Technical Cybersecurity Risk & Assurance Consultant
- Verfügbarkeit einsehen
- 0 Referenzen
- 110‐130€/Stunde
- Vilnius
- Europa
- ro | en | it | de
- 11.09.2026
- Contract ready
Kurzvorstellung
Geschäftsdaten
Qualifikationen
Projekt‐ & Berufserfahrung
5/2024 – 7/2026
Tätigkeitsbeschreibung
Combined defensive security operations with hands-on penetration testing, exposure validation, vulnerability management and risk-based security assessment across endpoint, identity, cloud, network and application environments.
Security Testing, Exposure and Risk Assessment
• Planned and executed security assessments across more than 100 web applications and APIs, AWS assets and more than 1000 infrastructure components using Pentera, AppCheck and manual testing techniques.
• Conducted Active Directory password-strength assessments and controlled ransomware simulations to validate defensive readiness and attack resistance.
• Validated authentication and authorisation weaknesses, vulnerable components, exposed services, insecure configurations and exploitable attack paths, separating actionable findings from scanner noise.
• Discovered and catalogued internet-facing assets, subdomains, APIs, cloud storage, certificates and shadow IT to support external attack-surface monitoring.
• Consolidated and deduplicated vulnerability findings, assessing contextual risk based on severity, exploitability, exposure, asset criticality and business impact.
• Produced prioritised remediation recommendations and communicated technical and business risk to asset owners, service owners and executive stakeholders.
• Used Tanium to assess Windows, Linux and macOS devices for vulnerabilities, missing patches, configuration weaknesses and compliance deviations.
• Supported remediation tracking and verification through targeted retesting and follow-up reporting.
Security Operations, Detection and Incident Response
• Monitored and investigated endpoint, identity, cloud and network events using CrowdStrike Falcon EDR/XDR, NG-SIEM and Identity Protection across Windows, Linux, macOS, AWS and MS Azure & Entra ID environments.
• Managed security incidents through triage, investigation, containment, eradication, recovery and post-incident review, coordinating technical actions and communicating risk and restoration requirements to stakeholders.
• Configured SIEM data ingestion, tuned detections and developed CrowdStrike Fusion workflows for phishing, account compromise, malware and infected-host scenarios.
• Improved the consistency of alert enrichment, notification and response activities through workflow automation.
• Supported CrowdStrike Falcon deployment and endpoint-fleet health, investigating installation failures and Reduced Functionality Mode issues across Windows, Linux and macOS.
Technology used: CrowdStrike Falcon EDR/XDR, NG-SIEM, Identity Protection and Fusion SOAR; Pentera; AppCheck; Tanium; Burp Suite; OWASP ZAP; Nuclei; Nmap; Metasploit; Amass; OpenVAS/GVM; Tenable Nessus; AWS; Azure; Entra ID; Microsoft Defender for Office 365; Varonis; Rubrik; BeyondTrust.
Cyber Security Engineer
5/2023 – 5/2024
Tätigkeitsbeschreibung
• Assessed web applications, backend services and APIs, identifying and validating authentication weaknesses, injection risks, insecure configurations and vulnerable components.
• Worked with developers and service owners to explain findings, agree remediation actions and verify fixes through targeted retesting.
• Deployed and tuned Splunk dashboards, searches and alerts to improve visibility of application, infrastructure and security events.
• Developed repeatable functional and security checks using Python and JavaScript, applying security-focused QA practices to application, API and backend validation.
• Conducted cloud and cyber-risk assessments across GCP-hosted services, including IAM, API security, data protection and backend resilience; contributed to strategy, policy, UK GDPR and awareness activities.
Technology used: Splunk, Burp Suite, OWASP ZAP, Postman, Snort, Wireshark, Python, JavaScript, Cypress, Selenium, Jira and GCP.
Test Automation, Test Management
10/2022 – 10/2023
Tätigkeitsbeschreibung
Remote freelance engagement for end customer Continental Automotive, delivered via Valantic GmbH, focused on automated validation of embedded ECU security and flashing workflows.
• Analysed ECU security test requirements and translated them into structured, traceable test specifications.
• Authored detailed test case descriptions and maintained requirements traceability in IBM DOORS.
• Automated validation of ECU flashing and OTA update workflows using Python, Robot Framework and Lauterbach PRACTICE.
• Developed automated checks focused on secure flashing, update robustness, diagnostic behaviour and repeatable embedded validation.
• Used Vector CANoe, ODIS, Wireshark and Lauterbach Debugger to validate embedded system behaviour and diagnose defects.
• Managed test execution, defect evidence, result analysis and technical reporting.
• Supported Agile/Scrum delivery using Jira and Confluence in a distributed remote environment.
Tools: Python, Robot Framework, Lauterbach PRACTICE, Lauterbach Debugger, Vector CANoe, ODIS, Wireshark, IBM DOORS, Jira, Confluence, Agile/Scrum
Cyber Security, Test Automation
1/2022 – 5/2023
Tätigkeitsbeschreibung
Test automation role focused on enhanced parallelization of device, applications and services assessments. Role based in London, with full remote working possible.
• Designed and deployed a parallel automated test system capable of executing system-level tests across multiple physical devices.
• Built and commissioned a physical test rack supporting parallel validation of up to 16 devices.
• Integrated physical test equipment with supporting test services and applications, both on-premise and in cloud environments.
• Automated result collection, storage and reporting into TestRail and GCP.
• Reduced manual regression effort by up to 95% through automation of execution, data collection and reporting.
• Expanded automated test coverage by approximately 5x through new web, device, API, regression and security-aware test suites.
• Automated web application tests using Selenium, Cypress and Playwright.
• Conducted vulnerability and risk assessments on connected devices and cloud products using Nmap and Wireshark.
Tools: Python, JavaScript, Selenium, Cypress, Playwright, Postman, GCP, Jenkins, TestRail, Nmap, Wireshark, Jira, Confluence
Test Automation
4/2020 – 1/2022
Tätigkeitsbeschreibung
QA automation role focused on consumer electronics, set-top-box testing, embedded applications and backend services validation, AV capture automation and performance testing. Hybrid role based from the London office.
• Automated system-level validation of set-top-box and media platforms by simulating end-user behaviour.
• Automated UI-level testing using AV capture processing, Python, Lua and the Test Wizard suite.
• Developed automated checks for consumer electronics user journeys, device responsiveness, stability and regression behaviour.
• Conducted backend service testing using Postman.
• Analysed network traffic using Wireshark to investigate communication issues and potential security concerns.
• Developed Python/OpenCV-based performance test scripts to measure responsiveness and detect regressions.
• Designed and executed stress, load and spike tests to validate system stability under demanding conditions.
• Automated storage and management of test results in GCP and TestRail.
Tools: Python, Lua, Test Wizard, AV capture tools, Postman, Wireshark, OpenCV, GCP, TestRail, Bash, Jira
Qualitätsmanagement / QS / QA (IT), Test Automation
4/2014 – 3/2020
Tätigkeitsbeschreibung
Embedded automotive validation role focused on IC and mHEV powertrain systems, HiL testing, battery modelling, motor testing, automation, data analysis and reporting.
• Automated HiL test execution, data analysis and reporting for IC and mHEV powertrain systems.
• Used dSPACE, Python, Matlab/Simulink and Vector CANalyzer to validate real-time embedded automotive systems.
• Conducted manual and automated validation in HiL environments.
• Developed and maintained validation workflows for embedded control systems.
• Created scripts to automate execution, data processing and reporting of test results.
• Developed LiFePO4 battery models in Matlab/Simulink and validated model behaviour against real-world test data.
• Analysed starter motor test data to verify performance, reliability and compliance with expected behaviour.
Tools: Python, dSPACE, Matlab/Simulink, Vector CANalyzer, HiL, data analysis tools, embedded automotive systems
Softwaretester, Test Automation, Validierungsingenieur
8/2011 – 3/2014
Tätigkeitsbeschreibung
Embedded software and model-based development role with strong testing, validation and simulation responsibilities for automotive control software.
• Developed test scripts for multiple validation stages including MiL, SiL and PiL.
• Executed unit, module, integration and hardware-level tests for embedded automotive software.
• Used BTC Embedded Tester and TPT for model-based and embedded software validation.
• Managed software requirements and traceability using Rational DOORS.
• Adjusted TargetLink models to meet development and testing requirements.
• Generated embedded C code for target platforms and authored embedded C code based on functional specifications.
• Developed and maintained Vector CANoe rest-bus simulations and acted as an internal trainer for Vector CANoe.
Tools: Embedded C, TargetLink, Rational DOORS, BTC Embedded Tester, TPT, Vector CANoe, MiL, SiL, PiL, automotive embedded systems
Softwareentwickler, Testdesign (IT)
Ausbildung
Northumbria University
London, UK
Gh. Asachi Technical University
Iasi, Romania
Über mich
Progressed from developing and validating software and automotive embedded systems to conducting penetration tests, vulnerability assessments, exposure validation, risk scoring and security posture assessments across web applications, APIs, infrastructure, cloud and identity environments. Combining a structured testing and validation mindset with hands-on experience in SOC operations, incident response, threat detection, vulnerability management and remediation verification.
Experienced with CrowdStrike Falcon, SIEM and SOAR platforms, Pentera, AppCheck, Tanium, Burp Suite and cloud-security tooling. MSc-qualified in Cybersecurity, with a strong ability to convert technical findings into prioritized, evidence-based risk decisions and practical remediation actions. Experienced in remote and international environments, working effectively with engineers, service owners, security teams and management.
Weitere Kenntnisse
Software Development → Software Testing → Embedded Systems Validation → QA → Security Testing → Cybersecurity Risk and Assurance
• Software development and engineering: Implementation, debugging, simulation and technical root-cause analysis.
• Software testing: Functional, integration, regression and automated testing; defect.
• Systems and embedded validation: MiL, SiL, PiL and HiL testing; ECU flashing, OTA workflows and vehicle-communication simulation.
• QA via Test Automation: analysis and quality assurance, test infrastructure design and automated checks development.
• Cybersecurity testing and assurance: Web, API, infrastructure, cloud, identity and attack-surface assessments; vulnerability validation, risk scoring and remediation verification.
• Defensive security operations: SOC monitoring, incident response, threat hunting, detection engineering and SOAR.
CORE COMPETENCIES:
• Penetration testing: Web applications, APIs, infrastructure, cloud, Active Directory and attack surfaces discovery.
• SOC & incident response: Monitoring, triage, threat hunting, containment, eradication, recovery and stakeholder communications.
• Vulnerability management: Consolidation, manual validation, contextual risk scoring, prioritization, remediation guidance and retesting.
• Security engineering: SIEM ingestion, detection tuning, CrowdStrike sensor health and SOAR workflow.
• Endpoint assurance: Tanium vulnerability, compliance and security-posture assessments across Windows, Linux and macOS.
• Remote delivery: Independent assessments, executive and technical reporting, cross-functional workshops and asynchronous collaboration.
Persönliche Daten
- Rumänisch (Muttersprache)
- Englisch (Fließend)
- Italienisch (Gut)
- Deutsch (Grundkenntnisse)
- Europäische Union
Kontaktdaten
Nur registrierte PREMIUM-Mitglieder von freelance.de können Kontaktdaten einsehen.
Jetzt Mitglied werden
