Information Security - Penetration testing & Application security testing
Dicetek LLC
Sharjah
On-site
AED 60,000 - 100,000
Full time
Boost your interview chances
Create a job specific, tailored resume for higher success rate.
Job summary
An established industry player is seeking a skilled Information Security professional with expertise in Penetration Testing and Application Security Testing. In this dynamic role, you will conduct thorough security assessments for web and mobile applications, ensuring compliance with the latest security frameworks and standards. You'll collaborate with internal teams and external vendors to implement security measures and stay ahead of emerging threats. If you're passionate about safeguarding applications and thrive in a fast-paced environment, this opportunity is perfect for you.
Qualifications
- 3-5 years of experience in Information Security with a focus on Penetration Testing.
- Security certifications such as CEH, OSCP, CISSP, and GPEN are preferred.
Responsibilities
- Conduct application security testing and vulnerability assessments for various applications.
- Plan and execute periodic testing activities, document findings, and develop remediation plans.
Skills
Penetration Testing
Application Security Testing
Vulnerability Assessment
Web and Mobile Application Hacking
Knowledge of OWASP
Security Tools (Nessus, BurpSuite)
Education
Tools
Nessus
Qualys
BurpSuite
Metasploit
Kali Linux
WebInspect
Acunetix
Minimum Qualifications
- Bachelor's Degree, with 3 - 5 years of experience in Information Security, specifically in Penetration Testing & Application Security Testing.
- Security certifications such as CEH, OSCP, OCSE, OSWA, CISSP, GPEN.
- Experience in application security testing for banking applications and other internal applications.
- Web and Mobile Application hacking and penetration testing experience.
- Vulnerability assessment skills.
- Experience with Wireless, VOIP, ATM Security testing, and WebAPI testing.
- Hands-on experience with security tools like Nessus, Qualys, BurpSuite, Netsparker, Metasploit, Kali Linux, WebInspect, Acunetix, etc.
- Thorough knowledge of OWASP, SANS, and similar security frameworks.
- Practical experience auditing various OS, Database, Network, and Security technologies.
Job Responsibilities
- Conduct application security testing, vulnerability assessments, penetration testing, and configuration reviews for networks, web applications, mobile applications, payment gateways, APIs, and thick-client applications.
- Perform manual and automated testing of Web, Mobile, Infrastructure, Network, Wi-Fi, ATM, payment gateways, and API applications.
- Contribute to the design, development, and support of new or upgraded business/infrastructure application projects with security recommendations throughout the implementation lifecycle.
- Ensure deployment of applications with appropriate security measures, including relevant technologies, architectures, policies, and compliance frameworks.
- Plan and execute periodic testing activities, document findings, and develop remediation plans. Coordinate with internal teams for reporting and closure of issues.
- Stay updated with the latest trends, tools, techniques, and emerging vulnerabilities, threats, and countermeasures in application security.
- Work with and manage external security vendors and auditors during assessments.