This job ad has been posted over 30 days ago...



Associate Information Security Consultant/ Information Security Consultant Full-time

at Secureyes in Mumbai (Published at 25-10-2018)

About SecurEyes - SecurEyes is a pure-play information security consulting firm which started in 2005 with global offices & presence at India, UAE, Oman, KSA & USA. It specializes on Risk Assessment, GRC Consulting, Information Security Training and on-demand information security consulting. Our clients include large Government Organizations, Banks & Financial Services Institutions, International Airlines, Large Trading Houses and Public sector companies across the globe. We are technically focused with passion, integrity and with a strong belief in providing world-class services to our clients to create a difference in their information security environment.
Job Title – Associate Information Security Consultant/ Information Security Consultant
Job Location – Mumbai
Experience – 1 to 2 years
CTC – As per Industry Standard
Job Description
• Strong knowledge of the OWASP, SANS top 25, WASC security Standards and detailed knowledge of common web application attack vectors such as SQL injection, CSRF, XSS, Session Management issues, Direct Object reference, Click jacking, buffer overflows, etc.
• Experience in performing application security testing using manual techniques and automated tools along with runtime vulnerability testing tools.
• Experience in static and dynamic secure code review.
• Experience in manual application penetration testing of thick client applications, mobile applications, web services, API’s etc.
• Thorough understanding of common web technologies like .NET, PHP, Java, XML, SAML, SOA, SOAP, web services etc and protocols including HTTP(S), DNS, FTP, SSH etc.
• Had performed manual mobile application penetration testing on platforms like Android, IOS etc.
• Should have knowledge on Risk Rating Standards like DREAD, CVSS etc.
• Experience in VA/PT of networks, servers, devices etc.
• Good understanding of web application architecture and Secure development life cycle(SDLC).
• Experience in threat modelling and risk analysis.
• Understanding of software development methodologies such as waterfall, Rational Unified Process and Agile software development.
• Experience in automated web application vulnerability scanners (e.g., AppScan, Web inspect, Accunetix, Burpsuite Pro, etc) is desirable.
• Should be ready to travel within and outside the country.
• Perform web, thick-client, mobile application security assessments (using manual and automated penetration testing methods) and code reviews, with report preparation.
• Preparing audit reports and findings tracker sheets for each application in the provided template.
• Communicate with customer teams to explain and demonstrate vulnerabilities to application/system owners and assist with the mitigation of the identified vulnerabilities.
• Researching the latest security best practices, staying abreast of new threats and vulnerabilities and helping to disseminate this information within the group as well as the organization.
• Conceive of and implement technical and process improvements.
• Maintaining the quality of audit and audit report.
• Experience in training sessions on Information security awareness.
• Enhancing the technical skill sets of the team members.

Skills required/Expertise
• 1-3 years of proven experience in application security domain
• A Bachelor or a Master’ s degree in B. E/ B. Tech/ M. Tech/ M.S.
• Proficient in written and oral English communication skills.
• Expertise in web application security testing.
• Expertise in mobile application security testing.
• Strong organizational, teamwork, multi-tasking and time-management skills.

Share resume at

Recent jobs at Secureyes

Viewed: 717 times
« Go back to category
Is this job ad fake? Report it!   
Recommend to a friend