GrepJob
Commvault

Senior Application Security Tester

Commvault
Apply
about 3 hours ago
Bengaluru, India
Senior
H1B Sponsor

Responsibilities

  • Perform detailed application security testing (DAST, SAST, IAST) on internal and customer-facing applications.
  • Lead threat modeling and security assessments across the SDLC for both on-premises and cloud-hosted environments.
  • Utilize automated security testing tools to identify security vulnerabilities.
  • Manually validate and prioritize security issues identified by automated scans.
  • Collaborate with DevOps, Engineering, and Cloud teams.
  • Provide remediation guidance to development teams and validate fixes.
  • Conduct code reviews and perform secure code analysis as necessary.
  • Stay current on emerging threats, vulnerabilities, and industry trends in application security.
  • Document findings clearly and concisely for both technical and non-technical audiences.
  • Mentor junior security testers and contribute to overall security program improvements.

Requirements

  • Bachelor’s degree in computer science, Cybersecurity, Information Technology, or related field.
  • 5+ years of experience in application security testing or offensive security.
  • Deep understanding of OWASP Top 10, CWE/SANS Top 25, and other security best practices.
  • Hands-on experience with testing applications hosted in AWS, Azure, or GCP environments.
  • Familiarity with RESTful APIs, microservices architecture, and container security.
  • Experience in testing GenAI solutions.
  • Strong command of scripting languages for custom testing and automation.
  • Experience with security testing tools such as Fortify, Checkmarx, Veracode, Burp Suite Pro, and OWASP ZAP.
  • Solid understanding of secure SDLC and DevSecOps principles.

Benefits

  • Continuous professional development, product training, and career pathing.
  • Annual health check-ups and Tuition Reimbursement.
  • An inclusive company culture with opportunities to join Community Guilds.
  • Personal accident cover and Term life cover.

Tech Stack

AWSAzureBashDockerGoogle Cloud PlatformKubernetesPowerShellPythonTerraform

Categories

Security