Summary
Overview
Work History
Education
Skills
Accomplishments
Timeline
Generic

Claudiu Tananau

Application Security Engineer
Bucharest,B

Summary

In my work, I excelled as an Application Security Analyst, mastering vulnerability assessments and advanced code review, particularly in CxQL queries and software security protocols. My proactive collaboration with clients and ability to convey complex security measures effectively showcase my technical expertise and strong communication skills. Achievements include significantly enhancing application security through customized mitigation strategies.

Overview

3
3
years of professional experience
2
2
Languages

Work History

Application Security Analyst

QualiTest
06.2021 - 06.2024

Vulnerability Assessment

  • Utilized the Common Vulnerability Scoring System (CVSS) to assess and prioritize vulnerabilities in client applications.
  • Conducted thorough vulnerability assessments to identify security weaknesses and potential exploitation paths.

Advanced Code Review

  • Performed in-depth code reviews within a Static Application Security Testing (SAST) environment to detect security flaws.
  • Analyzed source code for vulnerabilities such as SQL injection, cross-site scripting (XSS), and other common security issues.

Mitigation Recommendations

  • Provided actionable mitigation strategies and recommendations to clients for True Positive findings.
  • Ensured clients' applications were secure by advising on best practices and secure coding standards.

Manual Analysis and Custom Queries

  • Manually reviewed and added security findings that were not initially detected by automated tools, enhancing the accuracy and thoroughness of security assessments.
  • Created and utilized custom CxQL (Checkmarx Query Language) queries to identify complex vulnerabilities.

Client Collaboration and Reporting

  • Communicated effectively with clients to explain security findings, the potential impact of vulnerabilities, and recommended remediation steps.
  • Prepared detailed security reports summarizing assessment results, including identified vulnerabilities, risk levels, and suggested fixes.

Education

No Degree - Computer And Information Sciences

WellCode
Bucharest, Romania
04.2001 -

Bachelor's Degree - Foreign Languages And Literatures

University of Bucharest
Bucharest, Romania
04.2001 -

Skills

    Vulnerability Assessment

    Software security protocols and knowledge

    OWASP Software Security knowledge

    C (Algorithms & Data Structures)

    Python – Django (personal project experience)

    Java- OOP & Algorithms

    SQL Databases

    JavaScript, HTML, CSS

    CxQL queries

Accomplishments

    SPOTLIGHT AWARD


    In May 2022 I received the Spotlight Award directly from the CEO Anbu Muppidathi for my exemplary performance, dedication, team spirit, and results-driven approach which make Qualitest stronger in the industry.

Timeline

Application Security Analyst

QualiTest
06.2021 - 06.2024

No Degree - Computer And Information Sciences

WellCode
04.2001 -

Bachelor's Degree - Foreign Languages And Literatures

University of Bucharest
04.2001 -
Claudiu TananauApplication Security Engineer