysis with Product teams.
 Have done a responsible disclosure for Cytiva’ s web portal.
Ernst & Young LLP
Security Consultant [Aug 2017 – Aug 2019]

 Security Testing for Network/ infrastructure, Virtual Desktop Infrastructure assets, DLP components, Desktop
(thick/thin) &Mobile applications, REST/SOAP API, Cloud Security and web applications 21 financial
institutions/microfinance clients Stock Exchange.
 DDoS Simulations (UDP/ICMP Flood, SYN Flood, HTTP Get Flood, TCP Connection Attack, TCP Flag-based
Attacks), Phishing attack Simulations and Wi-fi testing.

Internal
DIVYA JAIN
+91-9972999930 jaidivya25991@[Link] [Link]/author/?a=9480 [Link]/in/divya-jain-104b870/

Tata Consultancy Services (Group acquisition from Barclays)


Security Analyst [May 2015 – Aug 2017]

 Vulnerability assessment of Barclays’ in-house applications and Network components covered under global
information security process of the organization.
 Recommending improvements in security systems, procedures and developed remediation plans.
 Wi-fi penetration testing Simulations.
Centre of Development and Computing [CDAC-ACTS]
Trainee - IT infrastructure and system Security [Sep 2014 – Feb 2015]

 Concepts of applications security implementation, Ethical Hacking and Cyber Forensics.


 Analyze the Threats Detection Techniques, Intrusion Detection and Prevention measures.
 Security Testing techniques and Strategies across different Cyber Security Domains like: Application, Infrastructure
Security.
 Analyze and solve problems conceptually and from diverse industries, such as government manufacturing, retail,
education, banking/ finance, healthcare and pharmaceutical.

SCHOLASTICS
Bachelor of technology [ Computer Science & Engineering, 2014]
Post-Graduation Diploma [ PG Diploma in IT Infrastructure security and Services – CDAC-ACTS, 2014]

PERSONAL DOSSIER
Date of Birth: 01 Sep 1991 | Marital Status: Married | Gender: Female | Language: English, Hindi | Nationality: Indian

Internal

Common questions

Powered by AI

Divya Jain holds several cybersecurity certifications, including Offensive Security Certified Professional (OSCP) and Certified Ethical Hacker (CEH v9). These certifications reflect her skills in offensive security, as they both focus on penetration testing, ethical hacking, and the practical aspects of finding and exploiting vulnerabilities in systems to improve security defenses .

Divya Jain's work has improved organizational security postures by implementing thorough security assessments across multiple platforms and developing comprehensive security procedures. At Cytiva, her responsible disclosure and development of security testing frameworks helped fortify their web portal and other products. Her efforts with process automations at Continental Automotive India demonstrated a substantial efficiency improvement, indicating a more robust security environment .

Divya Jain's previous experience has prepared her for a Cyber Security Architect role through her extensive experience across multiple cybersecurity domains, such as application security, cloud penetration testing, network testing, and hardware security. Her responsibilities in establishing security test frameworks, defining security processes, and automating security testing at organizations like Continental Automotive and Cytiva demonstrate her ability to design robust security architectures. Her ongoing pursuit of the CISSP certification further prepares her technically and theoretically for an architect role .

Divya Jain has been actively involved in responsible vulnerability disclosure, which includes disclosing vulnerabilities to Cytiva’s web portal. She has received the spotlight award for such disclosure efforts within Cytiva, showcasing her commitment to ethical practices and the enhancement of security measures across organizational systems .

Divya Jain faces unique challenges with SCADA systems, such as the complexity of industrial protocols (Ethernet/IP, OPC, Modbus, ProfiNet) and ensuring the security of digital communication among industrial equipment. She addresses these by conducting thorough security assessments, including protocol reversing and memory forensics. She leverages her skills in firmware security and reverse engineering to identify vulnerabilities and improve security processes within these complex systems .

Divya Jain's expertise in cybersecurity covers both practical and theoretical aspects through her extensive training, certifications, and experience in various domains such as Application Security, Cloud Penetration Testing, Network and Infrastructure Penetration Testing, and Firmware Security. She has hands-on experience with a wide range of tools like Burp Suite Pro, AWS Inspector, and Nessus, as well as theoretical knowledge demonstrated by her ongoing CISSP certification pursuit and prior achievements like OSCP and CEH .

Divya Jain employs strategic approaches like establishing comprehensive security assessment procedures, setting up dedicated security test centers, and automating security processes. She leads with an emphasis on process optimization and team guidance, seen in her leadership of a team of four at Continental Automotive India, where she managed various hardware and IoT projects, focusing on security automation and effective resource utilization .

Divya Jain has significantly contributed to security testing processes by setting up and automating security test centers, leading security assessments, and developing test case procedures and reporting templates. At Continental Automotive India, she led the establishment of a Security Test Centre, reducing time for ethernet security processes by 99%. In her role at Cytiva, she created security assessment procedures and automated OS hardening processes using PowerShell .

Divya Jain ensures the security of hardware and IoT devices through comprehensive testing techniques such as Firmware Security and Fuzz Testing using tools like Binwalk, FMK, and JTAGulator. She conducts hardware testing, such as JTAG/SPI/UART interfaces, and leads projects handling gateways, TCUs, and IoT products to establish and enhance security processes and hardware security protocols .

Divya Jain's background in diverse industries like manufacturing, finance, and healthcare has given her a broad perspective on cybersecurity challenges and practices. This exposure helps her analyze problems conceptually and apply tailored cybersecurity solutions effectively across various domains. She integrates her understanding of industry-specific threats and compliance requirements to develop robust security strategies that cater to the unique needs of each industry, enhancing her problem-solving approach .

You might also like