HamburgerMenu
hirist

Job Description

Description :



We are looking for a skilled Security Analyst with 3- 5 years of experience in application and cloud security.

The candidate will be responsible for performing LAMP-based web application security testing, REST API security testing, and AWS cloud infrastructure security assessments. The role focuses on improving the organizations overall application security posture and supporting compliance and audit requirements.

Key Responsibilities :



- Perform manual and automated PAN Testing for LAMP-based web applications (Linux, Apache, MySQL, PHP).



- Conduct REST API security testing, including authentication, authorization, input validation, and rate limiting checks.


- Identify vulnerabilities such as OWASP Top 10, business logic flaws, and configuration issues. Validate vulnerability fixes and perform re-testing.


- Assess AWS cloud infrastructure security.


- Security Posture Improvement


- Work closely with development and DevOps teams to shift security left. Provide actionable remediation guidance to engineering teams.


- Help define and improve secure coding practices and security standards. Support secure SDLC and DevSecOps initiatives.

Compliance & Governance :


- Assist in meeting compliance requirements such as ISO 27001, SOC 2, FEDRAMP, etc Support internal and external security audits.


- Maintain security documentation, risk assessments, and vulnerability reports.



Required Skills & Qualifications :

Technical Skills :



- 3- 5 years of hands-on experience in application security testing.


- Strong understanding of LAMP stack security.



- Experience with REST API security testing (Postman, Burp Suite, OWASP ZAP). Hands-on experience securing AWS cloud infrastructure.


- Knowledge of OWASP Top 10, CWE, and common attack vectors.


- Familiarity with vulnerability scanning tools (e.g., Nessus, Qualys, Snyk, etc.). Understanding of authentication mechanisms (OAuth, JWT, API keys).



Tools & Technologies :



- Burp Suite, OWASP ZAP, Postman


- AWS Security tools (IAM, GuardDuty, Inspector, CloudTrail) Git, CI/CD pipelines (security integration preferred)


- Linux command line

Preferred Qualifications :



- Security certifications such as CEH, OSCP, GWAPT, AWS Security Specialty, or CISSP (Associate).


- Experience with DevSecOps and CI/CD security automation. Knowledge of container security (Docker, EKS) is a plus.


- Scripting knowledge (Python, Bash) is an advantage.


The job is for:

May work from home
info-icon

Did you find something suspicious?

Similar jobs that you might be interested in