Bhanu Rekha Vasamsetti
Cyber Security Analyst
About
Dedicated Security Analyst with 3+ years of experience in vulnerability management, security assessments, secure configuration, and source code review. Skilled in both manual and automated application security testing, with hands-on experience identifying and resolving vulnerabilities in software applications. Proficient in conducting comprehensive vulnerability assessments to identify, prioritize, and mitigate security risks using industry-standard tools such as Tenable.io, Burp Suite, Nmap, and Nessus while adhering to CIS Benchmarks. Experienced in developing and implementing effective vulnerability management strategies for continuous monitoring, identification, and remediation of security weaknesses. Hands-on experience performing Static Application Security Testing (SAST) using Apiiro and integrating secure code review practices within CI/CD pipelines to detect vulnerabilities early in the development lifecycle. Experienced in repository-level risk assessments, identifying misconfigurations, exposed secrets, and insecure dependencies to strengthen the overall application security posture. Skilled in preparing detailed VAPT (Vulnerability Assessment and Penetration Testing) reports, including findings, risk analysis, and remediation recommendations, with a primary focus on vulnerability assessment. Strong understanding of networking and core security concepts, with the ability to analyze and audit Python source code for potential security vulnerabilities. A self-driven and team-oriented professional committed to maintaining security standards and implementing secure practices throughout the Software Development Life Cycle (SDLC).
Skills & Expertise (21)
Work Experience
Cyber Security Analyst
GENPACT
Aug 2023 - Present
Performed Static Application Security Testing (SAST) across multiple repositories using APIIRO to identify security vulnerabilities, coding flaws, and compliance gaps during early stages of the SDLC. Integrated APIIRO with GitLab CI/CD pipelines to enable continuous code scanning, automated policy enforcement, and secure build validation before deployment. Conducted detailed source code analysis to detect vulnerabilities such as injection issues, insecure authentication mechanisms, improper input validation, and sensitive data exposure. Performed repository-level risk assessments to identify hardcoded secrets, token exposures, misconfigurations, and outdated or vulnerable third-party dependencies. Applied risk-based prioritization using CVSS scoring, application criticality, and data sensitivity to focus efforts on high-impact vulnerabilities. Mapped applications to their respective repositories and environments to ensure complete security coverage and visibility across the development lifecycle. This contributed to strengthening secure coding practices by providing recommendations aligned with industry standards and secure SDLC guidelines. Experience in performing manual and automated penetration testing to identify vulnerabilities, validate security weaknesses, and assess their potential business impact. Ensured Secure Software Development Lifecycle (SDLC) practices by collaborating with stakeholders and development teams on design reviews, secure configurations, compliance validation, and data privacy controls across multiple network management products. Gathered and analyzed business and security requirements to define security testing strategies, identifying application vulnerabilities and strengthening overall system architecture. Conducted detailed technical security assessments, documenting Findings with clear reproduction steps, impact analysis, and actionable remediation recommendations. Partnered with development teams to remediate vulnerabilities and implement security gates within development workflows to ensure secure releases. Automated security hardening and vulnerability scanning processes, optimizing scan efficiency and generating periodic security reports for stakeholders. Implemented secure architecture principles across applications and infrastructure, and integrated security controls within CI/CD pipelines (including SAST/DAST) to enable early detection of vulnerabilities. Developed and executed security testing scenarios simulating real-world attack vectors to evaluate the effectiveness of implemented security controls. Reviewed and audited Python scripts and application code to identify insecure coding patterns, input validation Flaws, improper exception handling, and dependency-related risks. Performed vulnerability assessments and security testing across web applications, APIs, and infrastructure, conducted risk-based prioritization (CVSS), and collaborated with development teams to remediate issues in alignment with secure coding practices. Worked with cloud environments and containerized deployments (Docker, Kubernetes), addressing security configurations, and applied industry frameworks such as NIST, ISO 27001, and COBIT while monitoring and adapting to evolving threat landscapes.
Education
Bachelor of Science - Adikavi Nannaya University
- ยท Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Availability Details
Visa Status
Citizen
Relocation
Open to Relocation
Skills (21)
Click a skill to find developers with the same skill