Suggestions
Subham Misra
Cloud and Container Security Engineer
Subham Misra is a skilled professional with expertise in a variety of cybersecurity domains, including Cloud Native Security, Web and Mobile Security, Red Teaming, IoT Security, Cloud Security, and API Security.
In Cloud Native Security, Subham specializes in building and designing Container security solutions, CSPM (Cloud Security Posture Management), and automating security in CI/CD pipeline environments.
With a focus on Web and Mobile Security, Subham is proficient in assessing enterprise-level sensitive legacy and modern technology-rich API-based web applications. Additionally, he has extensive experience in assessing Mobile applications for both Android and iOS platforms, utilizing SAST and DAST techniques.
Subham has a background in Red Teaming, having conducted assessments for clients with enterprise Active Directory setups. His expertise includes using methodologies like assume breach and adversarial simulation to assess security. He is knowledgeable in executing techniques such as Kerberoasting and Golden and Silver ticket hash replay attacks, and proficient in using tools like BloodHound and Mimikatz.
In IoT Security, Subham has performed Firmware analysis using tools like Firmadyne and binwalk. He possesses a deep understanding of attacks on BLE protocol and Zigbee-based devices and has experience with tools like Gattacker, Bettercap, and btlejuice. Notably, he recently conducted an assessment of a popular SmartWatch device, uncovering critical security issues.
Subham has also conducted Cloud Security assessments, identifying vulnerabilities such as unauthorized access to sensitive data in S3 buckets, misconfigurations in OAuth Identity provider setups for third-party applications, and insecure Docker registries.
Experienced in API Security, Subham has developed REST APIs and has expertise in assessing APIs following the OWASP Top 10 for API vulnerabilities. He has identified vulnerabilities like Broken Object & Function level Authorization, Excessive data exposure, and Broken authentication in JWT implementations.
Subham Misra holds a Bachelor of Technology in Computer Science and Engineering from West Bengal University of Technology, Kolkata. He has worked as a Cloud Security Engineer at Cisco and previously held roles as a Consultant, Senior Analyst, and Advisory Trainee at PwC India.