23 Aug
|
Orcapod Consulting Services
|
Bengaluru
23 Aug
Orcapod Consulting Services
Bengaluru
Job Title
Penetration Testing Engineer
Location- Bangalore
Work mode- Hybrid
Notice period- Immediate joiner/15 days or less
Skills to Evaluate
Penetration Testing, OWASP, Web Application Security Testing
Experience
4 to 6 Years
Location
Bengaluru
- Experience in the range of 4-6 years.
- Hands-on experience with testing frameworks in line with Web App, Mobile, Web Services/APIs, Network.
- Experience with Open Web Application Security Project (OWASP), Open-Source Security Testing Methodology Manual (OSSTMM) methodologies and tools.
- Work closely with application, network and infrastructure teams when performing tests against current or existing systems
- Use manual techniques to exploit identified vulnerabilities like cross-site scripting, SQL injections, session hijacking and buffer overflows to obtain controlled access to target systems
- Validate vulnerability assessment results where appropriate, prioritize the remediation requirements and work with network, infrastructure and desktop teams to address security problems
- Perform exploit analysis for identified vulnerabilities manually, with custom scripts or use tools such as Metasploit
- Work closely with the application development teams, technology teams and the other members of the Information Security team to identify and remediate security issues as part of Incident Response
- Be a part of the SDLC process for testing new application systems/infrastructure
- Participate in multiple organizational areas such as security architecture and design, service delivery, training and client communication.
- Create, maintain and report metrics that measure effectiveness of various security controls.
- Document areas of significant exposure to information systems and recommend solutions.
- Develop and maintain a formal reporting process highlighting results, conclusions, and recommendations which can be viewed by peers and senior management
- The ability to articulate risks and findings to management
- Experience in preparing a security threat model and associated test plans.
- Experience in translating complex security threats to simpler procedures for web application developers, systems administrators, and management to understand security testing results.
- Knowledge of current information security threats. Good understanding of coding best practices and standards.
- In-depth knowledge of application development processes and at least one programming or scripting language (e.g., Java, Scala, C#, Ruby, Perl, Python, PowerShell) is preferred.
- Critical thinking and valuable problem-solving abilities.
- Organized planning and time management skills are preferred.
- Certification on CEH (Certified Ethical Hacker) or OSCP (Offensive Security Certified Professional) is desirable.
- Bachelors degree in Computer Science, Information Technology, or a related field.
- Proficiency in using penetration testing tools such as Burp Suite, Metasploit, Nessus, and others.
- Strong understanding of networking protocols, web application architectures, and operating systems.
- Excellent problem-solving skills and attention to detail.
- Effective communication skills, both written and verbal, to articulate security issues clearly to non-technical stakeholders.
Education Qualificaiton B-Tech or Relevant
Roles & Responsibilities
- Conduct thorough penetration testing on applications, networks, and systems to find vulnerabilities that could be exploited by cyber attackers.
- Collaborate with development teams to understand the technical architecture and identify potential security risks.
- Develop detailed reports outlining findings from penetration tests, including risk assessments and remediation recommendations.
- Stay updated on the latest security trends, vulnerabilities, and attack vectors to enhance testing methodologies.
- Assist in the overall security assessment process, including threat modeling and security audits.
- Participate in security incident response and remediation activities when needed.
- Provide training and knowledge sharing with team members regarding security best practices and findings.
📌 Penetration Testing Engineer (Bengaluru)
🏢 Orcapod Consulting Services
📍 Bengaluru