Epicareer Might not Working Properly
Learn More

Security Tester

Salary undisclosed

Apply on


Original
Simplified

Required Skills:

  • Strong knowledge of Security Testing methodologies, including Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST).
  • Hands-on experience with penetration testing of large and complex systems, including web, mobile, and enterprise applications.
  • Familiarity with industry-standard security testing tools, such as OWASP ZAP, Burp Suite, Nessus, Veracode, or Fortify for both SAST and DAST.
  • Understanding of secure coding practices and the ability to assess vulnerabilities related to CWE, OWASP Top 10, and SANS Top 25 vulnerabilities.

Preferred Skills:

  • Experience in threat modeling and understanding attack vectors and security flaws within large systems.
  • Strong knowledge of network security protocols, application security, and database security.
  • Familiarity with manual code reviews and identifying vulnerabilities in source code.
  • Knowledge of compliance standards such as ISO 27001, NIST, GDPR, or PCI-DSS.

Responsibilities:

  • Demonstrate that the developed system conforms to security requirements as specified in the Functional Requirements Document.
  • Conduct comprehensive Static Application Security Testing (SAST) to identify vulnerabilities in the application source code.
  • Perform Dynamic Application Security Testing (DAST) to uncover runtime vulnerabilities in applications and services.
  • Conduct in-depth penetration testing to simulate real-world attacks and identify security weaknesses that could be exploited by attackers.
  • Ensure that system results are based on the requirements provided and aligned with security best practices.
  • Collaborate with developers to mitigate identified vulnerabilities and ensure that proper security controls are implemented.
  • Produce detailed Test Analysis Reports that outline security vulnerabilities, test results, and remediation recommendations.
  • Serve as the QA lead for security, ensuring that the system meets all specified security requirements before release.

Expected Deliverables:

  • Creation of security test scripts and execution plans.
  • SAST, DAST, and Penetration Test Reports with identified vulnerabilities and remediation steps.
  • Test Analysis Reports documenting the overall security testing process and results.
  • Recommendations for mitigation strategies and improving system security.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
Report this job