Summary
Overview
Work history
Education
Accomplishments
Timeline
Generic

Vinay Kumar Gandla

United Kingdom

Summary

Experienced application development and information security professional with expertise in mainframe systems, COBOL, JCL, VSAM, and knowledge of CICS. Skilled in troubleshooting, problem-solving, and analysis under high-pressure environments while adhering to tight deadlines. Proficient in Agile (Scrum), Waterfall, and other SDLC models. Demonstrates strong capabilities in vulnerability assessment and penetration testing across web applications, APIs, mobile platforms, networks, infrastructure, and wireless systems. Adept at using tools such as Qualys WAS/VM, Burp Suite Pro, HCL AppScan, OWASP ZAP Proxy, SQL Map, Nessus, Acunetix, and various open-source solutions. Committed to delivering secure and efficient solutions while contributing to organisational success.

Overview

10
10
years of professional experience
7
7
years of post-secondary education

Work history

Penetration Tester

Nextics Software Solutions Pvt Ltd
12.2022 - 03.2025

Project 1: SOC Operations, Vulnerability & Patch Management

SOC Operations & Vulnerability Management:

  • SOC Operations & Vulnerability Management: SOC Integration & Continuous Monitoring: Configured and managed SOC tools (Palo Alto XDR, Securonix SIEM, Microsoft Defender, CrowdStrike) to enable real-time threat detection and effective incident response
  • Vulnerability Management & Patch Coordination: Led regular vulnerability scans using Qualys; performed detailed triage and false positive analysis to ensure accuracy in vulnerability reporting
  • Tools & Integration: Palo Alto XDR, Securonix SIEM, Microsoft Defender, CrowdStrike
  • Vulnerability Management: Regular vulnerability scans using Qualys; triage, false positive analysis, and patch management coordination
  • Process & Training: Building and refining SOC processes, playbooks, and providing technical training
  • VAPT & Manual Penetration Testing: Testing Scope: Web, API, network, mobile, and thick-client applications
  • Reporting: Comprehensive documentation of risk assessments and remediation recommendations

Project 2: VAPT & Manual Penetration Testing:

  • Manual Penetration Testing & Analysis: Executed comprehensive manual penetration tests targeting web, API, network, mobile, and thick-client applications.

Employed a combination of automated tools (Nessus, Burp Suite, Metasploit, Wireshark) and manual techniques to identify and exploit vulnerabilities

  • Risk Assessment & Secure SDLC Integration: Conducted detailed risk assessments, secure code reviews, and collaborated with development teams to integrate secure coding practices throughout the SDLC

Developed technical reports that included risk assessments, impact analysis, and actionable remediation recommendations

  • Reporting & Continuous Improvement: Documented detailed findings from penetration tests, updating vulnerability management strategies and security controls based on evolving threat intelligence

Supported the creation of SOC services for clients using both remote and on-site solutions, ensuring robust protection of information systems

Software Developer

Legato Health Technologies
02.2019 - 02.2021
  • Extensively working on analysis, Development, Testing, Implementation Maintenance and Production Support activities
  • Participated in monthly and technical Release Implementations
  • Provide post-deployment support for the changes/projects after Production implementation
  • Held Responsible for a detailed root cause analysis for each problem and implements appropriate countermeasures to avoid the problem from reoccurring
  • Interacted with Business partners to capture project requirements and reporting parameters
  • Develop the code for automation ideas submitted on Innovation hub for repetitive work
  • Developed code for data extraction and data migration from Nasco System to WGS system
  • Monitoring Daily/weekly/Monthly batch jobs in SAR and maintaining status for Audit purpose

Software Developer

Tetrasoft India Pvt. Ltd
04.2015 - 02.2019
  • Liaising closely with line-managers, architects to ensure high-quality, professional and team-focused software engineering environment
  • Conducting peer reviews for application design, coding and adherence to set standards, procedures & methodologies, as well as mentoring of junior staff in these disciplines
  • Involvement in complete Systems Development Life Cycle (SDLC) of application
  • Implementation of Ad-Hoc request and Provides Mailbox support
  • Discussion with client to find out requirements and carry out optimization of requirements as per available technologies
  • Analyzing programs, implementing business logics by coding new programs and performing existing program change requests
  • Perform peer code review of newly developed software programs or existing programs
  • Fixed the recurring abends and saved the budget & manual efforts

Education

Master of Science - Data Science

Cardiff Metropolitan University
01.2021 - 06.2022

MTech - Embedded Systems

Jawaharlal Nehru Technological University
11.2012 - 12.2014

BTech - Electronics and Communication Engineering

Jawaharlal Nehru Technological University
07.2008 - 05.2012

Accomplishments

● Experienced in Application Development, Support, and Maintenance for Mainframe systems.

● Expertise in COBOL, JCL, and VSAM, with knowledge of CICS.

● Proficient in troubleshooting, problem-solving, and analysis, with the ability to work under pressure and meet tight deadlines while fully committed to the task.

● Experience with Scrum (Agile), Waterfall model, and familiarity with other SDLC models.

● Proficient in management of Information Security which includes Vulnerability Assessment and penetration testing of Web, APIs, Mobile Applications, Network, Infrastructure, wireless and conducted Internal and External Social Engineering and being a part of Red Team Assessment.

● Experienced in using various vulnerability assessment and penetration testing using various tools like Qualys WAS, Qualys VM, Burp Suite Pro, HCL Appscan, OWASP ZAP Proxy, SQL Map, Nessus, Acunetix and many opensource tools.

Timeline

Penetration Tester

Nextics Software Solutions Pvt Ltd
12.2022 - 03.2025

Master of Science - Data Science

Cardiff Metropolitan University
01.2021 - 06.2022

Software Developer

Legato Health Technologies
02.2019 - 02.2021

Software Developer

Tetrasoft India Pvt. Ltd
04.2015 - 02.2019

MTech - Embedded Systems

Jawaharlal Nehru Technological University
11.2012 - 12.2014

BTech - Electronics and Communication Engineering

Jawaharlal Nehru Technological University
07.2008 - 05.2012
Vinay Kumar Gandla