The Job logo

What

Where

Security Penetration Testing Security Engineer

ApplyJoin for More Updates

You must Sign In before continuing to the company website to apply.

Smart SummaryPowered by Roshi
Apply security skills to design, build and protect enterprise systems, applications, data, assets, and people. Provide services to safeguard information, infrastructures, applications, and business processes against cyber threats.
  • Project Role :Security Engineer
  • Project Role Description :Apply security skills to design, build and protect enterprise systems, applications, data, assets, and people. Provide services to safeguard information, infrastructures, applications, and business processes against cyber threats.
  • Management Level :10
  • Work Experience :4-6 years
  • Work location :Bengaluru

 

Job Requirements :

  • Key Responsibilities : a.Experience in web application security assessments, hands on techniques for identifying SQL injections, XSS, CSRF, authentication, OWASP top 10 issues. b.Good knowledge of security technologies for secure software development such as cryptography, authentication techniques and protocols etc. c.Experience on both commercial and open source tools ( Cenzic Hailstorm, Burpsuite, AppScan, WebInspect, Appspider, sqlmap, OWASP ZAP,) d.3Proven experience in identifying and exploiting business logic and framework related vulnerabilities. e.Vast experience in removing false positives, analyzing dynamic scan (webinspect, appscan) reports f.Knowledge of Secure SDLC and Security standards like OWASP, CWE, NIST, OSSTMM. g.Provide expert advice and recommendation to application development team as well as vendor.
  • Technical Experience : Experience in performing penetration testing on enterprise networks, web applications, APIs and mobile applications. Familiarity with common web vulnerabilities including XSS, XXE, SQL Injection, Deserialization Attacks, File Inclusion/Path Traversal Attacks, Server-side Request Forgery, Remote Execution Flaws, Server Configuration Flaws and Authentication Flaws. Experience in testing web-based APIs (REST, SOAP, XML, JSON). Experience in designing and documenting pragmatic remediation guidance for discovered vulnerabilities. Experience in performing Reverse Engineering for APIs and mobile applications. Experience developing actionable intelligence based on open-source intelligence (OSINT) gathering. Experience with 1 or more scripting languages such as Bash, Python, Perl, PowerShell. Experience on both commercial and open-source tools such as Kali Linux, Metasploit, Burpsuite, AppScan, WebInspect, Appspider, sqlmap, OWASP ZAP and others.
  • Professional Attributes : Strong analytical skill with a structured problem-solving approach Must have good verbal and written communication skill and a good team player Demonstrated creativity in complex problem solving and ability to work under pressure
  • Educational Qualification : BE/BTech
  • Additional Information : Certified in one of the Industry recognized penetration testing skill (OSCP, LPT, Comptia Pen test+, GPEN, GXPN)

 

Set alert for similar jobsSecurity Penetration Testing Security Engineer role in Bengaluru, India
Accenture Logo

Company

Accenture

Job Posted

a year ago

Job Type

Full-time

WorkMode

On-site

Experience Level

3-7 Years

Category

Technology

Locations

Bengaluru, Karnataka, India

Qualification

Bachelor

Applicants

Be an early applicant

Related Jobs

CGI Logo

Security testing Engineer

CGI

Bengaluru, Karnataka, India

Posted: a year ago

Job Title: Security Testing Position: Software Engineer Experience: 3 - 5 Years Category: Software Development/ Engineering Main location: India, Bangalore, Hyderabad, Employment Type: Full Time Security testing Engineer 3 to 5 years of experience in security testing activities Participate in requirement gathering calls & Understand the NFRs/Security testing requirements. Understand the System Architecture and the components involved in the applications. Prepare and present the test plan with suggestion on types of testing needed to for the application Create test cases from security testing services Develop capability to conduct manual code review and become proficient in Checkmarx tool. Develop capability to conduct manual penetration testing using Burp Suite and Zap-proxy tools and be proficient with OWASP top 10 web, API and Mobile pen testing Develop capability to conduct vulnerability scanning and management for Bell security Titanium project, ability to lead the project and coordinate with other teams and prepare assessment for remediation Develop capability to conduct security audits and through understanding on NIST controls Develop capability to conduct security testing practice for cloud related technologies Develop capability to identify false positives and prepare detailed report with number of vulnerabilities and provide proper recommendations to client Be responsible and take ownership for the work assigned and complete the activity on time without follow-ups Take ownership for end to end delivery of the project, including daily updates, weekly updates and reports walkthrough for the clients Demonstrate ability to handle multiple projects at the same time Certification needed: CEH, CISSP   Skills: English Security Assessment Telecommunications Vulnerability Assessment(IAVA) Security Certification