Application Offensive Security Engineer
Application Offensive Security Engineer
Location: Jersey city, NJ
Contract
Must have a good background in testing applications (I'm not looking for a know-it-all). Just a honest resume that reflects experience in application security testing and some red teaming. The ideal candidate would be someone who has been in application security for the last 5-6 years consistently, (I don't require certifications), someone who knows how to test manually applications and not just vulnerability scanning because we already have a team that performs that function), someone who has enjoyed Capture The Flags and loves to tinker in applications; anything else would be a bonus.
- Perform Offensive Security Testing against applications and APIs.?
- Perform application threat hunting to evaluate risk to applications.
- Perform manual security testing of applications.
- Provide the vulnerability information in the predefined report format after performing the testing using manual methodology and tools
- Generate reports on assessment findings and summarizes to facilitate remediation, document technical issues identified during security assessments
- Be a subject matter expert and respond to any security engineering questions/ requests related to Application Defense enhancements
- Collaborate with Security Architects, Product Manager, Risk Managers, and other teams to deliver high quality product.
- Minimum of 6 years of experience in testing web applications
- Minimum of 4 years of hands-on experience with App PenTest tools such as Burp Suite and Owasp Zap
- Ability to think outside the box and manually discover vulnerabilities and weaknesses in OWASP Top 10 without scanning
- Understanding of MITRE Framework and adversarial methodologies
- Bachelor s Degree and/or equivalent experience
Application Offensive Security Engineer
Location: Jersey city, NJ
Contract
Must have a good background in testing applications (I'm not looking for a know-it-all). Just a honest resume that reflects experience in application security testing and some red teaming. The ideal candidate would be someone who has been in application security for the last 5-6 years consistently, (I don't require certifications), someone who knows how to test manually applications and not just vulnerability scanning because we already have a team that performs that function), someone who has enjoyed Capture The Flags and loves to tinker in applications; anything else would be a bonus.
- Perform Offensive Security Testing against applications and APIs.?
- Perform application threat hunting to evaluate risk to applications.
- Perform manual security testing of applications.
- Provide the vulnerability information in the predefined report format after performing the testing using manual methodology and tools
- Generate reports on assessment findings and summarizes to facilitate remediation, document technical issues identified during security assessments
- Be a subject matter expert and respond to any security engineering questions/ requests related to Application Defense enhancements
- Collaborate with Security Architects, Product Manager, Risk Managers, and other teams to deliver high quality product.
- Minimum of 6 years of experience in testing web applications
- Minimum of 4 years of hands-on experience with App PenTest tools such as Burp Suite and Owasp Zap
- Ability to think outside the box and manually discover vulnerabilities and weaknesses in OWASP Top 10 without scanning
- Understanding of MITRE Framework and adversarial methodologies
- Bachelor s Degree and/or equivalent experience