Source description
About the role
As a Security Tester, your role involves performing manual security testing for various types of applications including web applications, APIs, Thick Client/Desktop Apps, and Mobile applications. You will be responsible for installing, configuring, and maintaining scanning and testing tools used for testing these applications. Your key responsibilities include: - Conducting manual security testing of web applications and API's hosted in Cloud and on-premises infrastructure. - Performing manual security testing of Thick Client/Desktop Apps using re-engineering techniques and tools like Echo Mirage, IDAPro, CFF Explorer, Dnspy, Wireshark, etc. - Conducting manual security testing of Mobile applications built for Android and IOS platforms using tools like GenyMotion, Drozer, MobSF, etc. - Knowledge and experience of working with Burp Suite for security testing. - Manually verifying security vulnerabilities identified by automated tools. - Assessing the severity of vulnerabilities based on the CVSS scoring mechanism. - Meeting with application teams to collect information and determine the scope of testing. - Providing status updates and resolving issues that impact testing. - Documenting identified security vulnerabilities and related matters clearly and concisely. - Reviewing, describing, and explaining identified security vulnerabilities to application teams and suggesting possible remediation. - Retesting application updates or deployed remediation logic to verify the resolution of security vulnerabilities. Qualifications required for this role: - 6-7 years of experience in Web Application, Web API Penetration Testing, Thick client Testing, and Mobile application testing, ideally in the Finance Domain. - Experience in conducting security assessments of AWS components such as S3 buckets, EC2 instances, Lambda functions, SNS, etc. used by cloud-hosted applications. - Experience using Burp Suite, OWASP ZAP, and other tools for security testing of Thick client apps and mobile apps. - Sound knowledge of common web application security vulnerabilities (OWASP Top Ten, SANS Top 25, etc.) and programming patterns leading to them, as well as remediation techniques. - Working knowledge of authentication and identity management technologies. - Strong interpersonal and communication skills with the ability to work in a team environment. - Ability to work independently with minimal direction and being a self-starter/self-motivated. As a Security Tester, your role involves performing manual security testing for various types of applications including web applications, APIs, Thick Client/Desktop Apps, and Mobile applications. You will be responsible for installing, configuring, and maintaining scanning and testing tools used for testing these applications. Your key responsibilities include: - Conducting manual security testing of web applications and API's hosted in Cloud and on-premises infrastructure. - Performing manual security testing of Thick Client/Desktop Apps using re-engineering techniques and tools like Echo Mirage, IDAPro, CFF Explorer, Dnspy, Wireshark, etc. - Conducting manual security testing of Mobile applications built for Android and IOS platforms using tools like GenyMotion, Drozer, MobSF, etc. - Knowledge and experience of working with Burp Suite for security testing. - Manually verifying security vulnerabilities identified by automated tools. - Assessing the severity of vulnerabilities based on the CVSS scoring mechanism. - Meeting with application teams to collect information and determine the scope of testing. - Providing status updates and resolving issues that impact testing. - Documenting identified security vulnerabilities and related matters clearly and concisely. - Reviewing, describing, and explaining identified security vulnerabilities to application teams and suggesting possible remediation. - Retesting application updates or deployed remediation logic to verify the resolution of security vulnerabilities. Qualifications required for this role: - 6-7 years of experience in Web Application, Web API Penetration Testing, Thick client Testing, and Mobile application testing, ideally in the Finance Domain. - Experience in conducting security assessments of AWS components such as S3 buckets, EC2 instances, Lambda functions, SNS, etc. used by cloud-hosted applications. - Experience using Burp Suite, OWASP ZAP, and other tools for security testing of Thick client apps and mobile apps. - Sound knowledge of common web application security vulnerabilities (OWASP Top Ten, SANS Top 25, etc.) and programming patterns leading to them, as well as remediation techniques. - Working knowledge of authentication and identity management technologies. - Strong interpersonal and communication skills with the ability to work in a team environment. - Ability to work independently with minimal direction and being a self-starter/self-motivated.
More at Diverse Lynx
Related open roles
Etl Testing Bangalore (Karnataka)
India
Data Loss Prevention (dlp) - Hyderabad, Bangalore
Bangalore
Data Loss Prevention (dlp) - Hyderabad, Bangalore (Karnataka)
India
Identity and Access Management Professional
Bangalore
Third Party Cyber Security Assessor
Bangalore
Identity And Access Management Chennai
Chennai