About the role
OSTTRA India
The Role: Application Penetration Tester
The Team: The OSTTRA Technology team is composed of Capital Markets Technology professionals, who build, support and protect the applications that operate our network. The technology landscape includes high-performance, high-volume applications as well as compute intensive applications, leveraging contemporary microservices, cloud-based architectures.
The Impact: Together, we build, support, protect and manage high-performance, resilient platforms that process more than 100 million messages a day. Our services are vital to automated trade processing around the globe, managing peak volumes and working with our customers and regulators to ensure the efficient settlement of trades and effective operation of global capital markets.
What's in it for you:
Osttra is seeking an application penetration tester for role Technology Security Analyst (Associate) to join the Global Security team reporting to the Information security and GRC Director.
This is an excellent opportunity to be part of a team based out of Gurgaon and to work with colleagues across multiple regions globally.
Role Description:
We are seeking a motivated and detail-oriented Application Penetration Tester with approximately 1-2 year of experience to join our growing security team. The ideal candidate will possess a strong understanding of web application vulnerabilities, penetration testing methodologies, and security best practices. You will be responsible for conducting thorough security assessments of our applications, identifying vulnerabilities, and providing actionable recommendations for remediation.
Responsibilities:
Conduct comprehensive penetration testing of web applications, mobile applications, and APIs using industry-standard methodologies (e.g., OWASP, PTES).
Identify and exploit vulnerabilities, including but not limited to SQL injection, cross-site scripting (XSS), cross-site request forgery (CSRF), and authentication/authorization flaws.
Perform vulnerability assessments.
Document and report findings in a clear and concise manner, including detailed steps for remediation.
Collaborate with development teams to ensure vulnerabilities are addressed effectively.
Stay up-to-date with the latest security threats, vulnerabilities, and penetration testing techniques.
Utilize penetration testing tools such as Burp Suite, OWASP ZAP, and Metasploit.
Contribute to the development and maintenance of security testing procedures and documentation.
Perform code reviews for security vulnerabilities.
Required Skills and Qualifications:
1-2 years of experience in application penetration testing.
Strong understanding of web application vulnerabilities and security principles.
Familiarity with common penetration testing tools and techniques.
Knowledge of OWASP Top 10 and other relevant security standards.
Ability to analyze and interpret vulnerability scan results.
Excellent written and verbal communication skills.
Strong problem-solving and analytical skills.
Understanding of network protocols (TCP/IP, HTTP, etc.).
Basic knowledge of cloud security.
Preferred Certifications:
CompTIA PenTest+, Certified Ethical Hacker (CEH), Offensive Security Web Application Exploitation (OSWE) or any other relevant security certifications.
Education:
Bachelor's degree in Computer Science, Information Security, or a related field (or equivalent experience).
About the company
OSTTRA is a market leader in derivatives post-trade processing, bringing innovation, expertise, processes and networks together to solve the post-trade challenges of global financial markets. OSTTRA operates cross-asset post-trade processing networks, providing a proven suite of Credit Risk, Trade Workflow and Optimisation services. Together these solutions streamline post-trade workflows, enabling firms to connect to counterparties and utilities, manage credit risk, reduce operational risk and optimise processing to drive post-trade efficiencies.
OSTTRA was formed in 2021 through the combination of four businesses that have been at the heart of post trade evolution and innovation for the last 20+ years: MarkitServ, Traiana, TriOptima and Reset. These businesses have an exemplary track record of developing and supporting critical market infrastructure and bring together an established community of market participants comprising all trading relationships and paradigms, connected using powerful integration and transformation capabilities.