17 Aug
|
SourceFuse
|
Punjab
Source Fuse Technologies hiring Security Tester with 3-5 years of experience.
Overview:
We are looking for a skilled and proactive Security Tester / VAPT Engineer with hands-on experience in performing security assessments across multiple platforms including Web Applications, Mobile Applications (Android & i OS), APIs, Network Infrastructure, and AI/LLM-based systems.
The candidate should possess strong knowledge of offensive security techniques, secure development practices, and up-to-date attack vectors. The role involves identifying vulnerabilities, validating exploitability, providing remediation guidance, and supporting secure product
development initiatives.
Key Responsibilities:
Web Application Security Testing
● Perform comprehensive VAPT for web applications using manual and automated techniques.
● Identify vulnerabilities such as:
○ OWASP Top 10
○ Authentication & Authorization flaws
○ Business logic issues
○ SSRF, SSTI, XXE, CSRF, RCE, IDOR, etc.
● Conduct secure configuration reviews and threat analysis.
● Validate remediation fixes and provide detailed reports.
Mobile Application Security Testing (Android & i OS)
● Conduct security assessments of Android and i OS applications.
● Perform:
○ Static & Dynamic Analysis
○ Runtime instrumentation
○ Reverse engineering
○ SSL pinning bypass
○ Root/Jailbreak detection bypass
○ Local storage & keychain analysis
● Analyze APK/IPA files and identify insecure implementations.
● Use tools such as Burp Suite, Frida, Objection, Mob SF, JADX, Hopper, Ghidra, etc.
API Security Testing
● Perform security testing for REST, Graph QL, SOAP, and g RPC APIs.
Identify vulnerabilities such as:
○ Broken Object Level Authorization (BOLA)
○ Broken Authentication
○ Injection attacks
○ Rate limit bypass
○ Sensitive data exposure
● Validate API authentication mechanisms including OAuth, JWT, API Keys, etc
Cloud Security Assessment
● Perform security assessments of cloud environments across AWS, Azure, a
📌 Security Tester (Punjab)
🏢 SourceFuse
📍 Punjab