
VAPT Pentester / Web Application Security
- Bangalore, Karnataka
- Permanent
- Full-time
- Encourage Shift Left Mindset - Proactively embed security requirements, by influencing implementation of security & privacy patterns from the start of the development cycle
- Implement via Influence - Influence stakeholders such as Product Owners, Solution Architects, Developers, Testers, Engineers & others to include security patterns into features, epics and stories in order to build secure, innovative & superior digital products for customers and employees
- Assessments Perform security assessment and perform gap analysis to provide appropriate remediations to the teams for implementing the fixes.
- Tools and Technologies Burp Suite, Postman, Tenable Nessus, Checkmarx SAST, GitHub and good knowledge about monolithic and microservice architecture and pipeline driven security.
- Security Code Review manual code review in Git etc
- API Security Review Open shift, container review etc.
- Database Security Requirements to enhance security on Database
- Web Server Security Requirements to enhance security on the web server
- Configuration Review has performed different configuration reviews and should have found good misconfigurations in the system.
- Integration review How the application connects with different systems, performed security review on those integrations.
- Transport Layer Security How communication channels are secured and understanding of the Transport layer security mechanisms and controls.
- Ability to collaborate with multiple stakeholders and manage their expectations from a security perspective
- Holistic thinking; must balance security and functionality using practical demonstrable examples. Must also contribute to and implement good architecture principles to lower technical debt
- Assertive personality; should be able to hold her/his own in a project board or work group setting
- Superlative written and verbal communication skills; should be able to explain technical observations in an easy-to-understand manner
- Ability to work under pressure and meet tough/challenging deadlines
- Influencer- must be able to convince various stakeholders (internal IT Teams, C-Level execs, Risk & Audit) of why a certain observation is a concern or not
- Strong understanding of Risk Management Framework and security controls implementation from an implementer standpoint
- Has strong decision making, planning and time management skills.
- Can work independently.
- Has a positive and constructive attitude.
- Education
- General
- Professional
- General Information Security:OSCP, CEH, CISM/CISA or similar
- General Cloud Security: CCSK /CCSP or similar
- Specific Cloud Security: Azure Security or similar
- Network Security: CCNA, CCNP, CCIE, Certified Kubernetes Security Specialist
- Experiences
- Industry
- Regional
- Functional
- Knowledge & Skills
- Technical
- Functional
- Managerial
- Thinking Related
- People Related
- Self Related
- Influencer/Security Evangelist for the Team/Squad
- Positive & Constructive Attitude
- Autonomous worker / Decision Maker
- Good listener
- Patient & Calm during stressful situations
- High energy individual / Motivator
- Win-Win Attitude
- Hacker/Defense-In-Depth mindset
- Analytical thinking
- Team Player/Interpersonal Skills
- Eye for detail
- Persistent & Persuasive
- Organized / Structured
- Deadline oriented
- Competent and committed
- Peoples Person; understands stakeholder management
- Empathetic
- Passionate about architecting smart solutions
- Innovator/Out of the box thinker
- Collaborative Leadership style
- Confident Presenter
Expertia AI Technologies