Location Bangalore - WFO
Core Application Security Skills
- Secure SDLC (SSDLC) implementation and integration
- Threat Modeling (STRIDE, DREAD, attack trees)
- Vulnerability Assessment & Penetration Testing (VAPT)
- Code Review for security flaws (SAST techniques)
- OWASP Top 10 deep expertise
- Business Logic Vulnerability identification
- API Security testing (REST, GraphQL)
Security Tools & Technologies
Static & Dynamic Testing
- SAST: Checkmarx, Fortify, Veracode, SonarQube
- DAST: Burp Suite, OWASP ZAP, Acunetix
- SCA (Dependencies): Snyk, Black Duck, WhiteSource
Runtime & DevOps Security
- Container security: Docker, Kubernetes (K8s security)
- CI/CD Security: Jenkins, GitHub Actions, GitLab CI
- Secrets management: HashiCorp Vault, AWS Secrets Manager
Programming / Technical Knowledge
- Solid in at least one:
- Python / Java / JavaScript / Go
- Secure coding practices:
- Input validation
- Authentication & authorization
- Cryptography basics (AES, RSA, hashing)
- Experience reviewing:
- Web apps (Java, .NET, Node.js)
- Microservices-based architecture
Cloud Security (Highly Preferred)
- AWS / Azure / GCP security fundamentals
- IAM roles, policies, least privilege
- Secure cloud architecture design
- Tools:
- AWS Security Hub
- Azure Defender
- GCP Security Command Center
Testing & Offensive Skills
- Manual penetration testing skills:
- XSS, SQL Injection, SSRF, CSRF
- Mobile app security basics (Android/iOS)
- Network fundamentals (TCP/IP, HTTP, DNS)
- Familiarity with:
- Metasploit, Nmap, Wireshark
Compliance & Standards
- OWASP ASVS
- PCI-DSS, ISO 27001 (basic understanding)
- GDPR / data privacy basics
- - Role & responsibilities
Interested Share your updated CV to:
[email protected]
Contact / WhatsApp: +91 95664 37666
📌 Hiring For Application Security Engineer - Bangalore- WFO (Karnataka)
🏢 Vee Healthtek
📍 Karnataka