Responsibilities
- Conduct vulnerability assessments, threat modeling, and penetration testing of web applications to identify security vulnerabilities and weaknesses.
- Perform code reviews and analyze application designs to identify and mitigate security risks.
- Develop and implement secure coding standards and practices for application development.
- Collaborate with the software team to integrate security into the software development life cycle (SDLC) and assist in setting up the security pipeline for integration.
- Provide guidance and recommendations to the software team on how to remediate identified security vulnerabilities and weaknesses.
- Participate in all security-related initiatives such as bug bounty programs, hacker challenges, and penetration tests, and assist in defining the scope and testing approach for all assessments or programs.
- Engage in incident response activities, triage, investigate, and respond to security incidents.
- Stay up-to-date with the latest security threats, vulnerabilities, and technologies.
- Report to the Cyber Security Manager.
Requirements
- Bachelor's degree in computer science, information security, or a related field.
- 2+ years of experience in an application security role.
- Strong knowledge of web application security concepts and techniques.
- Experience with programming languages, such as Java, Python, and .NET.
- Familiarity with web application development frameworks, such as Spring and React.
- Knowledge of security standards and frameworks, such as OWASP, NIST, and ISO.
- Strong analytical and problem-solving skills.
- Excellent written and verbal communication skills.
Nice to Have
- Experience with vulnerability assessment and penetration testing tools, such as Burp Suite, Nmap, and Metasploit, will be an advantage.
- Understanding of cloud service providers and their offerings, preferably AWS, and its technologies and services will be an advantage.
Team
Reports to: Cyber Security Manager
Additional Information
- Candidates with less experience will be considered for the role of Application Security Analyst.