Software Test Engineering II-Support Services-Applications-CTB

3 - 5 years

5 - 9 Lacs

Posted:1 day ago| Platform: Naukri logo

Apply

Work Mode

Work from Office

Job Type

Full Time

Job Description

Job Summary: The successful candidate will have a strong background in penetration testing, including experience with various tools and techniques used to identify vulnerabilities in web applications and APIs. The ideal candidate will be able to analyze complex systems, identify potential security risks, and provide actionable recommendations for remediation.

Key Responsibilities:

  • Conduct thorough penetration testing of web applications and REST APIs using a variety of tools and techniques
  • Identify vulnerabilities in web applications, including but not limited to:
  • SQL injection
  • Cross-Site Scripting (XSS)
  • Cross-Site Request Forgery (CSRF)
  • Authentication and authorization weaknesses
  • Session management issues
  • Test REST APIs for security vulnerabilities, including but not limited to:
  • Input validation and sanitization
  • Error handling and logging
  • Authentication and authorization mechanisms
  • Data encryption and transmission
  • Analyze results and provide detailed reports outlining findings, recommendations for remediation, and estimated timeframes for implementation
  • Collaborate with development teams to ensure identified vulnerabilities are addressed and remediated in a timely manner
  • Stay up-to-date with the latest security threats, tools, and techniques through ongoing training and professional development

  • Requirements:
  • 3+ years of experience in penetration testing, with a focus on web applications and REST APIs
  • Strong understanding of web application security concepts, including but not limited to:
  • OWASP Top 10
  • Web Application Security Risks (WASR)
  • Secure Coding Practices
  • Experience with various penetration testing tools, including but not limited to:
  • Burp Suite
  • ZAP
  • Nmap
  • AJP
  • SQL injection tools (e.g. sqlmap)
  • Strong understanding of REST API security concepts, including but not limited to:
  • API Security Frameworks (e.g. OAuth 2.0)
  • Data encryption and transmission protocols (e.g. HTTPS)
  • Authentication and authorization mechanisms (e.g. JWT)
  • Experience with scripting languages (e.g. Python, Ruby) is a plus
  • Strong analytical and problem-solving skills
  • Excellent communication and reporting skills

  • Nice to Have:
  • CISSP or equivalent security certification
  • CEH or equivalent penetration testing certification
  • Experience with cloud-based services (e.g. AWS, Azure)
  • Familiarity with Agile development methodologies
  • Experience with DevOps tools (e.g. Docker, Jenkins)

  • What We Offer:
  • Competitive salary and benefits package
  • Opportunities for professional growth and development
  • Collaborative and dynamic work environment
  • Flexible working hours and remote work options
  • Mock Interview

    Practice Video Interview with JobPe AI

    Start Python Interview
    cta

    Start Your Job Search Today

    Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.

    Job Application AI Bot

    Job Application AI Bot

    Apply to 20+ Portals in one click

    Download Now

    Download the Mobile App

    Instantly access job listings, apply easily, and track applications.

    coding practice

    Enhance Your Python Skills

    Practice Python coding challenges to boost your skills

    Start Practicing Python Now
    Kotak Life Insurance
    Kotak Life Insurance

    Insurance

    Jaipur

    RecommendedJobs for You