Shubhpreet Kaur

Shubhpreet Kaur

Software Developer

Followers of Shubhpreet Kaur691 followers
location of Shubhpreet KaurBengaluru, Karnataka, India

Connect with Shubhpreet Kaur to Send Message

Connect

Connect with Shubhpreet Kaur to Send Message

Connect
  • Timeline

  • About me

    Technology consultant @EY || ISMS ISO/IEC 27001 :2022 Lead Auditor || ISC2-CC || DISA

  • Education

    • Guru Gobind Singh Indraprastha University

      2015 - 2019
      BTech - Bachelor of Technology btech
    • SCIT - Symbiosis Centre For Information Technology

      2021 - 2023
      Master of Business Administration - MBA Information security

      • Using John The Ripper to crack the password and hashes: Using John the ripper tool to crack the password with the combination of brute force attack and dictionary attack. The speed of the process depends upon the length of the password and the hash used to encrypt it. Further to minimize time complexity a custom word list was made.• Performing manual and automated reconnaissance: Performed reconnaissance on a domain name and found top-level domain, second-level domain, and sub-domains… Show more • Using John The Ripper to crack the password and hashes: Using John the ripper tool to crack the password with the combination of brute force attack and dictionary attack. The speed of the process depends upon the length of the password and the hash used to encrypt it. Further to minimize time complexity a custom word list was made.• Performing manual and automated reconnaissance: Performed reconnaissance on a domain name and found top-level domain, second-level domain, and sub-domains. Performing automated reconnaissance with the help of tool Bheem. Finding out mail servers and a list of IP addresses. Using Nmap to find hosts and services. Performed Database Auditing and prepared database auditing checklist.• Analysing network traffic through Wireshark: Used the Wireshark packet sniffer to analyze the network traffic. Analyzed packets each for the different protocols like ARP, TCP, UDP, HTTP, DNS, etc. Show less

  • Experience

    • Aspiring Minds

      Feb 2019 - Aug 2019
      Software Developer

      • AMCAT: Worked in Aspiring Minds as a backend developer intern. Worked upon live product AMCAT. Learnt about Simple Queue Service (SQS). .

    • EY Technology Solutions

      May 2022 - Jun 2022
      Intern in Technology Consulting

      • Research on Zero Trust Architecture: In-depth study about different components of ZTA, what changes are needed, and implementation of the concept of “never trust always verify”.• Research on UK Data Reform Bill and its impact on Organizations and Clients: Researched about UK Data Reform Bill, why it is necessary, and why a transition from the UK GDPR to the UK Data Reform Bill is required.• Mapping of ISO 27001:2013 and ISO 27002:2022

    • EY

      May 2023 - now
      Technology Consultant

      • Conducted comprehensive threat modeling assessments for Web applications, APIs, Mainframes, Databases, Application Server and some cloud-based systems • Analyze threat boundaries, threat vectors and suggested the countermeasures for the corresponding threat found to ensure the confidentiality, integrity, and availability of information assets • Conducted vulnerability assessments to identify and remediate security weaknesses and ensured security best practices and ensured compliance with industry standards and regulations. • Performed Risk Assessment on various applications of a financial institute. • Developed threat models using industry-standard methodologies, such as STRIDE, DREAD, and attack trees. • Ensure proper protocols are implemented during data transfer. • Ensured encryption of data on the basis of Data classification at rest, motion and use. • Implemented threat modeling automation tools to streamline the process and improve efficiency. Show less

  • Licenses & Certifications

    • Introduction to Cloud Computing

      Coursera
      May 2021
      View certificate certificate
    • ISC2-CC

      ISC2
      Dec 2023
      View certificate certificate
    • Diploma in Informormation System Audit

      Indian Institute of Banking & Finance (IIBF)
      Dec 2023
    • Certificate Examination in IT security

      Indian Institute of Banking and Finance
      Aug 2023
    • Third Party Risk Management Professional

      OneTrust
      Nov 2024
    • SOX

      Sarbanes-Oxley Compliance Professionals Association (SOXCPA)
      Sept 2024
      View certificate certificate
    • National Institute of Technology Warangal

      National Institute of Technology Warangal
    • ISO 27001 Lead Auditor - Information Security Certification

      IRCA | International Register of Certificated Auditors
      Apr 2024
    • Prevention of cyber crime and Fraud Management

      Indian Institute of Banking and Finance
      Sept 2023