Carlos Ramirez
@carlosramirez4
Application Security professional specializing in DAST, vulnerability testing, and IAM-focused access governance.
What I'm looking for
I’m an Application Security professional specialized in Application Security with 3+ years of experience in DAST, web application testing, vulnerability analysis, and IAM processes. I bring a strong analytical mindset, attention to detail, and a passion for learning emerging security technologies.
As a Dynamic Security Auditor at OpenText, I performed 3–5 daily automated and manual web application vulnerability scans using WebInspect and Burp Suite. I configured automated scans per client requirements, validated findings, and reduced false positives while improving reporting accuracy with risk severity level classification.
I also conducted manual testing across Authentication/Session, Access Control, Business Logic, and Input Validation, using attacks such as XSS, SQL Injection, and privilege escalation. In addition, I completed basic API testing using Postman and Burp Suite.
Before that, I worked as a Systems Security Administrator I, executing IAM procedures to support access governance by reviewing roles, privileges, and user accounts to prevent unauthorized access. Earlier, as a Tier II Fortify Technical Support Engineer, I supported Fortify products (WebInspect, Static Code Analyzer), performed static and dynamic security testing, and troubleshot issues across networks, databases, and application code while producing reports aligned with OWASP Top 10.
Experience
Work history, roles, and key accomplishments
Performed 3–5 daily automated and manual DAST web application vulnerability scans using WebInspect and Burp Suite, configuring scan settings to client requirements and improving reporting accuracy by reducing false positives. Conducted manual testing across authentication/session, access control, business logic, and input validation (e.g., XSS, SQL injection, privilege escalation) and performed ba
Executed IAM procedures to support access governance by reviewing roles, privileges, and user accounts to prevent unauthorized access. Processed BAU requests in Active Directory and O365, verifying approvals and compliance with corporate security policies for permission and account changes.
Fortify Support Engineer (Tier II)
Micro Focus
Aug 2017 - Nov 2018 (1 year 3 months)
Provided Tier II technical support for Fortify products (WebInspect and Static Code Analyzer) via email, phone, and remote sessions, including performing static and dynamic application security testing. Troubleshot complex issues across networks, databases, and application code using logs and reproduction, and produced reports aligned with OWASP Top 10.
Education
Degrees, certifications, and relevant coursework
EC-Council
CEH (Certified Ethical Hacker), Cybersecurity
CEH (Certified Ethical Hacker) certification is currently in progress.
PortSwigger Web Security Academy
Course, Web Security
2026 -
Training with PortSwigger Web Security Academy starting 02/2026.
Splunk
Splunk Fundamentals 1, Splunk
2020 -
Completed Splunk Fundamentals 1 training in 02/2020.
Microsoft
SQL Server for Developers, SQL Server
2018 -
Completed SQL Server for Developers training in 08/2018.
Universidad Fidelitas
Bachelor, Systems Engineering
2017 -
Bachelor’s studies in Systems Engineering starting in 05/2017 at Universidad Fidelitas (San Pedro).
Tech stack
Software and tools used professionally
Availability
Location
Authorized to work in
Job categories
Skills
Interested in hiring Carlos ?
You can contact Carlos and 90k+ other talented remote workers on Himalayas.
Message CarlosFind your dream job
Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!
