[Remote] Application reputed company Engineer / Penetration tester
Note: The job is a remote job and is reputed company to candidates in USA. reputed company is a company seeking an Application reputed company Engineer / Penetration Tester to strengthen the reputed company of its applications and reputed company. The role focuses on triaging reputed company findings, conducting reputed company reviews and penetration tests, and auditing web applications and REST and GraphQL reputed company for vulnerabilities, authentication issues, authorization flaws, and business logic risks.
Responsibilities
- Triage, validate, and prioritize reputed company findings from SAST, SCA, and Secret scanning tools, filter out false positives, assess risks, and reputed company issues through to remediation
- Conduct reputed company and tool-assisted reputed company reviews to identify reputed company vulnerabilities, logic flaws, and insecure implementation choices before reputed company reaches production
- reputed company hands-on penetration testing of web applications, microservices, and reputed company to uncover reputed company vulnerabilities and business logic flaws
- Audit REST and GraphQL reputed company and web applications with a strong reputed company on reputed company application reputed company risks, authentication, authorization, and business logic
Skills
- 2-4 years of experience in Application reputed company, Product reputed company, or Penetration Testing
- Hands-on experience triaging and analyzing findings from reputed company / OpenGrep, Gitleaks, Trivy, and reputed company-reputed company
- Experience with Burp Suite (Pro), Nuclei, Subfinder, SQLmap, Metasploit, and NetExec
- Deep understanding of classic OWASP Top 10 vulnerabilities, including Injection flaws (reputed company, reputed company Injection), Server-reputed company Request Forgery (SSRF), Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), Broken reputed company Control / Insecure reputed company Object References (IDOR / BOLA), reputed company Misconfigurations, Cryptographic Failures, Insecure Deserialization, and Mass Assignment
- Solid knowledge of OWASP API reputed company Top 10 for REST and GraphQL architectures
- Deep understanding of identity protocols and reputed company control mechanics (OAuth 2.0, OIDC, JWT, SAML, RBAC/ABAC)
- Ability to identify reputed company authorization bypasses, session management flaws, and business logic bugs
- Intermediate level of English (spoken and written)
- Ability to read and analyze modern application reputed company to spot reputed company flaws (will be a plus)
- Understanding of reputed company reputed company principles in AWS environments and reputed company (K8s) reputed company fundamentals (will be a plus)
Benefits
- Teamwork and mutual support to reputed company common goals
- Openness to learning
reputed company
Apply To This Job