Application and Product Security I Analyst I

Vertiv

Maharashtra

On-site

INR 1,800,000 - 2,400,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Vertiv seeks an Application and Product Security Analyst (Penetration Testing) based in Pune, India, to evaluate security across embedded devices, mobile and web applications. You will document findings, prepare detailed reports, and develop PoCs under senior guidance.

You’ll work with the global security team, support testing plans, and use GitLab for issue tracking while applying cryptography and threat modeling to improve product security.

Qualifications

  • Bachelor’s degree in information technology, computer science or related field.
  • OSCP/CEH or equivalent security certification is preferred.

Responsibilities

  • Conduct security evaluation and threat assessments of embedded systems, mobile apps, and web apps.
  • Create detailed technical reports and proof-of-concept code to document findings.
  • Perform black/white box testing across products under test as assigned by leads.
  • Coordinate with engineering teams to plan testing activities and resources.

Skills

Penetration testing
Embedded security
Cryptography
Security assessment
Threat modeling
Protocols & testing
Reporting & documentation

Education

Bachelors in IT/CS
OSCP / CEH certificate

Tools

Gitlab
IDA Pro
BinWalk
Valgrind

Job description

Vertiv (NYSE: VRT) brings together hardware, software, analytics, and ongoing services to ensure its customers’ vital applications run continuously, perform optimally, and grow with their business needs. Vertiv solves the most important challenges facing today’s data centers, communication networks and commercial and industrial facilities with a portfolio of power, cooling and IT infrastructure solutions and services that extends from the cloud to the edge of the network. A $4.5B company, headquartered in Columbus, Ohio, USA, Vertiv employs approximately 24,000 people and does business in more than 130 countries.

Position Summary

The Application and Product Security Analyst (Penetration Testing) is responsible for conducting security pen testing, monitoring, and auditing within a dynamic global organization. The products under test will have a range of possibilities from embedded devices to cloud services. Some of the products will be white box tests while others will be total black box engagements. A successful analyst will be able to take the product and evaluate the weak points in the design and implementation and focus in on those weaknesses to find security gaps under the guidance of senior engineers and testing leads. Analyst should clearly document the findings, analysis and prepare a detailed report.

This position will be primarily based out in Pune (Global R&D center), INDIA, and will consistently work under the guidance and processes of global security team and regional senior/lead test engineers.

Duties
  • Conduct security evaluation and threat assessments of embedded systems, mobile applications, web applications
  • Conduct research for the purposes of finding new vulnerabilities and enhancing existing capabilities
  • Circumventing security protection methods and techniques
  • Performing data bus monitoring (snooping) and data injection
  • Conduct communications protocol analysis in the embedded products, and applications
  • Conduct wireless communications channel snooping, and data injection
  • Learn to reverse engineering complex systems and protocols
  • Create detailed technical reports and proof of concept code to document findings
  • Perform System Breakdown of the project/product before testing, identify and evaluate all the testing requirements and plan out the detailed testing activities, resources etc. with the help of Senior/Lead test engineers
  • Provide proactive detailed interaction with respective engineering group on the testing needs, testing progress/status and provide detailed analysis report
  • Use of Gitlab for issue management, tool usage experience preferred
  • Preference given to other practical skills such as: functional analysis, memory image capture, static memory analysis, and data element extraction, etc.
Requirements
  • A bachelor’s degree in information technology, Computer Science or related field is highly desirable.
  • Additional advanced security qualifications such as OSCP (Offensive Security Certified Professional) certification, CEH (Certified Ethical Hacker) or equivalent preferred.
  • Two or more years of experience (2+ years) in information, application, embedded product security and/or IT risk management with a focus on security, performance, and reliability
  • Solid understanding of security protocols, cryptography, authentication, authorization and security
  • Good working knowledge of current IT risks and experience implementing security solutions
  • Ability to interact with a broad cross-section of personnel to articulate and enforce security measures
  • Excellent written and verbal communication skills as well as business acumen
  • Strong ability to establish partnerships and influence change and achieve results within dynamic environment
  • Meaningful technical contributions into the development lifecycle of an application, product or service
Preferred Knowledge Experience Includes
  • Understanding and development experience of embedded systems / software, and web-based applications
  • Linux network device driver/data-path performance exposure
  • Familiarity with compilers, debuggers, disassemblers, and other low-level development and analysis tools
  • Exposure to binary analysis tools such as IDA Pro, WinDbg, BinWalk, Valgrind, PIN, Panda and S2E
  • Working knowledge of hacking tools and techniques such as memory corruption exploits, rootkits, protocol poisoning, browser-based attacks, DNS poisoning, MetaSploit, nmap, Nessus, etc.
  • An understanding of common cryptographic algorithms and protocols including their weaknesses and attacks against them
  • Understanding of network protocols and experience developing packet-level programs
  • Understanding of common microcontroller programming tools and debugging interfaces
  • Exposure to Layer 2, Layer 3 networking, QoS
  • Knowledge of common malware/botnet exploits and how they are targeted to exploit embedded systems
  • Operating system configuration of Windows, Linux, Android, and iOS
  • Computer boot process including boot loaders
Work Authorization

No calls or agencies please. Vertiv will only employ those who are legally authorized to work in the United States. This is not a position for which sponsorship will be provided. Individuals with temporary visas such as E, F-1, H-1, H-2, L, B, J, or TN or who need sponsorship for work authorization now or in the future, are not eligible for hire.

Equal Opportunity Employer

We promote equal opportunities for all with respect to hiring, terms of employment, mobility, training, compensation, and occupational health, without discrimination as to age, race, color, religion, creed, sex, pregnancy status (including childbirth, breastfeeding, or related medical conditions), marital status, sexual orientation, gender identity / expression (including transgender status or sexual stereotypes), genetic information, citizenship status, national origin, protected veteran status, political affiliation, or disability.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application and Product Security I Analyst I
Application and Product Security I Analyst I

Vertiv Co • Pune District

On-site
INR 1,000,000 - 1,800,000
Production Analyst
Production Analyst

Vertiv • Maharashtra

On-site
INR 180,000 - 250,000
IT End User Services Senior Analyst
IT End User Services Senior Analyst

Vertiv • Maharashtra

On-site
INR 600,000 - 900,000
Engineer I Test Engineering
Engineer I Test Engineering

Vertiv Co • Pune District

On-site
INR 900,000 - 1,300,000
Senior Engineer Software - Testing
Senior Engineer Software - Testing

Vertiv • Maharashtra

On-site
INR 6,686,000 - 10,506,000
Application Security Engineer
Application Security Engineer

Byline Learning Solutions • Pune District

On-site
INR 1,200,000 - 1,800,000
Penetration Tester
Penetration Tester

VikingCloud • India

On-site
INR 700,000 - 900,000
SECURITY ANALYST
SECURITY ANALYST

Datacultr Fintech Limited • Gurugram District

On-site
INR 800,000 - 1,200,000
Competitive compensation structure
Exposure to global financial clients
Comprehensive health and wellness benefits
Associate Security Analyst (AppSec)
Associate Security Analyst (AppSec)

Kratikal Tech Private Limited • Bengaluru

On-site
INR 400,000 - 600,000
Health insurance
Gratuity payment
Employees' Provident Fund
Senior Security Consultant (Web Application Penetration Tester)
Senior Security Consultant (Web Application Penetration Tester)

NetSPI Inc. • Pune District

On-site
INR 1,400,000 - 2,000,000