job description
- perform web applications, thick client applications, mobile applications, api and network penetration testing.
- perform black-box, and grey-box testing, as well as build proof-of-concepts to demonstrate the severity of findings.
- hands-on experience in performing automatic and manual pen testing on application, network, systems and large enterprise infrastructure understanding of web-based application (owasp top 10) vulnerabilities.
- working knowledge of industry standard risk, governance and security standard methodologies
- hands-on experience on various scanning tools like kali, nessus, nmap, metasploit, burp suite, etc.
- conduct penetration testing of it infrastructure (os, web & db), network and security devices using various vulnerability assessment tools
- map out a network, discover ports and services running on the different exposed network and security devices
- analyse scan reports and suggest remediation / mitigation plan
- audit configuration of network and security devices should have experience on it infra .