Gerardo GiménezSecurity Engineer
Experienced Information Security Engineer with 7-year history of managing security of on premises, mobile and cloud web applications. Adept at identifying security risks and improving security architecture designs. Proven expertise in cybersecurity tools, including static and dynamic analyzers, WAF and SIEM tools
Tech stack
Security (6)
Testing (6)
Web (5)
JIRA (4)
Mobile (4)
Static analysis (3)
Jenkins (1)
Agile (1)
Writing (1)
Management
Java
SQL
Python
JavaScript
Security Testing
Experience
Security EngineerFearless Information Security, LLC Full-time
05/2019 - 09/2020

Provide application security support for a variety of of sectors, building a security program based on best practices - Build application security program, identifying risks - Conduct penetration testing activities - Provide static and dynamic code analysis coverage, automating the process and generating reports

JIRA
Static analysis
Security
Testing
Security ManagerJive Software Full-time
04/2018 - 04/2019

- Led application security program post-acquisition process, maintaining security activities and requirements for the product in a transition from on-premise datacenters to AWS cloud provider. - Integrated security into the Agile lifecycle, automating secure code analysis to meet product requirements within delivery timelines. - Reduced security program cost by replacing commercial tools with open source counterparts. - Worked side by side with support team to answer security concerns and vulnerabilities reports from customers, connecting directly with them if needed - ISO27001 and SOC2 recertification support, writing tools to automate security reporting - Train developers on common security vulnerabilities - Web Application Firewall maintenance and analysis to identify threats - Validate and determine scope of security issues - 3rd party penetration testing scheduling, set up and outcome analysis

JIRA
Agile
Static analysis
Web
Security
Testing
Writing
Jenkins
Lead Security EngineerClarolab
06/2016 - 03/2018

Worked as Security Quality Assurance Lead in ClaroLab for customer Jive Software - Define security testing schedule, in coordination with developers and QA teams - Define must fix bugs previous to a release - Validate compliance with security policy previous to a release - Automate security tasks - Coordinate, set up and engage with 3rd party penetration test providers for the product

Web
Mobile
Security
Testing
Security EngineerClarolab
11/2014 - 05/2016

Security Quality Assurance for customer Jive Software - Worked on web and mobile versions of the product - Run static and dynamic security scans, analyze results and generate reports - Conduct manual penetration testing - Report security bugs to developing teams, explain its implications and how they can be addressed - Validate proposed fixes for security bugs - Search for regressions on modified code with previous bugs

JIRA
Web
Mobile
Security
Testing
Education
Engineering in Information TechnologiesUniversidad Nacional del Noroeste de la Provincia de Buenos Aires
01/2008 - 01/2018