Senior Associate, Offensive Security

RSM US LLP

Bengaluru

On-site

INR 1,200,000 - 1,800,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

RSM US LLP is seeking an experienced Application Penetration Tester to join the Security and Privacy Risk Consulting group. You will lead security assessments, perform manual testing on web apps and networks, and advise clients across diverse industries while training team members.

You will collaborate with development teams, promote secure practices, and stay current with security trends to identify and remediate risks across client portfolios.

Qualifications

  • BS in Computer Science, Engineering, or related field.
  • Advanced web security expertise and knowledge of vulnerabilities.
  • 5+ years in code review, app security testing, or web development.
  • Excellent written and verbal communication skills.
  • Proficient in Java, Python, Ruby, JavaScript.
  • Experience with AWS cloud and cloud security best practices.
  • Familiar with Docker, CDK, Terraform, React, GraphQL, REST, JSON.
  • Integrity and confidentiality; adheres to company policies.
  • Technical background in app development, networking or security testing.
  • Certifications such as OSWA/OSWE/OSCP or Burp Suite/ AWS Security preferred.

Responsibilities

  • Lead security assessments including SAST and DAST.
  • Perform manual penetration testing of web apps, networks, and systems.
  • Collaborate with clients across stacks including cloud and development tech.
  • Develop and interpret security standards and guidance.
  • Promote secure development and cloud security practices.
  • Develop remediation recommendations for findings.
  • Communicate findings clearly to management and clients.
  • Identify improvement opportunities for clients.
  • Stay updated on latest security trends and tools.
  • Lead, mentor, and supervise staff on engagements.

Skills

Web security
Code review
Communication
Java
Python
JavaScript
Ruby
Docker
AWS
Security testing

Education

BS in CS/Engineering

Tools

Docker
CDK
Terraform
React
GraphQL
REST
JSON

Job description

We are the leading provider of professional services to the middle market globally, our purpose is to instill confidence in a world of change, empowering our clients and people to realize their full potential. Our exceptional people are the key to our unrivaled, inclusive culture and talent experience and our ability to be compelling to our clients. You’ll find an environment that inspires and empowers you to thrive both personally and professionally. There’s no one like you and that’s why there’s nowhere like RSM.

Application Penetration Tester – Offensive Security Testing (Sr. Associate)

RSM is seeking an experienced application penetration tester with expertise in both manual and automated testing to join our Security and Privacy Risk Consulting group. The ideal candidate will have a strong understanding of various testing methodologies and tools, as well as a passion for uncovering vulnerabilities and identifying potential security risks. This position will play a critical role in helping our clients prevent, detect, and respond to security threats affecting their critical systems and data. As a member of the Security, Privacy, and Risk Consulting team, you will oversee application security testing for our clients and train team members. Our team’s goal is to empower both development and security teams with accurate security findings at the highest standards of quality in order to identify and eliminate risk across our clients’ application portfolios. Join our team of more than 150 professionals dedicated to serving the cybersecurity needs of our diverse client base within a variety of industries.

Role Responsibilities:

  • Supervise and lead security assessments, including static and dynamic application security testing
  • Conduct manual penetration testing on web applications, network devices, and other systems
  • Collaborate with our clients in a fast-paced environment across many technology stacks and services, including cloud platforms and development technologies
  • Develop, enhance, and interpret security standards and guidance
  • Demonstrate and promote security best practices, including secure development and cloud security
  • Assist with the development of remediation recommendations for identified findings
  • Identify and clearly articulate (written and verbal) findings to senior management and clients
  • Help identify improvement opportunities for assigned clients
  • Stay up-to-date with the latest security trends, technologies, and best practices
  • Lead and foster teamwork and open communication to deliver successful outcomes
  • Supervise, mentor, and manage the engagement of other staff working on assigned engagements

Qualifications and Experience:

  • BS in Computer Science, Engineering, or related field or equivalent work experience
  • Advanced expertise in web security, with comprehensive knowledge of vulnerabilities and effective exploitation techniques
  • 5+ years of experience in code review, application security testing, or web application development
  • Excellent written and verbal communication skills
  • Proficient programming skills (e.g. Java, Python, Ruby, JavaScript)
  • Experience with cloud platforms, such as AWS, and knowledge of cloud security best practices
  • Familiarity with development technologies like Docker, CDK, Terraform, Java, Python, React, GraphQL, JSON, REST, etc.
  • Must possess a high degree of integrity and confidentiality, as well as the ability to adhere to both company policies and best practices
  • Technical background in application development, networking/system administration, security testing, or related fields
  • Experience with both static application security testing (SAST) and dynamic application security testing (DAST) using various tools and techniques
  • Preferred, but not required - one or more relevant certifications such as Offensive Security Web Assessor (OSWA), Offensive Security Web Expert (OSWE), Offensive Security Certified Professional (OSCP), Burp Suite Certified Practitioner, or AWS Certified Security Specialist.

Shift Timing: - Rotational Shift

At RSM, we offer a competitive benefits and compensation package for all our people. We offer flexibility in your schedule, empowering you to balance life’s demands, while also maintaining your ability to serve clients. Learn more about our total rewards at https://rsmus.com/careers/india.html.

RSM does not tolerate discrimination and/or harassment based on race; colour; creed; sincerely held religious beliefs, practices or observances; sex (including pregnancy or disabilities related to nursing); gender (including gender identity and/or gender expression); sexual orientation; HIV Status; national origin; ancestry; familial or marital status; age; physical or mental disability; citizenship; political affiliation; medical condition (including family and medical leave); domestic violence victim status; past, current or prospective service in the Indian Armed Forces; Indian Armed Forces Veterans, and Indian Armed Forces Personnel status; pre-disposing genetic characteristics or any other characteristic protected under applicable provincial employment legislation.

Accommodation for applicants with disabilities is available upon request in connection with the recruitment process and/or employment/partnership. RSM is committed to providing equal opportunity and reasonable accommodation for people with disabilities. If you require a reasonable accommodation to complete an application, interview, or otherwise participate in the recruiting process, please send us an email at careers@rsmus.com.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security
Cyber Security

RSM US LLP • Hyderabad

On-site
INR 1,500,000 - 2,100,000
Senior Associate 2, ORM Digital
Senior Associate 2, ORM Digital

RSM US LLP • Bengaluru

On-site
INR 1,000,000 - 1,500,000
Flexible scheduling
Competitive benefits package
Cyber Security Strategy, Senior Associate 1
Cyber Security Strategy, Senior Associate 1

RSM US LLP • Gurugram District

On-site
INR 1,200,000 - 2,000,000
Flexible schedule
Senior Associate 2 - ORM Digital
Senior Associate 2 - ORM Digital

RSM US in India • Hyderabad, Bengaluru

On-site
INR 900,000 - 1,300,000
Cyber Security Strategy - Senior Associate 1
Cyber Security Strategy - Senior Associate 1

RSM US in India • Gurugram District

On-site
INR 1,800,000 - 2,600,000
Cyber Security Strategy Senior Associate 1
Cyber Security Strategy Senior Associate 1

RSM US LLP • Gurugram District

On-site
INR 1,200,000 - 2,100,000
Senior Consultant, Offensive Security
Senior Consultant, Offensive Security

Kroll • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Technology Performance Senior Associate
Technology Performance Senior Associate

RSM US LLP • Bengaluru

On-site
INR 800,000 - 1,500,000
Competitive benefits and compensation
Flexible schedule
Technology Risk Consulting Associate 2
Technology Risk Consulting Associate 2

RSM US in India • Gurugram District

On-site
INR 600,000 - 1,200,000
Senior Associate 1, CQRM
Senior Associate 1, CQRM

RSM US LLP • Kolkata District

On-site
INR 600,000 - 800,000
Flexible schedule
Competitive benefits package
Equal opportunity commitment