Penetration Tester
Alignity Solutions Penetration Tester
Summary
You will perform manual and automated web application security testing using the OWASP Top 10 framework in a hybrid, contract-to-hire role based in Hyderabad.
- Jobseeker Video Testimonials
- Employee Glassdoor Reviews
We are an IT Solutions Integrator/Consulting Firm helping our clients hire the right professional for an exciting long-term project. Here are a few details.
Experience:3-8 Years
Requirements
We are looking for an experienced Application Security / Web Penetration Testing professional with strong hands-on expertise in manual and automated security testing of web applications. The ideal candidate should have a solid understanding of the OWASP Top 10, vulnerability assessment methodologies, risk prioritization, and secure remediation practices.
The candidate will be responsible for identifying and validating application security vulnerabilities, assessing their business impact, preparing detailed security reports, and working closely with development and business stakeholders throughout the vulnerability remediation lifecycle.
Key Responsibilities
- Conduct manual and automated security testing of web applications to identify security vulnerabilities and weaknesses.
- Perform application security assessments covering authentication, authorization, session management, input validation, business logic, API security, and other application components.
- Demonstrate strong knowledge and practical application of the OWASP Top 10 framework.
- Identify, validate, and exploit vulnerabilities using appropriate penetration testing methodologies and tools.
- Analyze vulnerabilities and prioritize findings based on:
- Severity
- Exploitability
- Business impact
- Compliance implications
- Exposure and attack likelihood
- Severity
- Perform vulnerability validation and develop Proof of Concept (PoC) demonstrating the impact and exploitability of identified vulnerabilities.
- Prepare comprehensive security assessment and penetration testing reports containing:
- Vulnerability description
- Affected application/component
- Technical details
- Evidence/screenshots
- Proof of Concept
- Risk rating/severity
- Business impact
- Remediation recommendations
- Vulnerability description
- Collaborate with developers, application owners, architects, and other stakeholders to explain security findings.
- Provide practical security guidance and remediation recommendations throughout the vulnerability remediation lifecycle.
- Track identified vulnerabilities and support development teams in understanding and resolving security issues.
- Perform retesting/reassessment of remediated vulnerabilities to confirm that fixes are effective.
- Verify that remediation activities have not introduced new security vulnerabilities or regression issues.
- Present security findings, risk implications, and remediation priorities to technical teams and executive stakeholders.
- Stay current with emerging web application vulnerabilities, attack techniques, security standards, and application security best practices.
Required Technical Skills
- Strong hands-on experience in Web Application Security Testing / Penetration Testing.
- Strong understanding of OWASP Top 10 and common web application vulnerabilities.
- Experience with vulnerabilities such as:
- SQL Injection
- Cross-Site Scripting (XSS)
- CSRF
- Broken Access Control
- IDOR/BOLA
- Authentication & Session Management issues
- Security Misconfiguration
- SSRF
- File Upload vulnerabilities
- Command Injection
- XXE
- Path Traversal
- Business Logic vulnerabilities
- API security vulnerabilities
- SQL Injection
- Experience performing both manual and automated vulnerability assessments.
- Ability to understand application architecture, request/response flows, authentication mechanisms, and APIs.
- Strong ability to validate vulnerabilities and distinguish true positives from false positives.
- Experience creating detailed PoCs and technical security reports.
- Good understanding of vulnerability severity and risk-rating methodologies such as CVSS.
- Knowledge of secure coding and application security remediation practices.