Job Description
1. To test, re-test (as needed) and validate Countermeasures implemented by the Development and DevOps team in response to identified Threats / Vulnerabilities and confirm that remediation efforts are effective, complete, and secure.
2. To confirm that the application meets defined security standards post-remediation activities without impacting the compliance expectations.
Duties and Responsibilities
o Testing and confirming the implemented Remediation measures
1) Run the steps to exploit identified/known Threats / Vulnerabilities and validate that they have been properly fixed. Verify and confirm that the issue is no longer exploitable by executing various scenarios including original and edge-case scenarios
2) Evaluate the correctness and completeness of implemented security controls such as:
a. Input validation
b. Authentication & session handling
c. Access control logic (RBAC, ABAC)
d. Output encoding/sanitization
e. Secure configuration (headers, SSL/TLS settings)
o Regression and Impact analysis - Ensure that the remediation measures do not break other security features or introduce new vulnerabilities. Perform regression testing on the related functionality.
o Risk-based testing
Tests to be conducted based on threat models, business criticality, and data sensitivity.
Focus on high-risk areas like authentication, PHI dataflows, admin functionalities, etc.
o Test Reports submission and Documentation
a. Document test results
b. Maintain Countermeasures, Threats / Vulnerabilities tracker updates and evidence (e.g., screenshots, logs, PoCs)
c. Provide improvement feedback where countermeasures could be more robust.
o Collaboration
Work closely with DevOps Team, Design and Development team, Security team, and QA team to conduct the tests and verification activities
Where applicable, share technical feedback to help developers implement more secure solutions
Job Classification
Industry: Software Product
Functional Area / Department: Engineering - Software & QA
Role Category: Software Development
Role: Software Development - Other
Employement Type: Full time
Contact Details:
Company: Nest Digital
Location(s): Bengaluru
Keyskills:
Cism
remediation
HP data protector
Access management
Enterprise applications
Network security
Javascript
Vulnerability
microsoft
SDLC