Lorena W. Kearney
Penetration Tester, Software
Austin, TX · (512) 555 0144 · name@example.com · linkedin.com/in/lorenawkearney
Key Qualifications
EXPERIENCE
Six years in offensive security consulting
INDUSTRIES
Software, financial technology, healthcare technology
SPECIALTIES
Web application testing, application programming interface testing, authentication flaws, reporting
SYSTEMS
Burp Suite, Metasploit, Nessus, Kali Linux, Nmap
CREDENTIALS
Offensive Security Certified Professional, Computing Technology Industry Association Security Plus
EDUCATION
Bachelor of Science in computer science, University of Texas at Austin
Results at a Glance
78
Web application engagements
40,000
Borrower records
210
Findings across client
Executive Summary
Penetration tester at a consultancy running about 90 engagements a year, most of them web and application programming interface tests under a tight scope and a fixed window. Six years testing, the Offensive Security Certified Professional behind him, and a habit of writing findings a developer can actually fix.
Signature Achievements
- Delivered 78 web application engagements in three years with every report issued inside the agreed window.
- Found an authentication bypass in a lending platform that would have exposed 40,000 borrower records.
- Chained three low severity findings into full account takeover on a scheduling product, which changed how the client ranked its backlog.
- Cut average report writing from four days to two by building a finding library with tested remediation text.
- Retested 210 findings across client engagements and confirmed 84 percent fixed on the first attempt.
- Ran the internal training that took two junior testers to their first solo web engagement inside a year.
Professional Experience
Penetration Tester
Barton Springs Offensive Security, Austin, TX 2022 to present
One of nine testers at a consultancy delivering around 90 engagements a year to software and financial technology clients.
- Scopes and runs web application and application programming interface tests under signed rules of engagement.
- Tests authentication, authorization and business logic rather than stopping at scanner output.
- Writes findings with proof of concept steps and remediation the development team can follow.
- Presents results to client engineering and executive audiences and runs the retest.
Security Consultant
Guadalupe Assurance Partners, Austin, TX 2020 to 2022
Four person security practice inside a technology consulting firm serving middle market clients.
- Ran external network penetration tests and vulnerability assessments with Nessus and Metasploit.
- Performed configuration reviews of cloud accounts and identity settings.
- Built the standard rules of engagement document the practice still uses.
Software Developer
Colorado Bend Web Studio, Austin, TX 2019 to 2020
Six person studio building web applications for small business clients.
- Fixed the security findings from a client audit, which is what turned the career toward testing.
Licensure and Certification
Offensive Security Certified Professional, 2022
Computing Technology Industry Association Security Plus certification, 2020
Member, Open Worldwide Application Security Project Austin chapter
Education
Bachelor of Science in computer science, University of Texas at Austin, 2019
Core Skills
Web application testing · Application programming interface testing · Burp Suite · Metasploit · Rules of engagement · Proof of concept development · Remediation guidance · Retesting · Client reporting