Get more replies from employers
Send a job-specific resume in minutes.
MHMarkets is seeking an experienced penetration tester to conduct manual testing of web apps, REST, GraphQL APIs and WebSockets in a trading environment. You will identify OWASP Top 10 and API security vulnerabilities and develop custom scripts to uncover issues missed by automation.
You will produce detailed reports with steps, risk ratings, business impact, and remediation guidance, and coordinate with DevSecOps and Infrastructure teams for remediation validation and retesting.
Conduct manual penetration testing of web applications, REST, GraphQL APIs, and WebSockets identify vulnerabilities aligned with OWASP Top 10 and OWASP API Security Top 10. Test financial and trading-specific business logic, including transaction manipulation, race conditions, authorization flaws, price manipulation and session-related vulnerabilities. Perform vulnerability exploitation and validation using Burp Suite and other offensive security tools. Develop custom scripts and techniques to identify vulnerabilities that automated scanners may miss. Assess authentication, authorization, session management, input validation, API security and transaction flows. Produce detailed penetration testing reports with reproducible steps, risk ratings, business impact and practical remediation recommendations. Work closely with Development, DevSecOps and Infrastructure teams to validate vulnerability remediation. Conduct retesting to ensure identified vulnerabilities have been properly resolved. Support continuous improvement of application security testing methodologies and security controls. Ensure security testing activities are conducted with minimal impact on trading systems and business operations.