Job Description
Job Description Strong knowledge of the OWASP, SANS top 25, WASC security Standards and detailed knowledge of common web application attack vectors such as SQL injection, CSRF, XSS, Session Management issues, Direct Object reference, Click jacking, buffer overflows, etc. Experience in manual application penetration testing of thick client applications, mobile applications, web services, APIs etc. Thorough understanding of common web technologies like .NET,rnPHP, Java, XML, SAML, SOA, SOAP, web services etc and protocols includingrnHTTP(S), DNS, FTP, SSH etc. Had performed manual mobile application penetration testing on platforms like Android, IOS etc. Should have knowledge on Risk Rating Standards like DREAD, CVSS etc. Good understanding of web application architecture and Secure development life cycle(SDLC). Experience in threat modelling and risk analysis. Experience in automated web application vulnerability scanners (e.g., AppScan, Web inspect, Accunetix, Burpsuite Pro, etc) is desirable. Should be ready to travel within and outside the country. Preparing audit reports and findings tracker sheets for each application in the provided template. Communicate with customer teams to explain and demonstrate vulnerabilities to application/system owners, and assist with the mitigation of the identified vulnerabilities. Researching the latest security best practices, staying abreast of new threats and vulnerabilities and helping to disseminate this information within the group as well as the organization.
Employement Category:
Employement Type: Full time
Industry: Recruitment Services
Role Category: Security Services
Functional Area: Not Applicable
Role/Responsibilies: Senior Information Security Consultant
Contact Details:
Company Name: entagon Consultancy
Location(s): Delhi, NCR
Keyskills:
ganizational
teamw