Job Description :
The Ethical Pen Testing Leader will join a dynamic team of world class security experts to conduct application security/penetration tests of our internal/external web, mobile, and web API service applications, leveraging both manual techniques as well as automated tools to uncover and report security vulnerabilities that exist.
You must be knowledgeable with business risks associated to common security vulnerabilities and to be able to effectively communicate complex technical concepts such as security vulnerabilities to application developers and/or senior managers who may have little to no experience with application security.
You must have the ability to work independently in a very large scale, enterprise setting and collaborate with peer team members. Previous experience as an application security professional with a large Financial Institution a plus.
Foundational Skills :
- Web application vulnerability scanning tools (Invicti DAST Scanner, SoapUI, Burp Suite Pro, Checkmarx).
- Conducting vulnerability assessments, code reviews and penetration tests against web/mobile application technologies, services, platforms and languages to find flaws and exploits.
- Strong Development background with hands on experience on Pen Testing.
- Experience in setting up Pen Testing capability in India.
- Experience in managing large teams.
- Executive presence. Very Good Communication & Interpersonal skills.
- Experience conducting vulnerability assessments, code reviews and penetration tests against web/mobile application technologies, services, platforms and languages to find flaws and exploits (e.g., SQL Injection, Cross-Site Scripting, Cross-Site Request Forgery, Clickjacking, Authentication/Authorization, Privilege Escalation, Business Logic Bypass, OWASP Top 10, SANS Top 25 etc.).
- Knowledge of network and Web related protocols/technologies.
- Ability to demonstrate manual web application testing experience.
- Experience with web application vulnerability scanning tools (e.g. Invicti DAST Scanner, SoapUI, Burp Suite Pro, Checkmarx etc.).
- Experience with vulnerability assessment tools and penetration testing techniques (e.g. web application proxies, packet capture analysis software, browser extensions, advanced penetration testing tools (full stack), Linux distributions, Windows OS, etc.).
- Experience of penetration testing on mobile platforms such as iOS and Android, mobile device simulators.
- Solid programming/debugging skills with proficiency in one or more of the following: Java, JavaScript, HTML, XML, PHP, ASP.NET, AJAX, JSON, Objective-C, and SOAP/REST web APIs.
- Expert-level experience and very detailed technical knowledge in at least 3 of the following areas :
1. General information security.
2. Security engineering.
3. Application architecture.
4. Authentication and security protocols.
5. Application session management.
6. Applied cryptography.
7. Common communication protocols.
8. Mobile frameworks.
9. Single sign-on technologies.
10. Development frameworks (Angular, React, etc.).
11. Exploit automation platforms.
12. Threat modeling.
- Demonstrated ability to learn and apply critical thinking to a variety of situations.
- One or more of the following certifications : GWAPT, CEH, OSCP, SANS (or qualified work experience).
- Strong scripting skills (e.g. Python, Perl, Shell script, JavaScript).
- Mobile programming abilities such as Xcode, Objective-C.
Ethical Penetration Testing Leader • Hyderabad