#TestingDNA
Job Opening for Application Security Testing Professionals
Experience : 3 - 5 Years
Job Location : Mumbai
Email : lalitn@sonyocareers.com
Phone : N/A
Website : N/A
Job Description :
- 3+ years of experience with both a detailed technical knowledge and hands-on practice working in penetration testing, secure software development or QA and 3+years of experience in cloud and application-level security architecture
- Advanced knowledge of web architectures, APIs, mobile applications, desktop applications, and cloud architectures
- Expert knowledge of secure application architectures, encryption technologies, cryptography and key management, authentication and control of application permissions, and implementation of same
- Experience with a broad range of attack classes and malware, their workings, and propagation methods
- Experience securing platform web APIs
- Leading code reviews, pen-tests, or similar projects
- Experience with a wide selection of security tools (code scanners, fuzzing, using proxies in security testing, etc.)
- Experience building security testing tools and scripts for specific environments and use cases, and the ability to craft proof of concept exploits to demonstrate issues
- Experience bringing security designs and secure development practices into Agile development environments, QA teams, and Product planning
- Ability to perform threat modeling or use other risk identification techniques
- Strong background in development, security testing, and writing security user stories and detailed technical specifications for security in application and product designs
- Detailed knowledge ofweb, mobile, and client application security vulnerabilities, attack methods, and countermeasure techniques
- Knowledge of web, and mobile application development and programming languages including Java, C#, C++, Objective C etc.
- Knowledge of security bug classification frameworks such as CVSS and DREAD, and experience applying security bug classification methods in development and QA
- Knowledge of e-commerce payment systems (credit card, debit card, bank transfers), fraud prevention measures to protect against e-commerce fraud etc.
- Results driven, creative, professional, persistent, quality oriented, and self-motivated work style
Skills / Experience (desired) - Strong programming and scripting skills
- Conversant with Linux, Windows, OSX, Oracle DB, SQL Server
- Familiarity with EMC, and VMWare
- Experience with PCI, Sarbanes Oxley, ISO 27001/27002, NIST 800-53, and HIPAA and Privacy regulations
- Certifications ? CISSP/ISSAP, CISSP