Key Responsibilities Include
- Conduct detailed penetration testing of web applications, mobile applications, thick clients, cloud-native applications, APIs, and network environments using both automated tools and manual testing techniques.
- Experience in security testing of AI chatbots, AI agents, and Model Context Protocol (MCP)-based applications is an added advantage.
- Identify, classify, and prioritize vulnerabilities based on risk and business impact, and prepare detailed reports that include clear findings, evidence, and proof-of-concept details where applicable.
- Collaborate with development and project teams to understand application functionality, identify potential security risks, and support the adoption of secure coding practices.
- Stay current with emerging security threats, vulnerabilities, technologies, and testing methodologies.
- Contribute to the development and improvement of internal security testing tools, methodologies, SOPs, and process documentation.
- Guide project teams on security best practices throughout the software development lifecycle.
Essential Job Requirements
- Bachelors degree in computer science, information security, or a related discipline.
- 4+ years of relevant experience in vulnerability assessment and penetration testing.
- Strong understanding of OWASP Top 10 around Web, API, LLM, Agentic Apps & MCP, SANS Top 25, OSSTMM, PTES, and NIST standards.
- Hands-on experience with leading application security testing tools such as HCL AppScan, Checkmarx, Veracode, and Burp Suite.
- Relevant certifications such as OSCP, OSWE, or CEH are a plus.
- Good conceptual understanding and practical hands-on experience with SAST, DAST, and other security testing approaches relevant to software development.
- Strong foundation in application architecture, development practices, and the software development lifecycle.
- Strong knowledge of secure software development principles, including cryptography, authentication mechanisms, and security protocols.
- Strong English communication skills, both written and verbal.
Other Job Requirements
- Strong communication and presentation skills, with the confidence to engage effectively with stakeholders.
- Ability to work collaboratively and effectively with cross-functional and geographically dispersed teams.
- Willingness to occasionally work outside standard business hours to accommodate global time-zone requirements.
- A proactive, self-motivated team player who performs well under pressure in a global environment.
- Strong organizational skills and the ability to identify and engage sponsors, stakeholders, and key collaborators across the organization.
DISCLAIMER
- Nothing in this job description restricts managements right to assign or reassign duties and responsibilities at any time.
- This job description reflects managements assignment of essential functions and does not prescribe or restrict the tasks that may be assigned.
- This role requires a combination of technical expertise, practical experience, and strong collaboration skills to help strengthen application security across the organization.
Penetration Testing, Vulnerability Assessment, Application Security