Job Title : Application Penetration Tester
We are seeking a highly skilled and experienced Application Penetration Tester to join our dedicated cybersecurity team in Chennai. In this critical role, you will be at the forefront of our defense strategy, responsible for proactively identifying, exploiting, and mitigating advanced security vulnerabilities across our diverse digital landscape.
Key Responsibilities :
- Conduct comprehensive penetration tests across a variety of platforms, including web applications, mobile (Android / iOS), APIs, cloud infrastructure, and internal networks.
- Utilize a combination of industry-standard tools (e.g., Burp Suite, Metasploit, Nessus, Nmap) and custom-developed scripts to perform in-depth security assessments.
- Perform advanced security assessments, including red teaming and black box testing, to simulate real-world attack scenarios and identify sophisticated threats.
- Develop custom exploit code and proof-of-concept scripts to demonstrate the potential impact of identified vulnerabilities to key stakeholders.
- Create detailed, actionable reports on findings and present clear remediation strategies to development and business teams.
- Collaborate with engineering and cross-functional teams to embed security best practices and secure coding principles into the software development lifecycle (SDLC).
Required Skills and Qualifications :
Experience : 6-8 years of hands-on experience in application and infrastructure penetration testing.Technical Expertise :
Advanced proficiency in penetration testing methodologies, including red teaming, black box testing, and advanced exploitation techniques.Expert-level experience with core penetration testing tools like Burp Suite, Metasploit, Nessus, and Nmap.Demonstrated experience testing web applications, APIs, mobile platforms (Android / iOS), and cloud environments.In-depth knowledge of cryptography, secure coding practices, and secure architecture design principles.Preferred Qualifications :
Offensive Security Certified Professional (OSCP) is highly desirable, but not mandatory.Experience in developing custom tools or scripts for security testing.(ref : hirist.tech)