A leading electronics company located in Bengaluru is seeking a skilled IT Security professional to perform VAPT on applications, provide detailed assessment reports, and suggest actionable remediation strategies. The ideal candidate will have a strong background in IT application security protocols, vulnerability analysis, and scripting languages. Excellent communication skills are essential for collaborating effectively with technical and non-technical teams. A Bachelor's degree in Computer Science or a related field is required, along with relevant security certifications.
Qualifications
Deep understanding of IT Application security protocols and their implementation.
Expertise with web application vulnerability scanners.
Ability to analyze scan reports and suggest remediation plans.
Responsibilities
Provide assessment reports that are understandable to target audiences.
Collaborate with various teams to ensure consistency of security protocols.
Monitor information security trends and inform technology leadership.
Skills
VAPT on IT Applications
Communication skills
Troubleshooting of security vulnerabilities
Knowledge of scripting languages
Web application security
Education
Bachelor of Science in Computer Science
Tools
Burp Suite
Acunetix
IBM AppScan
Fortify
Job description
Role Responsibilities and Qualifications
Ability to perform VAPT on IT Applications using various open source and commercial tools like Burp suite/ZAP/CSRF Tester etc.
Provide assessment reports that are easily understandable by the target audiences.
Analyze scan reports and suggest remediation / mitigation plan.
Require deep understanding of IT Application security protocols and its implementation.
Maintain good verbal communication skills; communicate effectively with technical and non-technical colleagues at all levels in the organization.
Work within the relevant legislation, policies, and procedures.
Ability to perform complex troubleshooting of security vulnerabilities.
OSCP, ECSA, LPT Master, GPEN or any other industry accredited security certifications.
Exposure to OWASP top 10 Knowledge on SDLC and Application Architecture.
Knowledge on Network Security.
Knowledge of scripting languages (Java, dot net, python etc.).
Broad background of networks, operating systems (windows, UNIX, Linux), firewalls and security engineering concepts.
Penetration testing planning, analyzing, remediation recommendations, and dashboarding.
Vulnerability remediation tracking and reporting.
Expertise with web application vulnerability scanners (Acunetix /HP Web Inspect/IBM AppScan etc. and with source code analysis tools (Fortify/Checkmarx/Vera code/Klocworks)).
Provide remediation guidance to identified vulnerabilities.
Managing the Statutory and Internal Auditors on Application Security.
Assess applicable policy, standards, and controls, indirectly manage security technologies, and direct the establishment and implementation of policies and procedures.
Collaborate and build relationships with firm's Architecture, Business Systems, Operations, Legal and Risk teams.
Collaborate and build relationships with IT Security and Audit colleagues to help define and ensure consistency of security protocols and risk management.
Monitor information security trends and keep technology leadership informed about information security related issues and activities potentially affecting the organization.
Ensure appropriate business continuity process is followed for infrastructure and applications in accordance with business needs, guidelines, policies, and procedures.
Expertise with Identity and Access Management on the Application.
General knowledge of OS-level scripting languages (bash, ksh, PowerShell, Python, etc.) a plus.
General knowledge of Active Directory (AD), Intrusion Detection and Cloud Technology (Azure).
Bachelor of Science in Computer Science or a related field.