Live opening · Posted 18 days ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
Responsibilities:
Conducted vulnerability assessments, penetration testing, and source code review.
Automate technical tasks in CI/CD through the use of APIs or tools.
Perform application source code security reviews for APIs, middleware, and frontends in Java, Python, Node.js, etc.
Exploit security flaws and vulnerabilities with attack simulations on multiple application platforms like Web, iOS, Android, and cloud platforms.
Perform SAST and DAST and improve SDLC.
Develop solution architecture and blueprints based on business technology and security objectives.
Research and maintain secure coding guidelines.
Perform a security architecture and low-level application security design review involving data protection, authentication and authorization, web application security, and network security.
Collaborate with product teams to build secure products and achieve the cybersecurity objectives of InMobi.
Maintain an active understanding of industry practices for secure software development and incident response.
Requirements:
Zealous to unlearn and relearn cybersecurity practices in a cloud-native DevOps-only environment.
3-6 years of experience in application security, penetration testing, and DevSecOps.
2-3 years of experience in building and managing security gating in Checkmarx or an equivalent tool.
2-3 years of experience in manual security code review.
Standardize and maximize automation in the CI/CD pipeline.
Excellent skills with application security testing tools such as Suite, OWASP ZAP, SQLMap, Kali, etc.
Experience with scripting languages such as Python, bash, PowerShell, etc.
Experience in building and deploying open-source security software in production and making it scalable.
Knowledge of Kubernetes and Docker containers.
Knowledge of OWASP Top 10 and SANS Top 25
Red Teamer with proven skills in exploitation.
Strong understanding of security fundamentals and general security technologies.
Excellent oral and written communication skills and a good team player.
Bug bounties, responsible disclosure awards, and the Hall of Fame are strongly preferred.
Certifications such as GWAPT, Offensive Security Certified Professional (OSCP), OSCE, or GIAC Penetration Testing (GPEN) are strongly preferred.
Experience
5-9 yrs
More openings worth a look
Recently tracked roles with full details and direct application links.