Security Engineer @Nykaa
Location: Mumbai • Full-time • ₹8L – ₹12L *No equity
Job Responsibilities:
- Exploit security flaws and vulnerabilities with attack simulations on multiple application platforms like Android, iOS and Web.
- Ability to flow from black box to gray box to white box tests.
- Ability to effectively work with the engineering teams to provide technical risk. assessment of technologies in networks, applications, code reviews in the release management cycle.
- Ability to perform vulnerability assessments and penetration testing, utilizing tools – commercial and open source.
- Perform, review and analyze security vulnerability data to identify applicability and false-positives.
- Conduct penetration testing in line with Open Web Application Security Project (OWASP)
- Write technical reports that include suggested resolution for identified problem areas and perform operational risk assessment
- Job Experience: 2-4 years minimum
Senior Security Analyst @Fire Compass
Location: Bangalore • Full-time
Job Responsibilities:
- Conduct in-depth cybersecurity assessments (network pen test and applications security assessment), leveraging tools, scripts, manual analysis etc., to provide detailed, high quality findings for our customers
- Gather & Analyse OSINT data from surface web & dark web, to determine level of risk to the organization
- Actively research potential sources of information that can aid open source intelligence gathering (OSINT)
- Create detailed reports & present to customers on regular basis. Help customers prioritize & remediate the findings
- Based on assessment activities, help improve our Online Digital Footprint & Shadow IT Monitoring platform
Job Requirements:
- 2-4 years of experience in pen-testing / red teaming, across network & applications, leveraging OSINT, Commercial Tools & Manual Testing
- OSCP Certification (Nice to have)
- At least a Bachelor’s degree in Computer Science, IT or related field
- Proficiency in at least one programming language
- Experience with Network Vulnerability Assessment Tools like: Nessus, Qualys, NMap
- Experience with Application Security Testing Tools like: Burp Proxy, AppScan, Netsparker, Acunetix
Comments