Infosys
Website:
infosys.com
Company:
https://www.linkedin.com/company/infosys
Seniority: Not Applicable
Industries: IT Services and IT Consulting
Job details:
- 3+ years of experience in Application Security Testing, Vulnerability Assessment, and Security Validation.
- Strong hands-on experience with DAST tools such as Burp Suite Pro, HCL AppScan, Acunetix, Netsparker, or equivalent.
- Solid understanding of Web, API, and Cloud Security concepts.
- Knowledge of OWASP Top 10, OWASP API Security Top 10, CVSS, CWE, and Secure SDLC practices.
- Experience in vulnerability reporting, risk analysis, remediation validation, and stakeholder communication.
- Understanding of authentication protocols such as OAuth 2.0, OpenID Connect (OIDC), SAML, JWT, and MFA.
- Experience with Cloud Security (Azure/AWS/GCP) and container security assessments.
- Exposure to SAST, SCA/OSS Security Testing, API Security Testing, and Threat Modeling methodologies.
Key Responsibilities Automation Testing
- Design, develop, and maintain automation frameworks using Selenium WebDriver with Java or C#.
- Develop and execute automated test scripts for Web, API, and Enterprise applications.
- Build reusable automation libraries and utilities.
- Integrate automation suites with CI/CD pipelines.
- Perform regression, smoke, sanity, and functional testing using automated frameworks.
- Analyze test results and provide detailed defect reports.
- Collaborate with developers, business analysts, and QA teams to ensure quality deliverables.
- Participate in test planning, estimation, and test strategy discussions. Security Testing
- Perform comprehensive Security Testing and Assessment activities across applications, APIs, cloud environments, and supporting infrastructure.
- Execute Dynamic Application Security Testing (DAST), Vulnerability Assessments, and Security Validation activities using industry-standard tools and methodologies.
- Conduct manual and automated security testing to identify vulnerabilities related to authentication, authorization, session management, encryption, access controls, and business logic flaws.
- Assess applications against industry standards and frameworks such as OWASP Top 10, OWASP API Security Top 10, CWE, NIST, and SANS.
- Identify, analyze, prioritize, and document security vulnerabilities with detailed risk ratings, business impact analysis, and remediation guidance.
- Perform false-positive analysis, vulnerability validation, and retesting to verify remediation effectiveness.
- Collaborate closely with Development, Architecture, QA, and DevSecOps teams to promote secure coding practices and integrate security into the Software Development Life Cycle (SDLC).
- Perform security reviews, threat assessments, and risk-based security evaluations for new and existing applications.
- Participate in vulnerability management activities including triage, tracking, risk acceptance reviews, and remediation validation.
- Prepare detailed security assessment reports and effectively communicate findings, risks, and recommendations to technical and non-technical stakeholders.
- Conduct false-positive analysis and provide remediation recommendations.
- Validate authentication, authorization, session management, encryption, and access control mechanisms.
- Support compliance initiatives and security governance requirements Preferred Skills
- Experience in IAM Security Testing (Saviynt, SailPoint, Access Governance testing).
- Exposure to Performance Testing tools such as JMeter or LoadRunner.
- Experience working in DevSecOps environments.
- Knowledge of container technologies such as Docker and Kubernetes.
- Scripting knowledge in Python, PowerShell, or Shell scripting.
Click on Apply to know more.