Web Application & Infrastructure Penetration Tester

OUP

Hinoba-an

On-site

PHP 789,000 - 1,577,000

Full time

12 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Oxford University Press is seeking a Cyber Security & Resilience Testing Specialist to defend digital platforms, services, and data worldwide. You will lead comprehensive penetration testing across web apps, APIs, cloud services, and mobile applications, reporting findings and guiding remediation.

You will work with a skilled security team, contribute to security testing methodologies, and help strengthen OUP's cyber resilience while supporting education-driven initiatives.

Qualifications

  • Experience conducting manual and automated penetration testing of modern web applications and supporting infrastructure.
  • Strong knowledge of application security principles and vulnerability assessment techniques.
  • Deep understanding of the OWASP Top 10 and experience identifying, exploiting, validating, and reporting vulnerabilities.
  • Experience with technologies such as .NET/ASP.NET, Java/Spring, Node.js, Python, PHP, and modern JS frameworks (React, Angular, Vue).
  • Experience performing API security assessments and testing across REST/GraphQL.
  • Excellent written and verbal communication; able to present findings to technical and non-technical audiences.

Responsibilities

  • Conduct comprehensive penetration testing across web apps, APIs, cloud-native services, mobile apps, and supporting infra.
  • Identify, exploit, validate, and document security vulnerabilities with OWASP alignment.
  • Perform SAST and DAST to detect insecure coding and runtime issues.
  • Assess API security including authentication, authorization, and data exposure risks.
  • Produce high-quality reports with findings and actionable remediations.
  • Collaborate with dev, infra, and business teams to improve security outcomes.

Skills

Penetration testing
OWASP Top 10
SAST/DAST
API security testing
Mobile security testing
Security reporting
Collaboration
Threat analysis

Education

Degree in Computer Science or Information Security

Tools

Kali Linux
Nmap
Burp Suite Pro
OWASP ZAP
JWT Toolkits
ffuf
Dirb/GoBuster/Feroxbuster
Metasploit
CrackMapExec/NetExec
WPScan
CMSMap
SQLMap
Nuclei
Wafw00f/LBD

Job description

Select how often (in days) to receive an alert: Create Alert

Location:

Noida Sector 62, UP, IN, 201309

Salary: dependent on skills and experience

Division: Group Technology

Job Title

Department: Cyber Security
Location: Sector - 62, Noida

About the Role
Introduction

At Oxford University Press, we are passionate about advancing learning, education, and research worldwide. As a Cyber Security & Resilience Testing Specialist, you will play a critical role in protecting our digital platforms, services, and data while supporting our mission to make a positive impact through education.

This is an exciting opportunity for an experienced penetration testing professional to join a collaborative and highly skilled Cyber Security team. You will work across a diverse technology landscape, testing modern web applications, APIs, cloud services, mobile applications, and supporting infrastructure. The role offers exposure to a variety of technologies and security challenges, allowing you to continuously develop your expertise while helping strengthen OUP's security posture.

If you are naturally curious, enjoy solving complex security challenges, and are passionate about offensive security and continuous learning, this role offers the opportunity to make a tangible impact across the organisation.

As a Cyber Security & Resilience Testing Specialist, you will:

  • Conduct comprehensive penetration testing activities across web applications, APIs, cloud-native services, mobile applications, and supporting infrastructure.
  • Identify, exploit, validate, and document security vulnerabilities, particularly those aligned to the OWASP Top 10 framework.
  • Perform Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) to identify insecure coding practices and runtime vulnerabilities.
  • Assess API security, including authentication, authorisation, and data exposure risks.
  • Conduct security testing of iOS and Android mobile applications and their supporting backend services.
  • Produce high-quality technical reports that clearly communicate findings, risks, and practical remediation recommendations.
  • Collaborate with development, infrastructure, and business teams to support remediation activities and improve security outcomes.
  • Contribute to the enhancement of security testing methodologies, standards, and best practices across the organisation.
  • Support the ongoing development of OUP's cyber resilience capabilities through proactive identification and management of security risks.
Impact

This role is essential in helping OUP identify and address security weaknesses before they can be exploited. Your expertise will directly contribute to protecting business-critical systems, sensitive information, digital products, and services used by learners, educators, researchers, and employees around the world. Through your work, you will help strengthen organisational resilience and support the delivery of secure and trusted digital experiences.

About You
  • Demonstrable experience conducting manual and automated penetration testing of modern web applications and supporting infrastructure.
  • Strong knowledge of application security principles and vulnerability assessment techniques.
  • Deep understanding of the OWASP Top 10 and experience identifying, exploiting, validating, and reporting vulnerabilities across all categories.
  • Experience testing applications developed using technologies such as:
    • .NET / ASP.NET
    • Java / Spring
    • Node.js
    • Python frameworks
    • PHP frameworks
    • React, Angular, Vue.js, and other JavaScript front-end technologies
    • REST and GraphQL APIs
    • Single Page Applications (SPAs)
  • Experience performing API security assessments.
  • Strong written and verbal communication skills, with the ability to present technical findings to both technical and non-technical audiences.
  • Experience using industry-standard security testing tools, including:
    • Kali Linux
    • Nmap
    • Burp Suite Professional
  • Experience with additional security testing tools such as:
    • OWASP ZAP
    • JWT Toolkits
    • ffuf
    • Dirb, GoBuster, Feroxbuster
    • Metasploit
    • CrackMapExec / NetExec
    • WPScan
    • CMSMap
    • SQLMap
    • Nuclei
    • Wafw00f / LBD
  • Experience conducting mobile application security testing across iOS and Android platforms.
  • Degree in Computer Science, Information Security, or a related discipline.
  • Industry certifications such as OSCP, CEH, CISSP, or equivalent.
Key Attributes
  • Naturally inquisitive, with a desire to investigate beyond the obvious and gain deeper understanding of systems and risks.
  • Analytical and methodical approach to solving complex problems.
  • Ability to translate technical security concepts into practical business-focused recommendations.
  • Strong stakeholder engagement and communication skills.
  • Adaptable, proactive, and committed to continuous professional development.
  • Self-motivated with a focus on delivering high-quality outcomes.
Queries

Please contact aarti.rana@oup.com with any queries relating to this role.

Diversity & Inclusion

We are committed to supporting diversity in our workforce and ensuring an inclusive environment where all individuals can thrive. We seek to employ a workforce representative of the markets that we serve and encourage applications from all backgrounds.

Dependent on skills and experience.

We are committed to supporting diversity in our workforce, and ensuring an inclusive environment where all individuals can thrive. We seek to employ a workforce representative of the markets that we serve and encourage applications from all.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Junior Web Application & Infrastructure Penetration Tester
Junior Web Application & Infrastructure Penetration Tester

OUP • Hinoba-an

On-site
PHP 986,000 - 1,380,000
Web & Cloud Penetration Tester — Security & Resilience
Web & Cloud Penetration Tester — Security & Resilience

OUP • Hinoba-an

On-site
PHP 789,000 - 1,577,000
Junior Web App & Cloud Security Pen Tester
Junior Web App & Cloud Security Pen Tester

OUP • Hinoba-an

On-site
PHP 986,000 - 1,380,000
Penetration Testing Analyst
Penetration Testing Analyst

Sun Life • Philippines

On-site
PHP 600,000 - 900,000
Senior Cloud Engineer Gurugram
Senior Cloud Engineer Gurugram

Economist Group • Hinoba-an

Hybrid
PHP 900,000 - 1,300,000
Private health insurance
Work From Anywhere program
Pension plan
+2
Digital Campaign Executive
Digital Campaign Executive

OUP • Hinoba-an

On-site
PHP 300,000 - 540,000
Project Editor
Project Editor

OUP • Hinoba-an

On-site
PHP 396,000 - 594,000
Editorial Assistant
Editorial Assistant

OUP • Hinoba-an

On-site
PHP 185,000 - 238,000
Penetration Testing Analyst
Penetration Testing Analyst

Sun Life • Manila

On-site
PHP 700,000 - 1,000,000
Annual leave 22-25 days
Maternity leave
Paternity leave
+7
Quality Engineer
Quality Engineer

Informa Group • Hinoba-an

Hybrid
PHP 729,000 - 1,127,000
Salary + bonus
24 days annual leave
4 volunteering days annually
+3