We are looking for an experienced in Manual Penetration Testing , Secure Code Review , and Mobile Application Security Testing . The ideal candidate should have hands-on experience identifying security vulnerabilities, performing code reviews, and working with industry-standard application security tools.
Key Responsibilities
- Perform manual application penetration testing on:
- Web Applications
- Mobile Applications (Android/iOS)
- APIs
- Internal Applications
- Internal & External Networks
- Conduct manual secure code reviews for applications developed in Java and C# .
- Perform Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) .
- Identify, validate, and exploit security vulnerabilities.
- Explain security issues, including:
- IDOR
- Second-Order SQL Injection
- CSRF
- Root Cause Analysis
- Remediation Recommendations
- Prepare technical reports and communicate findings to both technical and non-technical stakeholders.
- Work closely with development teams during vulnerability remediation.
- Evaluate and adopt recent security tools and technologies as required.
Required Skills
- 4–6 years of experience in Application Security
- Minimum 3 years of hands-on experience in:
- Manual Web Application Penetration Testing
- API Security Testing
- Mobile Application Penetration Testing (Android or iOS)
- Secure Code Review
- Strong understanding of:
- OWASP Top 10
- Secure Coding Practices
- Vulnerability Assessment & Penetration Testing (VAPT)
- SAST & DAST
Security Tools Hands-on experience with one or more of the following:
- Burp Suite
- OWASP ZAP
- IBM AppScan
- Acunetix
- Netsparker
- Checkmarx
- Veracode
- Kali Linux