Key Responsibilities: Application & API Security
● Conduct manual and automated penetration testing of web applications and APIs.
● Identify and validate vulnerabilities aligned with OWASP Top 10 and API Security Top 10.
● Perform threat modeling for new features and services.
● Conduct secure code reviews (static analysis) and recommend remediation.
● Validate findings from SAST, DAST, and dependency scanning tools.
● Provide remediation guidance and conduct fix verification testing.
● Participate in design reviews and architecture discussions from a security perspective. Cloud & Infrastructure Security
● Assess AWS/Azure/GCP configurations for common misconfigurations.
● Review IAM policies, storage access controls, and container security posture.
● Validate findings from CSPM/CNAPP tools.
● Support cloud-native application security assessments. Vulnerability Management
● Prioritize vulnerabilities using CVSS and business impact context.
● Track remediation SLAs and support risk acceptance decisions.
● Provide actionable recommendations to development teams. Security Testing & Automation
● Develop scripts and tooling (Python/Bash) to automate testing workflows.
● Improve security testing playbooks and documentation.
● Contribute to enhancing detection and monitoring coverage. Collaboration & Reporting
● Prepare high-quality technical reports with clear risk articulation.
● Translate technical findings into business-impact language.
● Work cross-functionally with DevOps, Cloud, and Engineering teams.