Offensive Web & API Security Engineer — Burp Suite
Hrtx
Taguig
On-site
PHP 800,000 - 1,200,000
Full time
14 days+
Application generator
Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.
Get past ATS filters
Job summary
A leading cybersecurity firm is seeking a skilled Web & API Security Engineer to perform security testing on modern web applications and APIs in Metro Manila. The role requires proficiency in identifying vulnerabilities and simulating real-world attacks. The ideal candidate has proven experience in penetration testing and can think like an attacker to uncover hidden risks. You will work closely with engineering teams to enhance the security of our platforms.
Qualifications
Proven experience in penetration testing of web apps and APIs.
Expertise in AuthN/AuthZ vulnerabilities (OAuth, IDOR, BOLA, SSO bypass).
Familiarity with API attack methods (replay attacks, schema issues, parameter pollution).
Responsibilities
Perform manual security testing on web applications and APIs.
Identify vulnerabilities such as logic flaws and authentication bypasses.
Simulate real-world attacks and design potential attack paths.
Skills
Penetration testing
OAuth vulnerabilities
API attack methods
Burp Suite Pro
Scripting (Python/Bash)
Tools
Burp Suite Pro
Postman
sqlmap
jwt_tool
Job description
A leading cybersecurity firm is seeking a skilled Web & API Security Engineer to perform security testing on modern web applications and APIs in Metro Manila. The role requires proficiency in identifying vulnerabilities and simulating real-world attacks. The ideal candidate has proven experience in penetration testing and can think like an attacker to uncover hidden risks. You will work closely with engineering teams to enhance the security of our platforms.