Job Overview
We are seeking a highly skilled and experienced Application
Penetration Tester to join our dynamic team. This role is ideal for someone
with a passion for cybersecurity, a deep understanding of application security,
and the ability to identify and mitigate vulnerabilities. The successful
candidate will play a critical role in ensuring the security of our
applications and guiding our security testing and vulnerability triage.
As part of this project, you will conduct a comprehensive
security assessment of a cloud-native, microservices-based architecture. Your
focus will be on web and mobile applications and cloud security testing,
adversary emulation, and continuous security posture improvement.
You will leverage your expertise in application security,
utilizing tools such as SAST (Static Application Security Testing), DAST
(Dynamic Application Security Testing), and SCA (Software Composition Analysis)
to perform both static and dynamic source code reviews. Additionally, you will
employ threat modeling and threat actor attack pathing to continually validate
the effectiveness of the customer’s security controls.
The primary goal is to ensure that the security controls
implemented by the organization are functioning as intended. By doing so, you
will enhance the overall security defenses and collaborate with global
development teams to maintain the ongoing security of the globally adopted
application.
Job Description Highlights
Security Testing of Developer Operations and Mobile Apps:
· Conduct thorough security testing of developer operations and
mobile applications (iPhone and Android).
· Identify security issues and vulnerabilities.
Source Code Reviews:
· Perform in-depth source code reviews to identify
security flaws or weaknesses.
Executing Tests/Assessments and
Drafting Reports:
· Execute detailed assessments and compile
findings into reports for further review and action.
Tools and Technologies:
Experience with tools like Burp Suite Pro, Checkmarx,
Corellium, Synopsys, Acunetix, VeraCode, SAST & DAST Tools, Plextrac, Cloud
security (AWS / Azure / Oracle), Postman, SmartBear ReadyAPI, SoapUI, and
Hashicorp Vault
Beyond a role, joining OnDefend means becoming part of a
community dedicated to making a difference. We offer:
Health and Wellness
Financial Benefits
Work-Life Balance
Professional Development
Company Culture
Additional Perks