Application Security Penetration Tester

Aryan-Solutions-Pte.-Ltd.

Singapore

On-site

SGD 60,000 - 100,000

Full time

8 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Aryan-Solutions-Pte.-Ltd. in Singapore seeks an experienced Application Security Penetration Tester to assess web applications, APIs, and related environments. You will identify vulnerabilities via penetration testing, SAST/DAST and VAPT, and work with DevOps to enable secure DevSecOps practices.

The role focuses on remediation, risk evaluation against OWASP Top 10, and reporting. You will collaborate with development and security teams to improve secure coding and testing in CI/CD pipelines.

Qualifications

  • 3–8 years of experience in Application Security, Penetration Testing or DevSecOps.
  • Hands-on with SAST/DAST and vulnerability assessment tooling.
  • Knowledge of OWASP Top 10 and common app vulnerabilities.

Responsibilities

  • Perform security assessments across web apps and APIs.
  • Conduct SAST, DAST, and VAPT activities and document findings.
  • Validate vulnerabilities and suggest remediation actions.
  • Evaluate risk against OWASP Top 10 and similar risks.
  • Produce clear assessment reports with severity and remediation.
  • Support remediation and retesting; integrate security tests into CI/CD.
  • Collaborate with DevOps, development and security teams.

Skills

SAST
DAST
VAPT
OWASP Top 10
Burp Suite
OWASP ZAP
Checkmarx
Fortify
SonarQube
Nessus
Qualys
Jenkins
GitLab
GitHub
Azure DevOps
Docker
Kubernetes

Tools

Burp Suite
OWASP ZAP
Checkmarx
Fortify
SonarQube
Nessus
Qualys

Job description

Role Overview

We are seeking an experienced Application Security Penetration Tester to perform security assessments across web applications, APIs, and supporting application environments. The role will focus on identifying and validating vulnerabilities through penetration testing, SAST, DAST, and vulnerability assessment activities.

The successful candidate will also work closely with development and DevOps teams to support vulnerability remediation and integrate security testing into DevSecOps and CI/CD processes.

Key Responsibilities

  • Perform penetration testing and security assessments across web applications and APIs.
  • Conduct Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Vulnerability Assessment and Penetration Testing (VAPT).
  • Identify, validate, assess, and document application security vulnerabilities.
  • Evaluate applications against OWASP Top 10 and other common application security risks.
  • Produce clear security assessment reports covering findings, severity, impact, and recommended remediation.
  • Perform remediation validation and vulnerability retesting.
  • Support Red Team and security testing activities where required.
  • Integrate automated security testing into DevSecOps and CI/CD pipelines.
  • Collaborate with development, DevOps, and security teams to resolve identified vulnerabilities.
  • Provide guidance on secure development and application security best practices.

Required Skills

  • 3-8 years of relevant experience in Application Security, Penetration Testing, VAPT, or DevSecOps Security.
  • Strong hands-on experience with SAST, DAST, and penetration testing.
  • Strong understanding of web application and API security.
  • Good knowledge of OWASP Top 10 and common application vulnerabilities.
  • Hands-on experience with security tools such as Burp Suite, OWASP ZAP, Checkmarx, Fortify, SonarQube, Nessus, or Qualys.
  • Familiarity with CI/CD and DevSecOps environments using tools such as Jenkins, GitLab, GitHub, or Azure DevOps.
  • Understanding of container security and environments such as Docker and Kubernetes.
  • Ability to analyze security findings, distinguish genuine vulnerabilities from false positives, and recommend appropriate remediation.
  • Strong analytical, troubleshooting, documentation, and communication skills.

Preferred Skills

  • Experience with Red Teaming or adversarial security testing.
  • Relevant security certifications such as OSCP, CEH, CREST, or equivalent.
  • Experience working within large enterprise or regulated environments.
  • Familiarity with secure coding practices and Software Development Life Cycle (SDLC) security.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Consultant
Application Security Consultant

Aryan-Solutions-Pte.-Ltd. • Singapore

On-site
SGD 120,000 - 180,000
Application Security Consultant
Application Security Consultant

ARYAN SOLUTIONS PTE. LTD. • Singapore

On-site
SGD 100,000 - 140,000
Senior Penetration Testing Engineer
Senior Penetration Testing Engineer

dtcpay • Singapore

On-site
SGD 120,000 - 180,000
Application Security Engineer (DevSecOps)
Application Security Engineer (DevSecOps)

Envoy Search Partners Pte Limited • Singapore

On-site
SGD 90,000 - 150,000
Application Security Consultant
Application Security Consultant

OX CONSULTANCY PTE. LTD. • Singapore

On-site
SGD 120,000 - 180,000
VAPT Engineer
VAPT Engineer

PCS SECURITY PRIVATE LIMITED • Singapore

On-site
SGD 90,000 - 150,000
Security Remediation Engineer
Security Remediation Engineer

TANGSPAC CONSULTING PTE LTD • Singapore

On-site
SGD 90,000 - 150,000
Penetration Testing Consultant
Penetration Testing Consultant

SWARMNETICS PTE. LTD. • Singapore

On-site
SGD 60,000 - 100,000
VAPT Engineer
VAPT Engineer

PCSS • Singapore

On-site
SGD 60,000 - 90,000
Penetration Tester
Penetration Tester

TechKnowledgey Pte Ltd • Singapore

On-site
SGD 65,000 - 90,000