Senior Penetration Tester / Application Security Engineer

We are looking for a Senior Penetration Tester / Application Security Engineer to perform a comprehensive security assessment of a web application and its APIs.

Project start: approximately Q4
Engagement: project-based / part-time
Main scope: Web Application & API Penetration Testing

Tech Stack
Drupal with significant custom development
Vue.js frontend and admin panel
Java backend
MongoDB
React Native for iOS and Android (mobile pentesting may be added later)
Responsibilities
Perform manual penetration testing of the web application and admin panel
Conduct API security testing
Test authentication, authorization, and role-based access controls
Identify business logic and security vulnerabilities
Assess the application against OWASP Top 10 and OWASP API Security risks
Prepare a professional penetration testing report with severity levels, vulnerability descriptions, evidence, and remediation recommendations

Requirements
Strong hands-on experience in Web Application and API Penetration Testing
Strong manual pentesting skills, not only automated scanning
Solid experience with Burp Suite and standard security testing tools
Experience testing custom-built web applications
Experience preparing professional pentest reports
Experience with Java, Drupal, or Vue.js is a plus
Mobile application pentesting experience is a plus, but not required

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available