Penetration Tester|| Application Security Enginer
Budget: $15 – $25 USD
I'm seeking an experienced penetration tester to perform a full-scope test on my web application. An intricate understanding of web applications and their vulnerabilities is crucial.
Your responsibilities would include:
- Identifying vulnerabilities within my web app
- Suggesting and implementing proper security measures
- Ensuring all functionalities and components are secure
• Developed secure SDLC policies and standards for Web apps. Built Application Security (AppSec) program from scratch.
• Perform Internal and external penetration tests against systems to identify vulnerabilities.
• Collaborate with the application development teams and develop test cases, which can check the security of applications, databases and authentication mechanisms.
• Experience using a wide variety of security tools to include Kali-Linux, Checkmarx CxSAST, CxIAST, Burp Suite Pro, Wireshark, Nmap, Nessus, Metasploit, and Nexpose.
• Involved in implementing and validating the security principles of minimum attack surface area, least privilege, secure defaults, avoiding security by obscurity, keep security simple, Fixing security issues correctly. Strong knowledge in Manual and Automated Security testing for Web Applications.
• Automation of security scanning process (DevSecOps) into the build environment with CI/CD pipeline using Codefresh, Maven, Gradle, GitHub tools.
• Participate in security testing to include source code Analysis, dynamic application security testing using open source and commercial tools.
• Performed APP code reviews, attesting compliance with the PCI-DSS security requirements.
• Reviewing Java and .Net programming language for security vulnerabilities.
• Perform analysis on test results and recommends remediation necessary.
• Worked on security protocols such as TCP/IP, SNMP, SMTP, NTP, DNS, LDAP and NFS on implementation, maintenance and monitoring.
• Create and maintain all the needed Security Center Dashboards.
• Working knowledge of OWASP Top 10 and SANS Top 25 software guidelines, Federal Financial Institutions Examination Council’s (FFIEC) regulations, including Payment Card Industry (PCI-DSS), and HIPAA.
• Performed security Risk analysis and gap analysis.
• Analyzed the results of penetrations tests, design reviews, source code reviews and other security tests.
• Participated in the implementation of AWS Cloud security for applications being deployed in the Cloud.
• Reviewed AWS Web Application Firewalls (WAF) and configured the rules and conditions to detect security vulnerabilities in the Cloud Front.
• Performed Continuous Integration (CI) and Continuous Delivery (CD) of SAST scans using Checkmarx.
• Performed Source Code repositories (GitHub), AWS IAM Roles, Users, Groups and Policies security assessments in order to build secure environment.
• Decided on what to remediate and what to risk accept based on security requirements.
• PCI-DSS Compliance Audit experience on controls like User access management, Change Management, Incident Management.
• Good Experience in exploiting the recognized vulnerabilities.
• Participate in the development of IT risk assessments for enterprise applications. The PCI, NIST framework has been utilized for IT risk assessments.
Experience in application security engineering and security engineering would be advantageous but is not mandatory. I'm looking forward to hearing strategies or methodologies you would implement to provide a robust security layer to my application.
Your responsibilities would include:
- Identifying vulnerabilities within my web app
- Suggesting and implementing proper security measures
- Ensuring all functionalities and components are secure
• Developed secure SDLC policies and standards for Web apps. Built Application Security (AppSec) program from scratch.
• Perform Internal and external penetration tests against systems to identify vulnerabilities.
• Collaborate with the application development teams and develop test cases, which can check the security of applications, databases and authentication mechanisms.
• Experience using a wide variety of security tools to include Kali-Linux, Checkmarx CxSAST, CxIAST, Burp Suite Pro, Wireshark, Nmap, Nessus, Metasploit, and Nexpose.
• Involved in implementing and validating the security principles of minimum attack surface area, least privilege, secure defaults, avoiding security by obscurity, keep security simple, Fixing security issues correctly. Strong knowledge in Manual and Automated Security testing for Web Applications.
• Automation of security scanning process (DevSecOps) into the build environment with CI/CD pipeline using Codefresh, Maven, Gradle, GitHub tools.
• Participate in security testing to include source code Analysis, dynamic application security testing using open source and commercial tools.
• Performed APP code reviews, attesting compliance with the PCI-DSS security requirements.
• Reviewing Java and .Net programming language for security vulnerabilities.
• Perform analysis on test results and recommends remediation necessary.
• Worked on security protocols such as TCP/IP, SNMP, SMTP, NTP, DNS, LDAP and NFS on implementation, maintenance and monitoring.
• Create and maintain all the needed Security Center Dashboards.
• Working knowledge of OWASP Top 10 and SANS Top 25 software guidelines, Federal Financial Institutions Examination Council’s (FFIEC) regulations, including Payment Card Industry (PCI-DSS), and HIPAA.
• Performed security Risk analysis and gap analysis.
• Analyzed the results of penetrations tests, design reviews, source code reviews and other security tests.
• Participated in the implementation of AWS Cloud security for applications being deployed in the Cloud.
• Reviewed AWS Web Application Firewalls (WAF) and configured the rules and conditions to detect security vulnerabilities in the Cloud Front.
• Performed Continuous Integration (CI) and Continuous Delivery (CD) of SAST scans using Checkmarx.
• Performed Source Code repositories (GitHub), AWS IAM Roles, Users, Groups and Policies security assessments in order to build secure environment.
• Decided on what to remediate and what to risk accept based on security requirements.
• PCI-DSS Compliance Audit experience on controls like User access management, Change Management, Incident Management.
• Good Experience in exploiting the recognized vulnerabilities.
• Participate in the development of IT risk assessments for enterprise applications. The PCI, NIST framework has been utilized for IT risk assessments.
Experience in application security engineering and security engineering would be advantageous but is not mandatory. I'm looking forward to hearing strategies or methodologies you would implement to provide a robust security layer to my application.