Company Description
TwinTech Solutions is a leading Digital Defense Consulting and Services firm specializing in advanced cybersecurity solutions. With over two decades of experience, our team holds prestigious accreditations such as GPEN, OSCP, CISSP, and ISO 27001, ensuring expertise across the cybersecurity domain. We adopt a client-focused approach to identify and mitigate organizational risks, delivering tailor-made solutions. Renowned for exceptional service quality, TwinTech Solutions is committed to driving impactful security measures for businesses worldwide.
Role Description
We are looking for a motivated Web Application Security Tester to join our security team. This role is ideal for candidates who are passionate about application security, ethical hacking, and vulnerability assessment. You will work with senior security engineers to identify, analyze, and report security weaknesses in web applications.
Key Responsibilities
- Perform vulnerability assessments and basic penetration testing of web applications under guidance.
- Identify common security issues such as SQL injection, XSS, CSRF, authentication flaws, and access control weaknesses.
- Use standard security testing tools (Burp Suite, OWASP ZAP, Nmap, etc.) for analysis.
- Document findings clearly with evidence, impact, and recommended remediation steps.
- Assist in retesting vulnerabilities after fixes are deployed.
- Learn and follow secure coding and testing practices based on OWASP Top 10 and industry standards.
- Support the team in research, proof-of-concept creation, and internal security reviews.
Required Skills
Basic understanding of web technologies ( HTML, CSS, JavaScript).Familiarity with OWASP Top 10 and common web application vulnerabilities.Hands-on exposure (even academic or self-taught) with tools like Burp Suite, Nmap, DirBuster, Postman, etc.Good analytical thinking and curiosity to explore security weaknesses.Strong written documentation skills.Preferred (Not Mandatory)
Any internship or project experience in web security / pentesting.Certifications such as CEH, eJPT, Security+, or self-learning badges.Basic understanding of Linux and scripting.