Thorough understanding of OWASP Top 10, their attack & defence mechanisms
-
Exposure to Secure SDLC Activities, Threat Modelling & Secure Coding
-
Experience on both commercial and open source tools like Burpsuite, AppScan, OWASP ZAP, BEEF, MetaSploit, Qualys, Nessus, Synk etc.
-
Identifying & exploiting business logic-related vulnerabilities.
-
Solid understanding of Cryptography, knowledge of PKI-based systems, TLS
-
Understanding of different AuthN/AuthZ frameworks (OIDC, oAuth, SAML) able to read/write/understand java code
-
Performed Static Analysis, Code reviews using tools like Snyk, Veracode, Checkmarx, Sonarqube etc.
-
Hands on Reversing mobile applications, class/small files, data obfuscators, or ciphers (Dex2jar, adb, Drozer, Clang, iMAS) and Dynamic Instrumentation tools like Frida/Objection
-
Execute penetration tests and security assessments on internal and external networks, Windows and Linux environments, cloud (AWS) Infrastructure.
-
Identify and exploit incorrect configurations and security vulnerabilities on Windows and Linux servers. Safely utilize tools, tactics, and procedures used in penetration testing engagements.
-
Shell scripting or automation of simple tasks using Python, or Ruby
-
Knowledge of PA-DSS, PCI SSF (S3, SSLC) etc.
-
Knowledge of security standards like PCI DSS, UIDAI, GDPR, NIST etc.
-
Understanding of Java Frameworks like Springboot, CI/CD, Jenkins.
-
In-depth understanding of production operations on public cloud infrastructure.
-
Excellent written and oral communication and a penchant for technical documentation.
-
Must have participated in various bug bounty programs (HackerOne, Bug Crowd, Private etc).