Application Security Engineer / Penetration tester
Growe
WorldwideremotePosted 24 days ago
Skill Required
Application-Security-EngineerPenetration-TesterCybersecurityAPI-SecuritySecurity-EngineeringApplication-Security-TesterApplication-Security-AnalystApplication-Security-SpecialistAppSec-EngineerSecurity-Testing-EngineerSecurity-EngineerSecurity EngineerPenetration TesterApplication DevelopersecurityPenetration TestingCloud SecurityMicroservicesBurp SuiteEngineeringKubernetesNmapGraphQLwrittenTestNGDevOpsOWASPOAuthCloudDesign PatternsAPIsIAMAWSJWTandFulltime
Key highlights
- Required experience: 2-4 years in Application Security, Product Security, or Penetration Testing
- Notable requirement: Deep understanding of OWASP Top 10 and OWASP API Security Top 10
- Notable requirement: Hands-on experience with Semgrep/OpenGrep, Gitleaks, Trivy, OSV-Scanner, Burp Suite Pro, Nuclei, Subfinder, SQLmap, Metasploit, NetExec
- Language requirement: Intermediate English (spoken and written)
- Preferred: Cloud security principles in AWS and Kubernetes (K8s) fundamentals
- Preferred: Ability to read and analyze modern application code for security flaws
Role overview
Responsibilities
- Triage, validate, and prioritize security findings from SAST, SCA, and Secret scanning tools, filter out false positives, assess risks, and track issues through to remediation
- Conduct manual and tool-assisted code reviews to identify security vulnerabilities, logic flaws, and insecure implementation choices before code reaches production
- Perform hands-on penetration testing of web applications, microservices, and APIs to uncover security vulnerabilities and business logic flaws
- Audit REST and GraphQL APIs and web applications with a strong focus on core application security risks, authentication, authorization, and business logic
Requirements
- 2-4 years of experience in Application Security, Product Security, or Penetration Testing
- Hands-on experience triaging and analyzing findings from Semgrep / OpenGrep, Gitleaks, Trivy, and OSV-Scanner
- Experience with Burp Suite (Pro), Nuclei, Subfinder, SQLmap, Metasploit, and NetExec
- Deep understanding of classic OWASP Top 10 vulnerabilities, including Injection flaws (SQLi, Command Injection), Server-Side Request Forgery (SSRF), Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), Broken Access Control / Insecure Direct Object References (IDOR / BOLA), Security Misconfigurations, Cryptographic Failures, Insecure Deserialization, and Mass Assignment
- Solid knowledge of OWASP API Security Top 10 for REST and GraphQL architectures
- Deep understanding of identity protocols and access control mechanics (OAuth 2.0, OIDC, JWT, SAML, RBAC/ABAC)
- Ability to identify complex authorization bypasses, session management flaws, and business logic bugs
- Intermediate level of English (spoken and written)
Nice to have
- Ability to read and analyze modern application code to spot security flaws (will be a plus)
- Understanding of cloud security principles in AWS environments and Kubernetes (K8s) security fundamentals (will be a plus)
- Strong communication skills to effectively collaborate with engineering, product, and DevOps teams
- Result-oriented mindset
- Openness to learning
Additional details
- Core value: GROWE TOGETHER – Our team is our main asset. We work together and support each other to achieve our common goals
- Core value: DRIVE RESULT OVER PROCESS – We set ambitious, clear, measurable goals in line with our strategy and driving Growe to success
- Core value: BE READY FOR CHANGE – We see challenges as opportunities to grow and evolve. We adapt today to win tomorrow
- Originally posted on Himalayas