Source description
About the role
You are being sought after to fill the role of Application Security Engineer / Penetration Tester, where your expertise in web, mobile, and API security testing will have a significant impact. Your responsibilities will extend beyond standard pentesting as you actively simulate real-world fraud scenarios to identify vulnerabilities that could result in financial loss, system misuse, or business risk. Key Responsibilities: - Perform comprehensive penetration testing on web applications, mobile apps, and APIs - Conduct business logic testing & fraud simulation including bid manipulation, price tampering, replay attacks, fake approvals, and maker-checker bypass - Identify, exploit, and assist in remediating critical vulnerabilities - Test authentication, session/token security, and access controls - Simulate attacks on transaction workflows and procurement systems - Utilize tools such as Burp Suite, OWASP ZAP, Kali Linux, and Metasploit for advanced testing - Execute API security testing, input manipulation, and attack scripting - Collaborate with engineering teams to ensure secure design & remediation - Emphasize the business impact of vulnerabilities including financial risk, fraud exposure, and reputational impact Qualifications Required: - 3+ years of experience in Penetration Testing / Application Security - Hands-on experience in web, mobile, and API security testing - Strong expertise in business logic testing & fraud simulation - Proficiency in Burp Suite, OWASP ZAP, Kali Linux, and Metasploit - Strong understanding of authentication, session/token security, and API security - Experience in input manipulation, replay attacks, and workflow exploitation - Ability to clearly articulate the business impact of vulnerabilities If you possess the required penetration testing skills and are eager to tackle high-impact security challenges, this role offers a unique opportunity to work on real-world fraud scenarios, secure large-scale transaction platforms, take ownership in identifying business-critical vulnerabilities, and be part of a fast-paced, impact-driven security environment. Apply now to be a part of this exciting journey! You are being sought after to fill the role of Application Security Engineer / Penetration Tester, where your expertise in web, mobile, and API security testing will have a significant impact. Your responsibilities will extend beyond standard pentesting as you actively simulate real-world fraud scenarios to identify vulnerabilities that could result in financial loss, system misuse, or business risk. Key Responsibilities: - Perform comprehensive penetration testing on web applications, mobile apps, and APIs - Conduct business logic testing & fraud simulation including bid manipulation, price tampering, replay attacks, fake approvals, and maker-checker bypass - Identify, exploit, and assist in remediating critical vulnerabilities - Test authentication, session/token security, and access controls - Simulate attacks on transaction workflows and procurement systems - Utilize tools such as Burp Suite, OWASP ZAP, Kali Linux, and Metasploit for advanced testing - Execute API security testing, input manipulation, and attack scripting - Collaborate with engineering teams to ensure secure design & remediation - Emphasize the business impact of vulnerabilities including financial risk, fraud exposure, and reputational impact Qualifications Required: - 3+ years of experience in Penetration Testing / Application Security - Hands-on experience in web, mobile, and API security testing - Strong expertise in business logic testing & fraud simulation - Proficiency in Burp Suite, OWASP ZAP, Kali Linux, and Metasploit - Strong understanding of authentication, session/token security, and API security - Experience in input manipulation, replay attacks, and workflow exploitation - Ability to clearly articulate the business impact of vulnerabilities If you possess the required penetration testing skills and are eager to tackle high-impact security challenges, this role offers a unique opportunity to work on real-world fraud scenarios, secure large-scale transaction platforms, take ownership in identifying business-critical vulnerabilities, and be part of a fast-paced, impact-driven security environment. Apply now to be a part of this exciting journey!
More at Crewkarma