We are seeking a skilled Application Security Engineer with a primary focus on Mobile Application Security and Security Testing. The ideal candidate will have a solid background in web and mobile application security, along with expertise in conducting penetration testing for both applications and APIs. As part of our dynamic team, you will be responsible for evaluating and enhancing the security posture of our clients' applications, APIs, and cloud configurations on platforms like Azure and AWS.
Primary Responsibilities
- Conduct comprehensive Web/Mobile application and API Penetration Testing, including Cloud configuration reviews on Azure/AWS platforms.
- Demonstrate expert-level understanding of application security concepts, both in technical implementation and procedural protocols.
- Utilize automated Vulnerability Assessment (VA) tools alongside manual penetration testing techniques.
- Hands-on experience with DAST tools such as Rapid7, BurpSuite Pro, CloudSploit, and ScoutSuite.
- Automate penetration testing tasks, including importing API specifications (Swagger, Open API, etc.) into testing tools.
- Interpret penetration testing results, provide detailed scoping, organize protests, and utilize vulnerability management tools effectively.
- Offer remediation recommendations to developers, including analysis of false positives and preparation of comprehensive security testing reports.
- Apply OWASP Risk rating methodology for accurate vulnerability reporting.
- Conduct reviews of Security Architecture controls, providing valuable insights into enhancing security measures.
- Flexibility to work in shifts spanning from 2 PM IST to 11 PM IST.
- Possesses end-to-end knowledge and experience in testing, including test planning, strategy, and estimation.
- Demonstrate excellent communication and client handling skills, with the ability to effectively interact with stakeholders.
- Proficiency in one or more scripting languages and automation tools.
- Utilize analytical skills for problem-solving and effective client interfacing, with a focus on stakeholder management.
- Knowledge of SDLC and Agile methodologies, ensuring alignment with security practices throughout development cycles.
- Exhibit project and team management capabilities, fostering a collaborative environment for achieving security objectives.
Qualifications
- Bachelor's degree in Computer Science, Information Technology, or a related field.
- 3-8 years of relevant experience in Application Security, with a focus on Mobile Application Security and Security Testing.
- Deep understanding of web application vulnerabilities (OWASP, SANS25) and industry-standard security procedures/guidelines.
- Proven track record in security testing, with expertise in both automated VA and manual penetration testing techniques.
- Strong understanding of cloud platforms such as Azure and AWS, with experience in reviewing cloud configurations for security vulnerabilities.
- Certification in relevant areas such as CEH, CISSP, or equivalent is highly desirable.
- Demonstrated ability to manage multiple projects simultaneously and deliver results within specified timelines.
- Strong attention to detail, with a commitment to maintaining the highest standards of security excellence.
Join our team and contribute to safeguarding the digital assets of our clients with your expertise in Application Security and Penetration Testing. Apply now to be part of our innovative and dynamic cybersecurity environment.