T&T-Cyber-Strategy & Transformation- AM – VAPT

Job Title: Application Security SME

Location: Bangalore, India (Mandatory)

Company: Deloitte India

Job Type: Full-time

Experience: 4-7 

Best fit Roles:

Web Application Penetration Testing, API Testing, Network Penetration Testing Mobile Application Penetration Testing, Source Code Review, Thick Client Application Testing

Certifications: Certified Ethical Hacker (CEH), Certified Red Team Professional (CRTP), Certified AppSec Pentester (CAPen), Certified API Security Analyst (CASA), OffSec Certified Professional (OSCP)

Responsibilities

  • Conduct end-to-end penetration tests on web applications, APIs, mobile applications, thick client applications, and network infrastructures to identify vulnerabilities.
  • Collaborate on projects with defined objectives, ensuring timely and successful delivery.
  • Analyze end-to-end application architectures and business logic for potential vulnerabilities.
  • Prepare detailed reports documenting findings, risk levels, and recommendations for remediation, ensuring clarity for both technical and non-technical audiences.
  • Perform in-depth source code reviews to detect security flaws and ensure compliance with secure coding standards.
  • Leverage advanced penetration testing tools and frameworks to replicate real-world attack scenarios, ensuring comprehensive vulnerability identification.
  • Execute cyber security assessments, including vulnerability assessments, penetration tests, and secure code reviews, both manually and using automated tools.
  • Present findings and remediation strategies to clients, providing guidance on best practices and potential risks.
  • Demonstrate understanding of core business processes and IT management practices to align security measures effectively.
  • Contribute to the development of best practices and methodologies within the security team.

The Key Skills

  • Expertise in penetration testing Web, Mobile application (both iOS and Android), API and SaaS application.
  • In-depth understanding of API security vulnerabilities and proven experience in securing API. Experience in writing proof of concepts, exploits and performing in-depth exploitation is desired.
  • Understanding of basic business and information technology management processes
  • Must have in-depth knowledge of OWASP TOP 10/SANS25 best practices and cyber security guidelines.
  • Must have detailed understanding of CIA Triads, Cryptography, Defense in Depth.
  • Experience in Infrastructure Penetration Testing and Application Security Testing
  • In-Depth understating of Risk, Threat, and Vulnerabilities.
  • Experience in secure code review and expertise in tools like Checkmarx, SonarQube, Veracode will be preferred.
  • Experience in conducting configuration reviews of Windows, Linux, UNIX, Solaris, Databases, etc.
  • Should possess knowledge of vulnerability exploitation and exploit development.
  • Experience in basic scripting such as: Shell, Python, etc.
  • Good knowledge of protocols, security measures and Networks including Firewall, IDS/IPS, Routers, Switches, and network architecture.
  • Familiarity with security principles and technologies.
  • Expertise in performing Threat Modeling, generating security architectural requirements to software development and product teams.
  • Expert knowledge of offensive security tools (e.g., Metasploit, Cobalt Strike, Burp Suite, Empire, etc.) and threat simulation frameworks.
  • Strong understanding of TTPs used by cybercriminals and APT groups (MITRE ATTACK framework knowledge preferred).

Apply now
To help us track our recruitment effort, please indicate in your cover/motivation letter where (jobs-near-me.eu) you saw this job posting.

Share

Recent Posts

Medical Affairs Manager GI Cancer

Job title: Medical Affairs Manager GI Cancer Company AstraZeneca Job description Medical Affairs Manager GI…

39 minutes ago

EXPRESSION OF INTEREST (EOI) – CALL FOR TECHNICAL EXPERTISE

The DAI-implemented USAID Policy LINK project invites individual technical experts and specialized entities (e.g., organizations…

1 hour ago

Vice President, U.S. Programs

Position description The Institute for Sustainable Communities (ISC), founded in 1991, is a climate organization…

1 hour ago

Groundwater under Antarctica: Ice sheets, Carbon and Oceanography (GAICO)

About the Project We invite applications from qualified and highly motivated students for 3.5-year PhD…

1 hour ago

Senior Technical Officer – Inclusive Education (Re-advertisement)

Vacancy: 01 Job Category: Technical Job Level: Mid Job Type: Full time Job Location: Dhaka…

1 hour ago

Senior Policy Officer

Position description Solar Heat Europe/ESTIF is looking for a dynamic person who will be steering…

1 hour ago
For Apply Button. Please use Non-Amp Version

This website uses cookies.