Role: Consultant Pen Tester with RED teaming experience
Location: Banglore ( Hybrid )
Experience: 8 years
Work Mode: FTE
About the role:
Secure Software applications and infrastructure from potential vulnerabilities and attacks. Drive product privacy and cybersecurity features and enhancements. Ability to work in a fastpaced rapidly changing Agile competitive environment.
Skills Required
Cybersecurity Certifications: CEH / OSCP Preferred.
A professional with a certain level of knowledge and at least 8 years of expertise in Software application pen testing
Knowledge of the DevSecOps framework understanding on NIST OWASP MITRE CWE etc
An understanding of programming languages such as C# Perl JavaScript Python and/or PHP.
Understanding of TCP/IP common networking ports and protocols OSI model
Knowledge of Threat modeling and risk assessment techniques.
Uptodate knowledge of cybersecurity threats current best practices and latest software.
An understanding of programs such as HP Fortify Puppet Chef ThreatModeler Checkmarx and Aqua. They may also need to know Kubernetes/ Docker. Security assessment tools (e.g. NESSUS NMap BurpSuite ZAP OWASP tools Kali Linux tools Fuzzing tools)
Significant knowledge of security best practices for clientserver product architectures focusing predominantly on cloudbased server development
Knowledge of one or more SSO methodologies (SAML LDAP OpenID)
Experience extracting pertinent security data from SIEM solutions and AWS audit logs and reports
Deep product knowledge to ensure the clinical functionality expected operating environment and interoperability to accurately determine a product s privacy and security risks.
Qualification:
Education: B.Tech / M.Tech in CS / IT / EE / EC / EI
Key responsibilities:
Assess architectures and designs for security vulnerabilities and suggest and implement proper alternatives
Oversee the management and remediation of identified security flaws within our development platforms
Build and maintain monitoring auditing and reporting frameworks that produce artifacts that support security and compliance needs
Drive vulnerability assessment and penetration testing (VAPT) activities for multiple R&;D applications implement DEVSECOPS across the product line
CI/CD integration of SAST and DAST platforms.
devsecops framework,pen,security risks,cloud-based server development,zap,testing,kubernetes,security,python,aws audit,mitre,ceh,networking protocols,php,aqua,owasp,osi model,cybersecurity best practices,tcp/ip,kali linux tools,saml,nessus,burpsuite,owasp tools,ldap,nist,product privacy,checkmarx,javascript,m.tech,c#,threat modeling,perl,threatmodeler,openid,sso methodologies,cwe,chef,cybersecurity threats,risk assessment techniques,puppet,nmap,devsecops,hp fortify,oscp,fuzzing tools,networking ports,docker,siem solutions,b.tech