Evgeny Erdelevsky

Advising methods to reduce or fix security risks to systems, creating and planning penetration methods, tests, and scripts. Responsible for working with clients to identify their needs from the test, like the type and number of systems they would like to test. Experience in manual penetration and application testing. White/gray/black box penetration testing on the financial systems using Kali Linux for OWASP top 10 Vulnerabilities like XSS, SQL Injection, CSRF, Privilege Escalation and all the test-case of a web application security testing.Skilled using Burp Suite, Acunetix Automatic Scanner, NMAP, DirBuster, Wireshark, Nessus, SQL Map for web application Penetration tests. Conducted Vulnerability Assessment on applications. Knowledge of network architectures, operating systems, application software and cyber security tools. Knowledge of programming languages, Python, golang, kotlin. Understanding of information security and applied cryptographic protocols.Proficiency in scripting, Unix operating systems and windows.  Ability to exploit recognized vulnerabilities.Strong written and oral communication skills with the ability to explain technical ideas to non-technical individuals at any level.Proficient in understanding application level vulnerabilities like XSS, SQL Injection, CSRF, Authentication bypass, Weak Cryptography, Authentication flaws etc. Conducted Dynamic and Static Application Security Testing (SAST & DAST). Carrying out attacks on customers' wireless networks, as well as bluetooth devices such as computer mice (mousejacking)Report writing using standardized method for rating IT vulnerabilities and determining the urgency of response. (CVSSv2.0 Calculator.) Providing details of the issues identified and the remediation plan to the stake holders. Worked with DevOps teams to automate security scanning into the build process.

Key Skills

OSINT
Computer Networks
Wireless networks
Moblie Apps
Communication skills
Linux/Unix

Professional Experience

May 2021
Present
Penetration Tester
USSC Yekaterinburg, RU
  • Performed web application, mobile application and infrastructure penetration tests, including critical infrastructure facility. 
  • Developed processes and implemented tools and techniques to perform ongoing security assessments of the environment.
  • Analyzed security test results, draw conclusions from results and developed targeted testing as deemed necessary.
  • Provided technical consultation on Security Tools and Technical Controls.
  • Lectured at the university from the company.
  • Rewrote some scripts used by the department at work 


Feb 2020
May 2020
University Lecturer
UrFU Yekaterinburg, RU
Taught Olympiad programming in Python to children 12-16 years old.
Ended because of Covid Restrictions.

Education

Sep 2018
Jun 2022
Bachelor in Computer Science in Matmech UrFU
Ural Federal Universiry

Achievements

Hackthebox Hacker rang
https://app.hackthebox.com/profile/268965
Research work
  • Scanned a large pool of addresses.
  • Wrote an exploit.
  • Analyzed the received data.
  • Rendered report.
  • This helped the company increase its prestige and find new clients. 

Hobbies & Interests

  • Adventure Sports
  • Computers
  • Hiking

Languages

Russian
(Native)
English
(Fluent)
German
(Basic)

Career Aspiration

In the next 3 years I want to obtain a Penetration Tester position with reputable company to enhance my career and help company excel.

Get in touch with Evgeny