Role & responsibilities
- Perform end-to-end security assessment of web applications before production launch
- Review application architecture from a cybersecurity perspective
- Conduct web application penetration testing
- Review authentication, authorization, user roles, session management, and password-security controls
- Identify vulnerabilities based on OWASP Top 10, OWASP WSTG, and related application-security standards
- Perform secure code reviews and identify coding-related security vulnerabilities
- Review database security, access controls, credentials, encryption, and SQL-related vulnerabilities
- Review web server, cloud/server configuration, TLS/SSL, firewall, security headers, and production configuration
- Review third-party integrations and APIs from a security perspective, where applicable
- Perform vulnerability scanning and automated security testing
- Review third-party libraries and application dependencies for known vulnerabilities
- Evaluate file uploads, input validation, error handling, logging, audit trails, and sensitive-data handling
- Identify business-logic vulnerabilities and privilege-escalation risks
- Provide detailed remediation recommendations to the development team
- Retest the application after fixes are implemented
- Provide a final security assessment / residual-risk report before production launch
Preferred candidate profile
- 5+ years of overall cybersecurity experience
- Minimum 3+ years specifically in web application security and penetration testing
- Experience working with financial services, mortgage, lending, fintech, or similar applications is preferred
Required Technical Skills:
- Strong Web Application Security knowledge
- OWASP Top 10
- OWASP Web Security Testing Guide (WSTG)
- OWASP Application Security Verification Standard (ASVS)
- Web Application Penetration Testing
- Secure Code Review
- Authentication and Authorization Testing
- SQL Injection and Database Security
- Cross-Site Scripting (XSS)
- CSRF, SSRF, Session Management, and Access Control Testing
- SAST, DAST, and Software Composition Analysis (SCA)
- Vulnerability Assessment
- Burp Suite / OWASP ZAP or equivalent security-testing tools
- Server and Infrastructure Security
- Cloud Security knowledge
- TLS/SSL and security-header configuration
- Secrets and credential management
- Security Logging and Monitoring
- Secure Software Development Lifecycle (Secure SDLC)
Preferred Certifications:
Certifications are preferred but hands-on application-security experience is more important.
Relevant certifications may include:
- OSCP
- OSWE
- GIAC GWAPT / GWEB
- CISSP
- CEH or equivalent security certifications
Expected Deliverables:
- Application Security Assessment Report
- Penetration Testing Report
- List of vulnerabilities categorized as Critical / High / Medium / Low
- Evidence and affected areas for each vulnerability
- Recommended remediation for each issue
- Security configuration recommendations
- Retesting of identified vulnerabilities after remediation
- Final pre-production security assessment / residual-risk report