Role: Security Tester
- ๐บ๐ธ United States
- On-site
- 9 months ago
- SAST
- DAST
- Nessus
- Devops
- Penetration Testing
- CI/CD
- Agile
- OWASP
- CVSS
- XSS
- CSRF
- Python
- Bash
- PowerShell
- AWS
- Azure
- GCP
Location: Carmel, Indiana (All 5 Days onsite)
Contract positionl
Overview
We are seeking aSecurity Tester with strong hands-on experience inApplication Security Testing, Vulnerability Assessment, SAST/DAST tools, and secure code review. The ideal candidate must have expertise inCheckmarx, Nessus, IBM AppScan, and other vulnerability scanning tools. This role requires ahands-on security engineer capable of identifying vulnerabilities, validating security issues, and collaborating with DevOps, QA, and engineering teams to ensure secure application development.
Responsibilities
-
Performapplication security testing using SAST/DAST tools such asCheckmarx, IBM AppScan, and Nessus.
-
Conductvulnerability assessments,penetration testing, andsecure code reviews for web and mobile applications.
-
Analyze scan reports, validate vulnerabilities, and provide remediation guidance to development teams.
-
PerformAPI security testing, including authentication, authorization, token validation, and payload manipulation.
-
Implementsecurity best practices across SDLC and CI/CD pipelines.
-
Document vulnerabilities, risk ratings, remediation steps, and mitigation strategies.
-
Work with cross-functional teams (Dev, QA, DevOps, Cloud) to ensure secure application design.
-
Maintain security testing documentation, test cases, and guidelines.
-
Continuously evaluate and integrate new security tools, techniques, and frameworks.
-
Experience working inAgile environments with sprint-based security testing.
Skills
-
Hands-on experience with Checkmarx (SAST), Nessus (Vulnerability Scanning), and IBM AppScan (DAST).
-
Strong understanding ofOWASP Top 10, CWE, CVE, CVSS scoring, and secure coding principles.
-
Experience withAPI security, including token security, session management, and injection-based attacks.
-
Knowledge ofWeb and API vulnerabilities, such as XSS, CSRF, SQLi, authentication bypass, IDOR, SSRF, RCE, etc.
-
Ability to analyzeSAST/DAST scan results and validate false positives.
-
Hands-on scripting skills (Python, Bash, or PowerShell preferred).
-
Familiarity withcloud security concepts (AWS/Azure/GCP).
-
Strong documentation and reporting skills.
Role: Security Tester ยท Han IT Staffing