- Conduct in-depth VAPT assessments across web mobile (Android & iOS) APIs network infrastructure and server environments.
- Utilize both manual and automated testing methodologies to uncover vulnerabilities.
- Prepare comprehensive reports detailing vulnerabilities their impact exploitability and recommended remediation strategies.
- Work closely with development and DevOps teams to validate prioritize and resolve security issues including retesting post-remediation.
- Support secure DevOps operations deployment pipelines and platform maintenance.
- Demonstrated understanding of standalone and managed Kubernetes clusters CI/CD tools and platform engineering principles.
- Practical experience in cloud platforms such as AWS GCP and Huawei Cloud.
- Integrate security testing tools (SAST DAST IAST) into CI/CD pipelines for continuous security validation.
- Automate repetitive security tasks to enhance operational efficiency and consistency.
- Stay informed on industry standards and frameworks such as OWASP Top 10 SANS Top 25 and MITRE ATT&CK.
- Apply the latest threat vectors and attack techniques in validation and testing activities.
Requirements
- Minimum 3 years of hands-on experience in vulnerability assessment offensive security or application security.
- Proven ability to assess and test web applications mobile platforms APIs servers and network infrastructures.
- Strong familiarity with DevOps practices CI/CD pipelines and cloud environments in enterprise settings.
- Proficient in using tools like Burp Suite Metasploit Nessus Nmap and similar security platforms.
- Sound knowledge of security standards and frameworks such as OWASP SANS MITRE and NIST.
- Experience with manual and automated secure code review processes.
- Comfortable scripting with Python Bash PowerShell or equivalent languages.
- Excellent communication skills with the ability to articulate technical vulnerabilities and risks to both technical and non-technical audiences.
- Possession of relevant certifications is a plus including eJPT OSCP eCPPT PNPT OSWE.
Extensive background in managing and supporting distributed systems. Proficient in troubleshooting tools and techniques for Java and C++ based services. Skilled in identifying and resolving performance issues across backend systems, databases, message brokers, and load balancers. Hands-on experience with DevOps tools such as Jenkins, Terraform, and Helm charts. Familiar with system monitoring solutions, particularly Prometheus. Deep knowledge of databases, Kubernetes, various load balancers, and Google Cloud Platform (GCP). Strong background in Linux/Unix system administration and solid understanding of operating system fundamentals.