Get more replies from employers
Send a job-specific resume in minutes.
Sisainfosec is seeking a skilled security tester to conduct comprehensive web, API, and mobile penetration testing across multiple platforms, including thick clients. You will perform automated and manual security assessments and collaborate with development teams for remediation.
Required expertise includes OWASP Top 10, SANS Top 25, and NIST standards, with strong test reporting and stakeholder communication. BE/B.Tech or M.Tech in CS/IS and relevant certifications are preferred.
1.Conduct penetration testing onweb,mobile(android +ios), API, and thick-client applicationstoidentifysecurity weaknesses
2.Conductautomated and manualSecure code review
3.Identifyand exploit vulnerabilities such asOWASP Top 10, SANS Top 25, and business logic flaws.
3. Client interactionon projectupdation/status
5.Collaborate with developers, product teams forRemediation support
6. Perform retest post confirmation on the fixes
6. Follow-upwith the relevant stakeholders on the remediation of open vulnerabilities
Web,APIand Mobile Penetration Testing
Proficiencywith penetration testing tools such as:
Burp Suite, OWASP ZAP, Postman, Nmap,SQLMap, Metasploit, Echo mirage
Mobile testing tools (e.g.,MobSF, Frida) is a plus.
Good understanding onOWASP Top 10, SANS CWE Top 25, NIST standards.
Good written and spoken communication skills
Ability to do report walkthrough with relevant stakeholder
BE/B.Techin Computer Science or Information Science OrM.Techin Computer Science or Information Science
Certifications:CEH,CompTIA,PenTest+,GPEN, OSCP, CREST CRTpreferable