Experience
8 - 10 yrs
Salary (CTC)
₹12.6L - ₹18.2L
Job Location
Hyderabad, India
Vacancy
1
Designation
Information Security Engineer
Job Type
Not specified
Job Description
Job Summary
As a Consultant - Info Security Engineer, you will have the outstanding opportunity to collaborate with world-class professionals in Hyderabad, Telangana, India.
Youll play a crucial role in ensuring the security and integrity of our applications, both on-premises and in the cloud, by performing security penetration testing. This position is for those who are ambitious and determined to make a significant impact in the field of information security.
Responsibilities
- Perform manual security penetration assessments of web applications and APIs hosted within on-premises infrastructure.
- Conduct security assessments on web applications and APIs deployed in cloud environments using AWS services such as S3 buckets, EC2 instances, Lambda functions, API Gateway, and SNS.
- Apply re-engineering techniques using tools like Echo Mirage, IDAPro, CFF Explorer, Dnspy, MS sys-internals, Wireshark, dotpeek, and ghidra for thick client/desktop applications.
- Manage Vulnerability Disclosure Program (VDP) and Bug Bounty reports with detailed technical validation, consistent assessment of impact and severity, and fair evaluation aligned with policies.
- Use CVSS scoring mechanisms to assess risk levels of identified vulnerabilities.
- Innovatively identify techniques to exploit vulnerabilities in applications, generate impactful proof-of-concepts (POCs), provide walkthroughs to app-dev teams, and offer remediation mentorship.
- Write comprehensive reports and update existing documentation.
- Work independently and multi-functionally, mentoring peers and junior team members, helping them learn and apply new attack techniques during security testing.
Qualifications
- Bachelor s or Master s degree in Computer Science, Technology, Engineering, Mathematics, or related fields, or equivalent professional experience (B.E. / B.Tech / M.S. / M.Tech / MCA).
- 8-10 years of practical experience in security assessment of web applications, web APIs, thick client apps, mobile apps, and AWS services, preferably within the finance domain.
- Proficiency in using web/API testing tools such as Burp Suite, Postman, and OWASP ZAP.
- Practical experience with Kali and performing advanced security assessments of applications.
- Detailed knowledge of common web application security vulnerabilities (OWASP Top Ten, SANS Top 25, etc.), programming patterns leading to them, and remediation techniques.
- AWS Cloud Practitioner Certification or other cloud certifications are helpful.
- Additional security certifications like C|EH, CPent, etc., are a plus.
- Plus/Good to Have Experience in conducting security assessments of AI applications.
- Understanding of server-less architectures and micro-services on AWS.
