
Pentester /Mobile Application Security
- Bangalore, Karnataka
- Permanent
- Full-time
- Encourage Shift Left Mindset - Proactively embed security requirements, by influencing implementation of security & privacy patterns from the start of the development cycle
- Implement via Influence - Influence stakeholders such as Product Owners, Solution Architects, Developers, Testers, Engineers & others to include security patterns into features, epics and stories in order to build secure, innovative & superior digital products for customers and employees
- Assessments Perform security assessment and perform gap analysis to provide appropriate remediations to the teams for implementing the fixes.
- Tools and Technologies Expertise Burp Suite, MobSF, Frida, Kali Linux, Nessus, Checkmarx SAST, Kubernetes, Docker, Jenkins, GitHub, OpenShift and good knowledge about microservice architecture and pipeline driven security.
- Web Application Security
- Security Code Review
- Container Review
- Infrastructure Review
- WAF rules review
- Ability to collaborate with multiple stakeholders and manage their expectations from a security perspective
- Holistic thinking; must balance security and functionality using practical demonstrable examples. Must also contribute to and implement good architecture principles to lower technical debt
- Assertive personality; should be able to hold her/his own in a project board or work group setting
- Superlative written and verbal communication skills; should be able to explain technical observations in an easy-to-understand manner
- Ability to work under pressure and meet tough/challenging deadlines
- Influencer- must be able to convince various stakeholders (internal IT Teams, C-Level execs, Risk & Audit) of why a certain observation is a concern or not
- Strong understanding of Risk Management Framework and security controls implementation from an implementer standpoint
- Has strong decision making, planning and time management skills.
- Can work independently.
- Has a positive and constructive attitude.
- Education
- General
- Professional
- General Information Security: CISSP, OSCP, CEH, CISM/CISA or similar
- General Cloud Security: CCSK /CCSP or similar
- Specific Cloud Security: AWS/Azure/GCP/Oracle Solution/Security or similar
- Network Security: CCNA, CCNP, CCIE, Certified Kubernetes Security Specialist
- Industry
- Regional
- Functional
- Technical
- Functional
- Managerial
Expertia AI Technologies