Key Responsibilities :
- Conduct security testing across applications, APIs, and systems using industry-standard tools.
- Utilize tools such as Burp Suite, OWASP ZAP, Fortify, and others to identify and analyze vulnerabilities.
- Lead or contribute to the automation of security testing within CI / CD pipelines using GitLab or similar platforms.
- Perform validation and retesting of remediated vulnerabilities to ensure effectiveness.
- Work closely with development, QA, and DevOps teams to integrate security best practices throughout the SDLC.
- Stay updated with the latest security threats, tools, and trends.
- Document findings, prepare detailed reports, and present results to technical and non-technical stakeholders.
- Collaborate in DevSecOps initiatives and contribute to the overall cybersecurity posture of the organization.
Required Skills & Experience :
Minimum 5 years of hands-on experience in application and infrastructure security testing.Strong experience with security testing tools such as :
Burp SuiteOWASP ZAPFortify (Static and Dynamic Analysis)Deep knowledge of OWASP Top 10 vulnerabilities and common attack vectors.Hands-on experience with CI / CD pipelines, preferably with GitLab.Familiarity with DevOps environments and integrating security testing within CI / CD workflows.Solid understanding of cybersecurity principles, threat modeling, and risk assessment.Ability to analyze security vulnerabilities, provide actionable remediation recommendations, and verify fixes.Preferred Qualifications :
Experience in the cybersecurity domain or working in security-focused roles.Relevant certifications such as CEH, OSCP, CPT, or Security+.Exposure to cloud security testing (AWS, Azure, or GCP) is a plus.Experience with SAST / DAST / IAST tools and secure code review.Soft Skills :
Strong communication and presentation skills.Ability to clearly articulate security findings and risks to both technical and non-technical audiences.Excellent problem-solving skills and a proactive mindset.(ref : hirist.tech)