Application Security

January 12, 2025
Application deadline closed.

Job Description

Roles and responsibilities:

Hands-on experience in conducting network security assessment and vulnerability assessment. (Web/Android/iOS)

• Conduct penetration testing, secure coding, secure coding reviews, application security assessments and application design reviews.

• Conduct and compile findings on new vulnerabilities.

• Conduct scanning and testing to find vulnerabilities in IoT devices.

• Conduct IoT penetration testing on various types of applications, networks, systems and infrastructure.

• Good understanding of OWASP Top 10 and Web Application Security Reviews.

Manual penetration testing skills and techniques are required along with automated tools and frameworks.

• Mobile Application Security Assessment. (iOS / Android)

• Good understanding of OWASP Top 10 for mobile applications.

• Create project deliverables/reports and assist direct supervisor during submissions.

• Analyze errors in the code and reduce damage during operation in production.

• Communicate with the concerned team to get better explanations for security issues and prepare security test reports for security observations.

• Conduct a security audit to reduce IT security risks.

• Preparing reports, reviewing supported documents

• Data verification and analysis with external audit

• Verify manual test reports on a quarterly basis with external application security audit.

The candidate must be able to:

• Proven experience in securing applications.

• Technical Knowledge – Deep understanding and knowledge of technical application security including threat modeling, security by design, secure coding and software assurance.

• Knowledge of common security libraries, controls, and common security flaws.

• Knowledge of architecture and design.

• Ideally five or more years of programming experience, with three or more years of application security engineering experience.

Required profile for candidates

Any nationality

Any graduation()

any

Education and Certificates

Bachelor of Engineering (BTech/B.E), MTech, MSc, MCA in IT related field

Any of the following certificates:

ECSA, OSCP, OSEP, CRTE, GIAC Penetration Tester (GPEN), CompTIA PenTest+, CRTP, CRTOP