Position Overview :
In this role, you will support Rackspace's application security program by implementing and maintaining security testing capabilities, including static and dynamic application security testing, assisting with application penetration testing, and supporting our bug bounty program. You will work closely with development teams to identify, report, and help remediate security vulnerabilities across our application portfolio.
100% remote from within India
India Night Shift
Required Experience, Knowledge, Skills, and Abilities :
- 2-4 years in the information security field
- Experience working with application security, security testing, or DevSecOps practices
- Working knowledge of the SDLC, security concepts, and vulnerability assessment methodologies
- Hands-on experience with or understanding of programming and scripting languagesincluding one or more of the following : Python, Java, , Go, Ruby, PHP databases such as SQL and related tools such as Github, Gitlab, Jenkins, and CircleCI
- Understanding of common vulnerabilities, remediation approaches, and industry-standard classification schemes (CVE, CWE, CVSS, OWASP Top 10)
- Familiarity with relevant compliance regulations, such as PCI-DSS, ISO 27001, SOC 2, or HIPAA
- Passion for security and eagerness to learn about new technologies and emerging security vulnerabilities
- Strong communication skills with the ability to work collaboratively across teams
Key Duties and Responsibilities :
Execute application security testing using both automated tools and manual testing techniques on web applications, APIs, containers, and other software componentsConfigure, maintain, and operate SAST, DAST, and other application security testing toolsAnalyze and triage security findings, documenting clear remediation guidance for development teamsSupport the vulnerability reporting process and track findings through to resolutionAssist with triage and validation of external vulnerability disclosures and bug bounty reportsContribute to the development and documentation of application security processes and standardsParticipate in security code reviews and threat modeling exercisesHelp track and report metrics for application security program healthCollaborate with development and DevOps teams to integrate security into CI / CD pipelinesStay current with application security trends, tools, and best practicesSupport time-sensitive security events as needed under guidance of senior team membersEducation / Certifications :
Bachelor's degree () in Computer Science, Information Technology, Cybersecurity, or related technical fieldAt least one security certification such as :CEH (Certified Ethical Hacker)CompTIA Security+eWPT (eLearnSecurity Web Application Penetration Tester)GIAC certifications (GWAPT, GSEC)Offensive Security certifications (OSCP, OSWE)(ISC)² certifications (SSCP, CC)EC-Council certifications (CEH, ECSA)Skills Required
Sql, Hipaa, Java, DevSecOps, Iso 27001, Github, Go, Security Testing, CircleCI, Gitlab, Ruby, Application Security, Php, Python, Owasp Top 10, Jenkins