Strong understanding of security risks in networks and application platforms
Strong understanding of network security, infrastructure security and application security,
Strong understanding of OSI, TCP/IP model and network basics
Demonstrate technical penetration testing skills on IT infrastructure, web applications, mobile platforms and Red teaming
Strong technical skills: Information security, network security, Windows security, UNIX/Linux security, web and mobile application security, Cloud platforms.
Good knowledge on web,Thick client,API, Mobile (Android,iOS) VAPT and Penetration testing assessments.
Broad knowledge of security technologies for applications, databases, networks, servers, and desktops.
Ability to perform manual penetration testing.
Experience in Application Security Testing, or related functions Vulnerability Assessment, Penetration testing.
Perform penetration testing of various thick client software, web applications, and communications infrastructure to assist in hardening the cybersecurity posture against malicious actors
Perform technical writing to communicate the preparation, testing, and recommendation phases for various security tests. Work with stakeholders to remediate system vulnerabilities.
Expertise in the phases of penetration testing. Familiarity with Kali Linux distribution and the associated penetration testing tools suite. Experience in penetration testing simulations like Hack the Box or Capture the Flag exercises considered a plus.
Good Understanding of OWASP top 10 and mitigation techniques
Experience in performing web application security assessments using hands on techniques for identifying SQL injections, XSS, Security Misconfiguration, CSRF, authentication/ authorization issues
Experience on both commercial, open source tools and frameworks but not limited: Burpsuite, Checkmarx, Metasploit, Core-Impact, Kali-Linux, AppScan, WebInspect, SSLScan, Soap UI Pro, SonarQube, Qualys, Nikto, Nessus, nmap, sqlmap, OWASP ZAP .
Conduct Source code(SAST/SCA) Analysis manually.
Knowledge on scripting language like Python, Shell is an add-on.
Perform Vulnerability Assessment and Penetration Testing (VAPT) for web, mobile, API, network, cloud, and infrastructure components.
Identify, exploit, and document security vulnerabilities using manual and automated techniques.
Conduct source code reviews to detect security flaws.
Develop proof-of-concept (PoC) exploits for validated vulnerabilities.
Prepare detailed technical reports, including findings, severity ratings, and remediation recommendations.
Work closely with product, development, and infrastructure teams to help fix security gaps.
Research the latest vulnerabilities, exploits, attack trends, and security tools.
Participate in red team / blue team exercises when required.
Ensure VAPT activities are aligned with security standards (OWASP, SANS, NIST, ISO 27001, etc.).
Automate repetitive security testing tasks using scripts or tools.
Support compliance audits and security certifications.