company name: quesscorp
job title: application security testing + dast + mpt
experience required: 3-10 years
notice period: immediate / 15 days (max)
location: hyderabad, pune, mumbai, bangalore, chennai, kolkata, gurgaon
description:
qualifications required:
• bachelor's degree or higher in computer science, or equivalent.
• 3-10 years of experience working in the application security, vulnerability assessment, penetration testing, mobile application security, thick client and web api security assessments.
• strong understanding of owasp top 10 vulnerabilities but not limited to.
• proficiency in industry standard vulnerability testing tools like appscan, web inspect, burp suite, zap proxy, fiddler, olly debugger, ida pro, echomirage etc.
• ability to perform manual penetration testing and security assessments using automated tools.
• knowledge of web application components like frontend, backend, databases and application servers.
• understanding in web development technologies like html, css, javascript, php, java, .net and backend databases
• understand on the basic concepts of reverse engineering, memory analysis etc.
• understanding of basic networking protocols such as tcp/ip, dns, http
• understanding of vulnerability classification using national vulnerability database nomenclature such as cve/cvss
• certified information systems security professional (cissp), offensive security certified professionals (oscp), offensive security web expert (oswe), web application penetration tester (gwapt), certified ethical hacker (ceh), or equivalent
preferred:
• experience in web and mobile application security assessments and penetration testing.
• experience with vulnerability analysis tools such as appscan, web inspect, burp suite.
• outstanding english written and oral communication skills and the ability to prioritize work
• strong understanding of web and mobile vulnerabilities.