Application Security Penetration Tester
Gefragte Skills
Stellenbeschreibung
Role Overview
We are seeking an experienced Application Security Penetration Tester to perform security assessments across web applications, APIs, and supporting application environments. The role will focus on identifying and validating vulnerabilities through penetration testing, SAST, DAST, and vulnerability assessment activities.
The successful candidate will also work closely with development and DevOps teams to support vulnerability remediation and integrate security testing into DevSecOps and CI/CD processes.
Key Responsibilities
Perform penetration testing and security assessments across web applications and APIs.
Conduct Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Vulnerability Assessment and Penetration Testing (VAPT).
Identify, validate, assess, and document application security vulnerabilities.
Evaluate applications against OWASP Top 10 and other common application security risks.
Produce clear security assessment reports covering findings, severity, impact, and recommended remediation.
Perform remediation validation and vulnerability retesting.
Support Red Team and security testing activities where required.
Integrate automated security testing into DevSecOps and CI/CD pipelines.
Collaborate with development, DevOps, and security teams to resolve identified vulnerabilities.
Provide guidance on secure development and application security best practices.
Required Skills
3–8 years of relevant experience in Application Security, Penetration Testing, VAPT, or DevSecOps Security.
Strong hands-on experience with SAST, DAST, and penetration testing.
Strong understanding of web application and API security.
Good knowledge of OWASP Top 10 and common application vulnerabilities.
Hands-on experience with security tools such as Burp Suite, OWASP ZAP, Checkmarx, Fortify, SonarQube, Nessus, or Qualys.
Familiarity with CI/CD and DevSecOps environments using tools such as Jenkins, GitLab, GitHub, or Azure DevOps.
Understanding of container security and environments such as Docker and Kubernetes.
Ability to analyze security findings, distinguish genuine vulnerabilities from false positives, and recommend appropriate remediation.
Strong analytical, troubleshooting, documentation, and communication skills.
Preferred Skills
Experience with Red Teaming or adversarial security testing.
Relevant security certifications such as OSCP, CEH, CREST, or equivalent.
Experience working within large enterprise or regulated environments.
Familiarity with secure coding practices and Software Development Life Cycle (SDLC) security.
Application Note
Interested applicants may send their CV directly to shyam@aryan-solutions.com for consideration.
Quelle: mycareersfuture.gov.sg. Für die Inhalte der Inserate übernehmen wir keine Haftung.
Bewerbungstext erstellen
Wir erstellen aus deinem Profil und dieser Stelle einen Entwurf. Du prüfst und passt ihn an.
Nur mit Konto verfügbar.
Jetzt anmelden