– Application Security

Happiest ResumeMumbai, Maharashtra₹500,000 – ₹1,000,000
Adzuna INPosted 4h agoOriginal Listing
it-jobs

Job Description

We are looking for an Application Security / Penetration Testing Engineer with strong hands-on experience in web application and API security testing. The resource will support security testing of approximately 150 applications annually, using both manual testing and automated application security testing tools. The resource will also support our bug bounty program by independently validating, reproducing and documenting vulnerabilities reported by external security researchers. Key Responsibilities Application Security Testing  Perform manual penetration testing of web applications and APIs.  Conduct testing based on OWASP Top 10 and established application security testing methodologies.  Test authentication and authorization mechanisms.  Identify IDOR/BOLA, privilege escalation and access-control vulnerabilities.  Test session management and security controls.  Identify SQL Injection, XSS, SSRF, CSRF, XXE and other common vulnerabilities.  Perform business logic and workflow testing.  Conduct REST/API security testing.  Test JWT, OAuth and other authentication mechanisms.  Identify security misconfigurations and information disclosure.  Perform client-side security testing.  Document and demonstrate identified vulnerabilities with appropriate evidence. Automated Testing  Execute application security scans using DAST and other automated tools.  Configure applications and testing parameters for automated scans.  Analyze automated findings and validate them manually.  Identify and eliminate false positives.  Use automated tools to improve testing coverage and efficiency.  Supplement automated testing with manual security testing. Bug Bounty Support  Review vulnerabilities reported through the organization's bug bounty platform.  Reproduce reported vulnerabilities independently.  Validate whether vulnerabilities are genuine and exploitable.  Identify duplicate and false-positive reports.  Provide proof of concept and supporting evidence.  Assess severity and impact.  Proactively identify vulnerabilities before they are reported by external researchers.  Support the team in reducing unnecessary bug bounty expenditure. Reporting & Retesting  Prepare application security assessment reports.  Clearly document vulnerability details, severity, impact, evidence and remediation recommendations.  Maintain vulnerability tracking records.  Coordinate with development teams for clarification and remediation.  Perform vulnerability retesting after remediation.  Update reports based on retesting results. Required Technical Skills  3+ years of hands-on experience in Application Security / Penetration Testing.  Strong experience in web application security testing.  Good experience in API security testing.  Good understanding of OWASP Top 10 and OWASP API Security Top 10.  Hands-on experience with Burp Suite Professional.  Experience with OWASP ZAP, Nmap, Nuclei, Postman, SQLMap or similar tools.  Experience with DAST/automated security testing tools.  Good understanding of HTTP/HTTPS, REST APIs and common web technologies.  Ability to manually validate vulnerabilities identified by automated tools.  Ability to reproduce vulnerabilities reported by security researchers. OWASP's API Security Top 10 includes risks such as broken object-level authorization, broken authentication, broken function-level authorization, unrestricted resource consumption and SSRF, making API testing an important part of this role. Certifications At least one relevant cybersecurity/application security certification is required. Preferred:  eWPT/eWPTX  OSCP / OSCP+  GWAPT  GPEN  CEH  Security+  Other recognized AppSec/Penetration Testing certification Experience  3+ years of relevant experience in Application Security / Penetration Testing.  Experience conducting web application and API security assessments.  Experience with vulnerability reporting and remediation tracking.  Bug bounty experience is highly desirable.  Experience testing multiple applications and technologies is preferred. Behavioural & Professional Skills  Strong analytical and troubleshooting skills.  Good attention to detail.  Ability to think from an attacker's perspective.  Good technical documentation skills.  Ability to work independently and as part of a security team.  Ability to manage multiple application assessments and timelines.  Good communication skills. Key Performance Expectations  Complete assigned application security assessments within agreed timelines.  Identify vulnerabilities through both manual and automated testing.  Validate automated findings and minimize false positives.  Successfully reproduce bug bounty vulnerabilities.  Provide technically accurate reports and remediation recommendations.  Conduct timely retesting after remediation.  Contribute towards proactive vulnerability discovery and reduction of unnecessary bug bounty expenditure

Get AI-Matched to This Job

Upload your resume and our AI will score how well you match this and thousands of similar roles.