- Perform Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) using industry-standard tools.
- Conduct manual and automated secure code reviews across multiple programming languages.
- Execute infrastructure penetration testing (network, cloud, and on-prem environments).
- Perform API penetration testing including REST and SOAP services.
- Conduct Thick Client (desktop application) security testing.
- Identify, validate, and report security vulnerabilities with explicit remediation guidance.
- Develop and implement threat models for applications and systems.
- Collaborate with development, DevOps, and product teams to integrate secure SDLC practices.
- Support security assessments, audits, and compliance requirements.
- Stay updated with emerging threats, vulnerabilities, and security best practices.
- Mentor junior team members and contribute to knowledge sharing.
Strong hands-on experience with:
- SAST tools (e.g., Checkmarx, Fortify, SonarQube)
- DAST tools (e.g., Burp Suite, OWASP ZAP)
- Deep understanding of:
- OWASP Top 10, SANS Top 25
- Secure coding practices
Must have:
proven experience in Infrastructure Security, such as infrastructure vulnerability assessments, server and network security, security configuration reviews, cloud/infrastructure security, or related areas.
Preferred candidate profile
- 4 to 8 years of experience in application security and penetration testing.
- Immediate joiners are highly preferred.
- Candidates should be based in or willing to work from Bangalore.