DL
Penetration Tester
Diverse Lynx India
Location not stated
Mid level
3 weeks ago
- OWASP
- Penetration Testing
- XSS
- SQL Injection
- CSRF
- Burp Suite
- Kali Linux
- Nmap
- Nessus
- Wireshark
- Postman
- CVSS
- Vulnerability Management
- SAST
- DAST
- Threat Modeling
- Qualys
- HTML
- CSS
- JavaScript
- REST API
3 weeks ago
We are looking for an experiencedWeb Application Security Engineer / Penetration Tester with 5+ years of hands-on experience inWeb Application Security, VAPT, OWASP, and manual penetration testing.
Key Responsibilities
- Performmanual and automated penetration testing of web applications and APIs.
- Identify and exploit vulnerabilities based onOWASP Top 10 and industry security standards.
- Conduct security testing forXSS, SQL Injection, CSRF, IDOR, authentication/authorization, session management, and other application vulnerabilities.
- Use tools such asBurp Suite, Kali Linux, Nmap, Nessus, Wireshark, SQLMap, and Postman.
- Perform vulnerability assessments, validate findings, eliminate false positives, and assign severity usingCVSS.
- Prepare detailed vulnerability reports including evidence, business impact, risk, and remediation recommendations.
- Collaborate with developers and infrastructure teams to resolve security findings.
- PerformAPI security testing, security architecture reviews, and secure code reviews.
- Support vulnerability management, security dashboards, remediation tracking, and closure activities.
- Stay updated with emerging application security threats, attack techniques, and testing methodologies.
Web Application Security | VAPT | Penetration Testing | OWASP Top 10 | Burp Suite | Kali Linux | XSS | SQL Injection | CSRF | IDOR | Authentication & Authorization | API Security | Postman | Nmap | Nessus | SQLMap | CVSS | Vulnerability Management
Good to have: SAST/DAST, Secure SDLC, Threat Modeling, Fortify, Qualys, Acunetix, Security Architecture, Mobile Application Security, and cloud security.
Qualifications
- 7+ years of hands-on experience inWeb Application Security / VAPT / Penetration Testing.
- Strong understanding of web technologies such asHTML, CSS, JavaScript, HTTP/HTTPS, and REST APIs.
- Good communication skills with the ability to explain technical vulnerabilities and remediation to developers and business stakeholders.
Penetration Tester · Diverse Lynx India