03 Sep
|
SourceFuse Technologies
|
Sahibzada Ajit Singh Nagar
03 Sep
SourceFuse Technologies
Sahibzada Ajit Singh Nagar
Role Overview
In this role the candidate will be responsible to lead the team of cyber security pentesters & guide them to plan & execute authorized penetration tests. Co-ordinate with Project managers to ensure planning & execution of VAPT before production release of the applications. Ensure quality & timely delivery of the VAPT tests.
Act as a source of direction, training, and guidance for less experienced staff. Mentor and coach the IT security staff to provide guidance and expertise in their growth.
Key Responsibilities
- 7-8 years hands-on experience with VAPT of Web apps, Mobile apps, and APIs.
- Hands-on experience testing applications and infrastructure hosted on AWS - including AWS-specific misconfigurations (S3 bucket permissions, IAM policy weaknesses, security group/VPC exposure, exposed metadata endpoints, Lambda/API Gateway vulnerabilities, etc. ).
- Working knowledge of AWS security tooling/services (e. g. , AWS Inspector, GuardDuty, Security Hub) and how they factor into a pentest scope/report.
- Experience in Estimation, Planning, Execution of VAPT process (Both Automated & Manual) on all assets, including cloud-hosted assets.
- Consult with application developers, systems administrators, and management to demonstrate security testing results, explain the threat presented by the results, and consult on remediation.
- Experience providing advice on how to minimize risks and, on methods to fix or lower security risks to application and cloud infrastructure.
- Experience in creating Test Plans and Test Outcome Reports, Estimate and Monitor Test Effort, Defect Management and Co-ordination.
- Experience in Project Governance - Estimate Effort, Deploy and Manage Resources, Arrange Trainings as needed, Define Scope of Testing, Ensure implementation of test process,
Quality Assurance, Control Effort and Schedule Deviation.
- Experience in Monitoring, Measurement, Controlling and Reporting on the test progress.
- Experience in Team Management - Mentor team members, assign workload, utilise different skillsets.
- Experience maintaining the Pentest methodology and supporting documentation/processes.
- Strong hands-on expertise with Burp Suite (Skilled) as the primary testing tool, along with SQLmap, Nmap, Metasploit, MobSF, Objection, etc.
- Hands-on experience with testing frameworks such as PTES and OWASP (Web Top 10, Mobile MASTG, API Top 10).
- Applicable knowledge of Windows client/server, Unix/Linux systems, Mac OS X, VMware/Xen, and cloud technologies - primarily AWS, with working familiarity of Azure or Google Cloud a plus.
- Prior experience in software development preferred - aids in understanding application logic and code-level vulnerabilities, and enables more effective remediation conversations with dev teams.
- Curiosity to learn & adopt emerging technologies.
- Certifications such as Burp Suite Certified Practitioner, CEH, OSCP, OSCE, or AWS Security-related certifications (e. g. , AWS Certified Security - Specialty) are preferred.
Behavioural Competencies:
- Good Communication Skills
- Team Management
- Critical thinker and problem solver
- Quick Learner
- Time Management
- Adaptability
- Detail Oriented
- Self-Starter
Experience Level:
- Relevant Experience should be 7-8 years.
Educational Competency:
- BCA/MCA/B. Tech.
Interview Process
- 2 Technical Rounds
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 Security Testing Lead (Sahibzada Ajit Singh Nagar)
🏢 SourceFuse Technologies
📍 Sahibzada Ajit Singh Nagar