16 Aug
|
Cyberpwn
|
Bengaluru
16 Aug
Cyberpwn
Bengaluru
ROLE OVERVIEW
Execute hybrid and automated application penetration testing across the client application portfolio, covering scan configuration, finding validation, retest verification, and remediation tracking. This is a hands-on delivery role with structured progression toward Senior Engineer.
KEY RESPONSIBILITY AREAS (KRA)
- Execute hybrid and fully automated penetration testing across web applications and APIs in line with the agreed testing schedule.
- Configure and operate authenticated and unauthenticated dynamic application security testing using Fortify on Demand, OWASP ZAP, Burp Suite, and Qualys WAS.
- Validate and triage automated scan output, eliminate false positives, and confirm exploitability before findings are reported.
- Assign severity to findings using CVSS and application context, and prepare findings for peer review.
- Produce penetration test reports with OWASP-mapped findings, reproduction steps, and remediation guidance.
- Perform retest validation following remediation closure and document whether fixes are effective.
- Support Senior Engineers on manual testing of critical applications, taking ownership of defined test areas.
- Maintain scan configurations, authentication profiles, and application inventory records to ensure accurate testing scope.
- Track application security findings through to closure in the client workflow system and escalate at-risk items ahead of SLA breach.
- Support walkthrough sessions with development teams and capture remediation actions and owners.
- Contribute to the application testing schedule, coverage tracking, and monthly application security reporting inputs.
- Participate in shadowing, reverse-shadowing, and assisted-operation phases of knowledge transfer during mobilisation and transition.
KEY PERFORMANCE INDICATORS (KPIs)
- Assessment execution rate against the planned testing schedule.
- Report delivery timeliness following completion of testing.
- False-positive rate in reported findings.
- Severity rating precision, measured by severity upheld on peer review.
- Retest completion timeliness following receipt of remediation evidence.
- Application testing coverage contribution against the annual portfolio plan.
- Timeliness of escalation for at-risk findings ahead of SLA breach.
- Accuracy and timeliness of reporting inputs and coverage tracking.
REQUIRED TECHNICAL SKILLS & EXPERIENCE
- Hands-on application penetration testing experience across web applications and APIs.
- Working knowledge of OWASP Top 10 and OWASP API Security Top 10, with practical testing experience against each category.
- Proficiency with Burp Suite and OWASP ZAP for manual request manipulation and guided testing, with exposure to Fortify on Demand or Qualys WAS an advantage.
- Understanding of CVSS v3.x scoring and the application context factors that influence severity.
- Working understanding of authentication and session management technologies including OAuth, JWT, and SAML.
- Basic scripting (Python, PowerShell, or Bash) for test support, data handling, and report automation.
- Familiarity with IT service management and ticketing tools, with ServiceNow and Azure Boards preferred, for finding lifecycle tracking.
- Explicit written and verbal communication for reporting findings and coordinating with development teams.
WORKING ENVIRONMENT & CONDUCT
- Onsite presence at the client delivery centre in Bangalore five days per week is a mandatory condition of the role.
- Candidates must meet client-defined competency, certification, background verification, and conduct standards prior to onboarding.
PREFERRED / EXPECTED CERTIFICATIONS
- CompTIA Security or equivalent foundational security certification
- Burp Suite Certified Practitioner or eWPT (preferred)
- OSCP (preferred, not mandatory)
- CEH (preferred, not mandatory)
EDUCATIONAL QUALIFICATION
Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field (or equivalent practical experience).
📌 AppSec Engineer (Bengaluru)
🏢 Cyberpwn
📍 Bengaluru