Manager Application Security

10 - 15 years

30 - 45 Lacs

Posted:7 hours ago| Platform: Naukri logo

Apply

Work Mode

Work from Office

Job Type

Full Time

Job Description

  • At least 7 year of experience as a penetration tester
  • Proven abilities to approach a black box and white box testing.
  • Proven hands on experience in manual pen testing as major part of work profile
  • Hands-on experience with vulnerability scanners (static and/or dynamic) and frameworks, including but not limited to Burp Suite, Checkmark, OWASP ZAP, Burp, Nmap, Nessus, Metasploit Framework
  • Good hands on experience with API penetration testing of Rest/SOAP based interfaces
  • Perfect knowledge of OWASP methodology and web vulnerabilities – you can easily explain and show how it works
  • Python or any other scripting language. Comfortable using and working linux/unix environments
  • Desirable skills to have PCI, NIST guidelines including PII, ISO2700x, cloud security, virtualization, SecDevOps, containerized deployment.
  • Extremely committed and self-motivated individual with ability to deliver in challenging situations
  • Excellent written and oral communication
  • Assessing application and solution security controls against black box», grey box» and white box» attacks using both manual and automated (DAST) penetration techniques
  • Assessment of penetration test results with development teams, contribution to risk mitigation actions
  • Source code analysis (client/server/database) for vulnerabilities with scanning tools - SAST

Roles and Responsibilities
  • Discovering all information on system and solution exploitability ( of Top 10 vulnerabilities categorized by OWASP, CWE/CVE  like XSS, CSRF, CRLF, SQLi, XXE and uncommon HTTP Request Smuggling/Splitting, other) and security weaknesses from a variety of sources ( technical documentation, source code, communication with project and development teams)
  • Assessing application and solution security controls against black box», grey box» and white box» attacks using both manual and automated (DAST) penetration techniques
  • Assessment of penetration test results with development teams, contribution to risk mitigation actions
  • Source code analysis (client/server/database) for vulnerabilities with scanning tools - SAST
  • Analysis of customer and 3rd party penetration test results and communicating security results to the customer
  • Vulnerability assessment using various commercial and open source tool
  • Software Composition Analysis of product open source libraries using various tools
  • Contribution in enhancing penetration testing process, tools and automation of SAST/DAST tools in CI/CD pipelines

Mock Interview

Practice Video Interview with JobPe AI

Start Python Interview
cta

Start Your Job Search Today

Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.

Job Application AI Bot

Job Application AI Bot

Apply to 20+ Portals in one click

Download Now

Download the Mobile App

Instantly access job listings, apply easily, and track applications.

coding practice

Enhance Your Python Skills

Practice Python coding challenges to boost your skills

Start Practicing Python Now
Netcracker logo
Netcracker

Telecommunications Software

Maitland

RecommendedJobs for You

hyderabad, chennai, bengaluru