HamburgerMenu
hirist

Web Penetration Test Consultant - Software Quality Assurance

Kezan Consulting
Bangalore
4 - 6 Years
star-icon
3.8white-divider34+ Reviews

Posted on: 22/08/2025

Job Description

Role : Web Penetration Test Consultant

Contract Type : 6 Months (Extendable based on performance/project needs).

Experience : 4+ Years.

Locations : Bangalore and Pune (Onsite/Hybrid as per project requirement).

Start Date : Immediate / As soon as possible.


Job Description :

We are looking for an experienced Web Penetration Test Consultant with strong expertise in identifying security vulnerabilities in web applications and APIs.

The ideal candidate will have at least 4 years of hands-on experience in security assessments and penetration testing, with a deep understanding of web technologies, OWASP Top 10, and secure coding practices.

Key Responsibilities :

- Conduct manual and automated penetration testing of web applications, APIs, and portals.

- Identify, exploit, and document vulnerabilities in web-based applications and recommend appropriate mitigation strategies.

- Prepare detailed security assessment reports including risk ratings and actionable remediation guidance.

- Collaborate with development and security teams to validate fixes and assist in secure code reviews.

- Keep updated with the latest security threats, vulnerabilities, and industry best practices.

- Provide technical guidance and consulting to internal stakeholders on secure web application development.

Required Skills :

- Minimum 4 years of experience in Web Application Penetration Testing.

- Strong understanding of OWASP Top 10, SANS Top 25, and common web application security flaws.

- Hands-on experience with tools like Burp Suite, OWASP ZAP, Postman, Nmap, Nikto, and custom scripts.

- Ability to manually identify and exploit vulnerabilities such as XSS, SQLi, CSRF, SSRF, IDOR, etc.

- Proficiency in writing clear and concise technical reports.

- Familiarity with various web technologies (HTML, JavaScript, REST APIs, etc.

- Knowledge of secure coding practices and ability to conduct code reviews is a plus.

Preferred Certifications (Nice to Have) :

- OSCP / GWAPT / CEH / eWPT or any relevant certification.


info-icon

Did you find something suspicious?