• Designing test plans, executing tests, and identifying bugs and document test results to ensure a high-quality product.
• Testing BOT Security based on bot-signatures, bot-trap, device-fingerprint, rate-limiting, captcha to detect/mitigate automated bot attacks and protect web application.
• Testing BOT Machine Learning(ML) based Application security detection/mitigation to prevent behavior-based attacks like account takeover, website scanning, content scraping, Unusually High Upload/Download volume and much more.
• Performing WAF Security Testing such as SQL Injection, XSS Attacks, POST Body Limit, Buffer Overflow, CSRF and WAF signatures to protect web applications.
• Testing TCP/IP Layer3/Layer4 DDOS Appliance security features such as Source/Destination Rate Limits, Flood Attack etc.
• Utilizing network traffic tools curl, hping, scapy, wireshark and tcpdump.
• Automating functional sanity and regression test cases using Postman Collection APIs and Python Script
• Build and maintain a test network (Linux clients/servers, Security Appliance, switches, routers and IXIA/Breaking Point)
• Perform scale and performance testing of Network Security features using Traffic generators such as Ixia and Breaking point.