Security Testing Engineer (Bengaluru)

Security Testing Engineer (Bengaluru)

24 Sep
|
CGI
|
Bengaluru

24 Sep

CGI

Bengaluru

Role & responsibilities

Experience: 4-6 yrs in Security testing

Category:

Shift: Normal

Location: BNG/HYD

Position ID:

Employment Type: Full Time

Education Qualification: BE/MCA

Position Description: Sr. Security Tester (Penetration Tester) is responsible for identifying and exploiting vulnerabilities in systems, applications to assess the security posture of the application. This role involves conducting ethical hacking exercises, vulnerability assessments, simulate real-world attacks and provide actionable recommendations for remediation.

Responsibilities:

- 4-5 years of experience in vulnerability assessment and penetration testing (VAPT) of applications.
- Strong knowledge of the OWASP, SANS top 25, WASC security Standards and detailed knowledge of common web application attack vectors such as SQL injection, CSRF, XSS, Session Management issues, Direct Object reference, Click jacking, buffer overflows, etc. Mandatory skill set:
- Experience in performing application security testing using manual techniques and automated tools.
- Experience in automated web application vulnerability scanners (e.g., AppScan, Web inspect, Acunetix, Burpsuite Pro, Nmap, SQLMap, etc.) is desirable
- Good understanding of web application architecture and Secure development life cycle(SDLC)
- Thorough understanding common web technologies like .NET, PHP, Java, XML, SAML, SOA, SOAP,



web services etc and protocols including HTTP(S), DNS, FTP, SSH etc.
- Experience in threat modeling and risk analysis.
- Experience in performing web services, APIs security testing. Additional Skills:
- Experience in static and energetic secure code review.
- Experience in manual application penetration testing thick client applications, mobile applications.
- Should have manual mobile application penetration testing performed on platforms like Android, IOS etc.

Must-Have Skills: 4+ years of experience in penetration testing or ethical hacking for both Web, API and Mobile.

Proficiency with tools such as Burp Suite, Nmap, Nessus, Acunetix, etc.

Strong understanding of OWASP, SANS top 25, WASC security Standards and detailed knowledge of common web application attack vectors such as SQL injection, CSRF, XSS, Session Management issues, Direct Object reference, Click jacking, buffer overflows, common attack vectors etc.

Experience with scripting languages (Python, Bash, PowerShell).

Familiarity with cloud platforms (AWS, Azure, GCP) and their security models.

Excellent analytical, problem-solving, and communication skills.

Good-to-Have Skills: Certifications such as CEH, OSCP or similar are highly desirable

Preferred candidate profile

📌 Security Testing Engineer (Bengaluru)
🏢 CGI
📍 Bengaluru

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: security testing engineer (bengaluru) / bengaluru