| Job Description: |
REQ 10888263
Role Descriptions:
Must have a knowledge and hands on experience of tools such as Burp Suite, WebInspect, Postman, and similar utilities are used to intercept requests, analyze application behavior, identify vulnerabilities, and verify security controls beyond automated scan results. • Define the approved testing scope, application URLs, APIs, user roles, creation of security test cases and testing window before starting the activity. • Use Burp Suite to capture, modify, replay, and validate web/API requests for issues such as broken access control, injection, XSS, CSRF, session weaknesses, and insecure headers. • Use WebInspect for guided dynamic testing and to support validation of application-level security findings. • Use Postman to test API endpoints, authentication tokens, authorization logic, request parameters, response data exposure, and negative test cases. • Manually verify all findings to remove false positives and document evidence, impact, severity, affected endpoints, and recommended remediation.
Essential Skills: Application Security Testing, Postman,Burpsuit,API security and Mobile security. Must have hands on experiance in doing manual PT of the application Desirable Skills: Keyword: Skills: Data Quality~Automated QA - TestComplete Experience Required: 4-10 YEARS |