Security Tester for Pune Capgemini
Job Description: Application Security Testing
Act as a Subject Matter Expert (SME) on application and/or database security
Be part of Center-of-Excellence (CoE) group and work on building up the security testing practice
Perform application vulnerability scans and code reviews using web scanners, database scanners and static code analyzers
Carry out application, database risk, and vulnerability assessments to ensure compliance
Create application security testing methodology and test cases
Perform SDLC assessment
Perform application security architecture assessment
Carry out application security training for different testing teams
Perform Code review using source code analyzer
Required Skills:
Over 4 years of Application Security Experience
Strong familiarity with core application security testing principles
Good working knowledge of application exploitations and their remedies (e.g. Cross Site Scripting, SQL injection attacks, and buffer overflow)
Thorough understanding of application architecture and the various application tier and database tier components (e.g. schemas, database objects, and file system structure.)
Experienced with programming languages commonly used in application development, with the ability to review code for script languages (HTML, JavaScript, PHP, Perl, ASP) and compiled languages (Java, C/C++). Areas such as .Net, SQL, Web 2.0, XML, JBOSS, and Java
Code security assessment including configuring scanners, carrying out scans, prioritizing results, and developing detailed recommendations for remediation
Familiar with key security concepts/frameworks such as OWASP, CVE, and CVSS
Experience with Tomcat, Oracle Application Server, or WebSphere Application Server
Will be an added advantage to have experience with Source Code analyzers/ByteCode scanners (Fortify, Ounce, Coverity, Klocwork, Prefix/Prefast/ Findbugs, FXCop) and able to evaluate the results
RDMS experience, e.g. Oracle or MS SQL Server will be an added advantage
Experience- 4 to 6 years
Location- Pune
anshuman.mukherjee@capgemini.com