This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
User:Jvermont
From OWASP
Jesse Vermont Application Security Engineer/Penetration Tester
Jess brings over 20 years of hands-on, professional experience in software development to his work and knowledge base as an Application Security Engineer and Penetration Tester.
Having spent over a decade (13 years to be specific) as a professional Java/J2EE developer and another 8 years as a .Net (ASP.Net/C# and VB.Net) developer he has an outstanding knowledge of the languages with which he works as a Security Engineer.
Additionally he has over a decade of hands-on, professional experience in the 'Front-End' web technologies stack (JavaScript, HTML/CSS) and has a professional focus as an Application Security Engineer in AJAX/JavaScript, Java and ASP.Net; Jess is also primarily focused on Java Secure Coding/Security issues and can readily perform and has extensive experience in manual secure code reviews in the core Java language and the J2EE APIs.
Additionally Jess has 3 years Python scripting experience which he has used extensively write custom scripts for automated secure testing purposes;
Jess acted as Subject Matter Expert at a previous position in Web Technologies, Secure Code Reviews, IBM’s AppScan and OWASP’s ZAP; has outstanding knowledge of the OWASP Top 10, the ESAPI and other OWASP initiatives;
Among his skill set and experience includes manual secure code reviews in the aforementioned languages; Vulnerability Scanning and Web Application Penetration Testing as well as extensive experience with Fortify Static, Dynamic and Hybrid scans and analysis. Jess can and has worked closely with development teams in both Waterfall and Agile methodologies to ensure the delivery of as secure a code base as possible.
Programming/Scripting/Markup Languages:
Python Java HTML JavaScript XML ASP.Net/C#/Visual Basic/VB.Net CSS C++ ColdFusion Perl XAML
Professional Certificates: Web Applications Penetration Tester – InfoSec Institute Certified Security Testing Engineer – Fishnet/7Safe Certified Web Application Pen Tester – eLearn Security Certified Web Applications Developer – Washington University C.A.I.T
Operating Systems:
Kali Linux BackTrack 5 Linux, various flavors Windows, various Unix, various