06 Oct
|
Indusface
|
Bengaluru
06 Oct
Indusface
Bengaluru
Job Description
- Design and develop vulnerability detection modules for Indusface's Haiku DAST scanner to identify web application and API security flaws.
- Research evolving web attacks, CVEs, and evasion techniques targeting web apps and APIs, and translate them into scanner detection logic and test payloads.
- Leverage AI tools and models (LLM-assisted coding, agentic pipelines, ML-based triage) to build detection logic and tooling faster and handle the growing volume of vulnerabilities, CVEs, and scan data in the AI era.
- Build and improve crawling/discovery logic (including authenticated, SPA/JS-heavy, and API-driven applications) to increase scan coverage.
- Improve scan accuracy reduce false positives/negatives, tune confidence scoring, and validate detection logic against real-world applications.
- Design and prototype new scanner capabilities such as authenticated scanning, API/GraphQL scanning, and business-logic testing.
- Outstanding problem-solving and troubleshooting skills are a must, as solutions to many problems might not be obvious.
- Drive the end-to-end release process for scanner engine updates and new detection modules.
- Coordinate with DevOps/Release teams to validate rollout on staging and production.
- Monitor post-release scan quality and lead fixes for regressions, missed detections, or false-positive spikes.
- Troubleshoot customer scan issues, provide timely solutions, and write RCAs wherever necessary.
- Develop security tools and automation to reduce manual/repeated work and increase efficiency of the scanning pipeline.
Candidate Profile
- 4+ years of experience in vulnerability research/analysis and hands-on DAST/dynamic scanner or VAPT tool development.
- AI models, tooling using Agentic AI
- Good understanding of:
- Web application and API architectures,
crawling/spidering techniques
- Network security, network layers (OSI Layer-3 and Layer-4)
- Protocols like TCP/IP, DNS, HTTP, HTTPS, SSH, WebSockets
- Web application penetration testing techniques
- Identifying and mitigating web/network vulnerabilities and explaining how to prevent them
- Programming languages like Python, C/C++, or Java
- Hands-on experience in:
- Research on 0-days, critical vulnerabilities, exploits in the wild, and discovering recent vulnerabilities
- Web-app security (SQL Injection, XSS, CSRF, SSRF, IDOR, etc.), OWASP Top 10, OWASP API Top 10, SANS Top 25
- DAST/scanner tools: Burp Suite, OWASP ZAP, Nessus, Qualys, Acunetix, or similar
- Network analysis tools like tcpdump, Wireshark, and assisting tools like debuggers, hex editors, etc.
- Crafting regular expressions for detection logic, and verification & validation of findings
- Building or extending scanner engines, plugins, or crawler modules
- Analyzing existing or writing new POCs for vulnerabilities
- Headless browser automation (Selenium/Playwright) for crawling JavaScript-heavy applications
- Experience with ML-assisted detection or behavioral models for reducing false positives is a plus
- Contributions to open-source security tools or research publications
- Certifications (e.g., OSWE, GWAPT, CEH, CISSP) are a plus
- Effective written and verbal communication skills.
Good to Have
- Knowledge of API security testing (REST/GraphQL/SOAP) and authentication/session-handling edge cases.
- Understanding of Lua, Nginx, Apache.
- Developing security-related tools/programs.
- Knowledge of cloud infrastructure services and virtualization software (VMware, VirtualBox, Xen, etc.).
- Experience in any of Java, TestNG, Linux scripting, shell scripting, Python, Perl.
- Experience/knowledge of Amazon Web Services (AWS).
📌 Security Researcher/ Threat Researcher (Bengaluru)
🏢 Indusface
📍 Bengaluru