Penetration Testing, OWASP, Web Application Security Testing
Experience
4 to 6 Years
Location
Bengaluru
Job Description
- Experience in the range of 4-6 years.
- Hands-on experience with testing frameworks in line with Web App, Mobile, Web Services/APIs, Network.
- Experience with Open Web Application Security Project (OWASP), Open-Source Security Testing Methodology Manual (OSSTMM) methodologies and tools.
- Work closely with application, network and infrastructure teams when performing tests against new or existing systems
- Use manual techniques to exploit identified vulnerabilities like cross-site scripting, SQL injections, session hijacking and buffer overflows to obtain controlled access to target systems
- Validate vulnerability assessment results where appropriate, prioritize the remediation requirements and work with network, infrastructure and desktop teams to address security problems
- Perform exploit analysis for identified vulnerabilities manually, with custom scripts or use tools such as Metasploit
- Work closely with the application development teams, technology teams and the other members of the Information Security team to identify and remediate security issues as part of Incident Response
- Be a part of the SDLC process for testing recent application systems/infrastructure
- Participate in multiple organizational areas such as security architecture and design, service delivery, training and client communication.
- Create, maintain and report metrics that measure effectiveness of various security controls.
- Document areas of significant exposure to information systems and recommend solutions.
- Develop and maintain a formal reporting process highlighting results, conclusions, and recommendations which can be viewed by peers and senior management
- The ability to articulate risks and findings to man