Job DescriptionMust Have Skills:
· Strong API Automation Skills
· Experienced in Rest API Testing & SQL
Required Experience:
· 6+ years of IT experience with minimum 3 years of experience in Application Security including Code Security Review.
· Professional certification or designation in information security. An application security focused certification or designation is preferred. (e.g., GPEN, OSCP, etc.)
· Hands-on-experience in using industry standard tools for Penetration Testing and Source Code Review such as BurpSuite, OWASP ZAP, Fortify, Veracode etc.
· Support/lead operational application security activities including but not limited to penetration tests, mobile tests secure code review
· Provide advisory services to IT teams to support remediation of vulnerabilities
Essential Skills:
· Web Application Security (including web, mobile, API)
· Knowledge of AppSec industry practices (including OWASP)
· Understanding of SDLC and Agile Methodology
· Code and Architecture review
· Security Tools and technology (BurpSuite, ZAP, Fortify, Nessus etc.)
· Excellent communication
Desirable Skills:
· Good familiarity with industry specific programming languages such as C/C++, .NET, Java, Cobol, Python, etc.
· Strong development experience in 1 or 2 programming languages
RequirementsMust Have Skills: • Strong API Automation Skills • Experienced in Rest API Testing & SQL Required Experience: • 6+ years of IT experience with minimum 3 years of experience in Application Security including Code Security Review. • Professional certification or designation in information security. An application security focused certification or designation is preferred. (e.g., GPEN, OSCP, etc.) • Hands-on-experience in using industry standard tools for Penetration Testing and Source Code Review such as BurpSuite, OWASP ZAP, Fortify, Veracode etc. • Support/lead operational application security activities including but not limited to penetration tests, mobile tests secure code review • Provide advisory services to IT teams to support remediation of vulnerabilities Essential Skills: • Web Application Security (including web, mobile, API) • Knowledge of AppSec industry practices (including OWASP) • Understanding of SDLC and Agile Methodology • Code and Architecture review • Security Tools and technology (BurpSuite, ZAP, Fortify, Nessus etc.) • Excellent communication Desirable Skills: • Good familiarity with industry specific programming languages such as C/C++, .NET, Java, Cobol, Python, etc. • Strong development experience in 1 or 2 programming languages