Lead Cybersecurity - Application Vulnerability Security Tester

3 - 7 years

3 - 7 Lacs

Bengaluru / Bangalore, Karnataka, India

Posted:2 days ago| Platform: Foundit logo

Apply

Skills Required

SAST/SCA/DAST ecosystem Remediation Systems CWE

Work Mode

On-site

Job Type

Full Time

Job Description

Roles and Responsibilities: Perform SAST/SCA/DAST scans using industry vulnerability scanner SAST/SCA Veracode, using supplied compiled binary, configure scan platform to correct scan for both static code CWE s as we'll as SCA derived CVEs. Work will include coordination with app owner to ensure all branches of code are included in compiled binary file. DAST Work begins with crawling the target application to identify existing directory and file structure. Once identified, execute DAST scan using HCL product to identify dynamic issue only visible during code execution. During testing process, tester MUST ensure application is not degraded and/or taken out of service due to scanning activities Tester must ensure results from scanner are present in VM reporting platforms and visible to approved app users Validation - Supplier will perform manual validation and false-positive analysis on the automated scan results. Remediation Support: The remediation support will analyze the top-rated vulnerabilities along with provide support to application teams on remediation strategies from identified risks. Scan Retest: Supplier will perform revalidation tests of previously identified critical and high severity vulnerabilities as requested by the client application teams. Complex application testing and remediation/mitigation recommendation author Technical leadership of group of less experienced testers. Adversary based approach to test plan development Attempt to access unauthorized data Attempt to make unauthorized changes Bypass business logic, authentication, user privileges, etc. Hijack accounts (Does not include social engineering methods) Attempt to exploit OWASP Top 10 vulnerabilities EcoSystem Testing All forms of application security testing, attempt to exploit All forms of device security testing, attempt to exploit All forms of database security testing, attempt to exploit Full Stack review, weakness enumer

Mock Interview

Practice Video Interview with JobPe AI

Start Sast/Sca/Dast Interview Now

RecommendedJobs for You

Kolkata, West Bengal, India

Hyderabad / Secunderabad, Telangana, Telangana, India

Chennai, Tamil Nadu, India

Pune, Maharashtra, India

Hyderabad / Secunderabad, Telangana, Telangana, India