Security Consultant (SOFTWARE SECURITY)

(Staff)
Jl. Cimuncang No.29-31, Padasuka, Kec. Cibeunying Kidul, Kota Bandung, Jawa Barat 40125
Bandung - Jawa Barat - Indonesia

DESKRIPSI PEKERJAAN

Conduct security assessments such as penetration and vulnerability tests. Perform Blackbox/Graybox testing of Web/Mobile or Thick client applications. Perform Network Vulnerability Assessments and Penetration Testing. Risk Evaluation of observed vulnerabilities based on common risk scoring techniques such as CVSS. Perform Configuration Review to check compliance with Security Hardening baselines. Keep updated on knowledge of the IT security industry: including awareness of new or revised security solutions, security standards, trends / best practices, offensive techniques, and tools. Knowledge-share with team on techniques and results. Create detailed report of findings and recommendations after testing is complete and present to stakeholders. Coordinate with developers/stakeholders on the findings for appropriate fixes. Prepare project plans, ensure it is followed and track projects until closure. Stay up-to-date in current tools, techniques, and vulnerabilities to incorporate into testing practices. Coordinating with client to give best security solution for them Analyzing the client’s assets and identifying which security measures are needed Establishing security protocols and policies, as well as designing security plans to protect the client’s assets Meeting with clients Coordinating a team of security specialists for both Singapore and Indonesia team
REQUIREMENT

Degree in Computer Science / IT Security or other related disciplines Should have an overall exposure and understanding of Application and Network Security testing (VAPT) Strong knowledge of the OWASP Top 10, OWASP Mobile Top 10, SANS top 25. Detailed knowledge of common web application attack vectors such as SQL injection, CSRF, XSS, Session Management issues, Insecure Direct Object reference, Click jacking, buffer overflows, etc. Experience in manual application penetration testing of web- based applications, thick- client applications, mobile applications, web services, API s etc. Experience in manual mobile application penetration testing on platforms like Android, IOS, etc both client and server side applications. Should have knowledge on Risk Rating Standards like DREAD, CVSS etc. Experience in automated web application vulnerability scanners (e.g. Web inspect, Burp suite Pro, etc) Knowledge in Configuration Review based on standard CIS security hardening baselines or custom baselines Should have performed Black Box / Grey Box Application penetration testing. Experience in performing Network VA using popular tools such as Nessus or Nexpose. Experience in performing Network Penetration Testing for both internal and external networks. Good understanding of application protocols such as HTTP, SAML, OAUTH, OpenID Connect, etc. Good understanding of operation system and common application or services, such as webservice and active directory Good understanding of network technologies and protocols such as NIPS, IDS, TLS/SSL, DLP, firewalls, WAF, DNS and other common technologies and protocols. Knowledge in end-to-end flow on executing application and network penetration testing. Should be able to work as individual contributor or as team player wherever required. Certifications that would be added advantage – OSCP, GIAC Certifications (GWAPT, GPEN) CREST CRT, OWSE, CEH

DETAIL LOWONGAN
  • Umur -
  • Min. Qualification S1/D4
  • Min Experience Staff

LOKASI KERJA

Alamat

Bandung

GAMBARAN PERUSAHAAN

-

https://www.xtremax.com/

100-250

Casual(T-shirt)

Indonesian

Komputer/TI

02220534297

monday - friday

-

FOTO PERUSAHAAN

Lokasi Perusahaan Jl. Cimuncang No.29-31, Padasuka, Kec. Cibeunying Kidul, Kota Bandung, Jawa Barat 40125