profile-pic

Faizal Ali

Cyber security professional versed in vulnerability testing of various assessment and penetration technologies such as Web & Mobile application, API, Thick client and Networks.
  • Role

    Deputy Manager - Application Security Specialist

  • Years of Experience

    5.8 years

Skillsets

  • Python
  • C
  • Cloud
  • Bash
  • C++
  • DAST
  • SAST
  • Thick client
  • Maxt

Professional Summary

5.8Years
  • Apr, 2024 - Present1 yr 11 months

    Deputy Manager - Application Security Specialist

    Jio Platforms Limited
  • Jun, 2023 - Dec, 2023 6 months

    Application Security Engineer

    Checkmarx
  • Jan, 2020 - Jun, 20233 yr 5 months

    Security Services Associate Consultant

    Synopsys Inc.

Work History

5.8Years

Deputy Manager - Application Security Specialist

Jio Platforms Limited
Apr, 2024 - Present1 yr 11 months
    Performed security assessments and secure code reviews for products, internal tools, and third-party integrations. Collaborated closely with engineering and architecture teams to implement secure design principles during all phases of the SDLC. Conducted threat modeling for new product features and supported privacy-by-design initiatives across the platform. Discovered multiple High and Critical severity infrastructure-level vulnerabilities across both external and internal applications, leading to timely mitigation. Contributed to the development of internal AppSec best practices and hardening guides tailored to business units.

Application Security Engineer

Checkmarx
Jun, 2023 - Dec, 2023 6 months
    Conducted over 50 SAST and DAST assessments for high-risk applications in FinTech. Provided detailed remediation guidance to AppSec and development teams, improving vulnerability remediation time by 40%. Performed secure code reviews across Java, .NET, and JavaScript applications, identifying insecure coding patterns and logic flaws.

Security Services Associate Consultant

Synopsys Inc.
Jan, 2020 - Jun, 20233 yr 5 months
    Performed 150+ security assessments across Web, Mobile, API, Thick Client, and Network layers for clients in Finance, Insurance, and QSR domains. Identified and reported OWASP Top 10 and business logic vulnerabilities through manual and automated testing. Led end-to-end security assessment projects, including scoping, testing, reporting, and retesting. Assisted clients in interpreting findings, prioritizing risks, and implementing effective remediation. Created internal scripts and workflows in Python and Bash to improve testing efficiency.

Major Projects

2Projects

CTF Lab

Synopsys Inc
Jan, 2023 - Jun, 2023 5 months

    A captivating environment that features Linux and Windows with scenarios of corporate network where Cyber Kill Chain steps are followed to compromise the host machine.

Vulnerable AWS Cloud Environment

Synopsys Inc
Jan, 2020 - Jun, 2020 5 months

    A vulnerable AWS could environment using Terraform containing most vulnerabilities cited by Cloud Conformity and AWS Security Documentation.

Education

  • Bachelor in Computer Science and Engineering

    Chandigarh University (2020)