V
Penetration Test Engineer
Bengaluru, Karnataka, India · Full Time
Be the first to apply
- Experience
- 8+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 3 weeks ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About the Role
We are seeking a highly skilled Penetration Test Engineer specializing in application security, with a minimum of 8 years of experience. The primary responsibility is to carry out penetration tests for a broad range of web applications and APIs, ensuring robust security practices and vulnerability management.
Key Responsibilities
- Perform penetration testing on diverse web applications and APIs utilizing tools such as Burp Suite.
- Conduct comprehensive code reviews from a security perspective, leveraging strong programming and scripting expertise in languages like Java, JavaScript, and Python.
- Utilize SAST and DAST automated vulnerability assessment solutions, including analyzing and filtering false-positive reports.
- Apply in-depth knowledge of the OWASP Top 10 vulnerabilities, their underlying causes, and effective mitigation strategies.
- Integrate and automate security validations within continuous integration and deployment (CI/CD) pipelines.
- Execute penetration tests across multiple technology stacks and environments.
- Possess thorough understanding of network security, encryption protocols, access control mechanisms, and identity management.
- Conduct security assessments, vulnerability scans, and penetration activities to identify and remediate risks.
- Operate with various security tools and technologies, including Static Application Security Testing (SAST), Interactive Application Security Testing (IAST), and Dynamic Application Security Testing (DAST).
- Have knowledge and experience in cloud security best practices, including container security.
- Familiarity with incident response procedures and detailed root cause analyses.
- Understand and apply secure software development lifecycle (SDLC) methodologies.
- Participate in security audits, compliance evaluation, and subsequent remediation efforts.
Location
This position is based in Bangalore, Karnataka, India, with potential assignments across other Apple locations in India.