Web Penetration Tester Consultant

4 - 9 years

22 - 25 Lacs

Posted:1 week ago| Platform: Naukri logo

Apply

Work Mode

Hybrid

Job Type

Full Time

Job Description

Job Title: WebPT P1 - Consultant

Location:

Roles & Responsibilities:

  • Perform automated testing of running applications and static code (SAST, DAST).
  • Conduct manual application penetration tests on one or more of the following to discover and exploit vulnerabilities:
    • Web applications
    • Internal applications
    • APIs
    • Internal and external networks
    • Mobile applications
  • Experience in one or more of the following is a plus:
    • Mobile application testing
    • Web application pen testing
    • Application architecture
    • Business logic analysis
  • Work on application tools to perform security tests, including:
    • AppScan
    • NetsSparker
    • Acunetix
    • Checkmarx
    • Veracode
    • BurpSuite
    • OWASP ZAP
    • Kali Linux
  • Able to explain vulnerabilities such as:
    • IDOR (Insecure Direct Object References)
    • Second Order SQL Injection
    • CSRF (Cross-Site Request Forgery)
  • Provide root cause analysis and remediation guidance for identified vulnerabilities.

Mandatory Technical & Functional Skills:

  • Minimum three (3) years

    of recent experience working with application tools to perform security tests:
    • AppScan
    • NetsSparker
    • Acunetix
    • Checkmarx
    • Veracode
    • BurpSuite
    • OWASP ZAP
    • Kali Linux (or equivalent)
  • Minimum three (3) years

    of performing manual penetration testing and code review against:
    • Web applications
    • Mobile apps
    • APIs
  • Minimum three (3) years

    of experience working with both technical and non-technical audiences in reporting results and leading remediation conversations.
  • Preferred:

    One year of experience in the development of web applications and/or APIs.
  • Ability to identify and work with new tools/technologies to plug and play on client projects as needed to solve the problem at hand.

Certifications (Preferred but not required):

  • GWAPT (GIAC Web Application Penetration Tester)
  • CREST (Certified Testing Professional)
  • OSCP (Offensive Security Certified Professional)
  • OSWE (Offensive Security Web Expert)
  • OSWA (Offensive Security Web Application)

6-month contract role

Mock Interview

Practice Video Interview with JobPe AI

Start Job-Specific Interview
cta

Start Your Job Search Today

Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.

Job Application AI Bot

Job Application AI Bot

Apply to 20+ Portals in one click

Download Now

Download the Mobile App

Instantly access job listings, apply easily, and track applications.

coding practice

Enhance Your Skills

Practice coding challenges to boost your skills

Start Practicing Now
Kezan Consulting logo
Kezan Consulting

Consulting

Business City

RecommendedJobs for You