Role Overview
The Application Security Engineer (VAPT & API) will be responsible for protecting clients' web applications and APIs by serving as the subject matter expert (SME) for the Web Application Firewall (WAF) service. This role requires a strong offensive security mindset to conduct comprehensive vulnerability assessments and translate findings into effective policies to maintain a robust defense against emerging threats.
Responsibilities
- Perform Vulnerability Assessments and light Penetration Testing on client web applications and APIs to identify critical security flaws.
- Provide effective mitigation strategies for vulnerabilities including the OWASP Top 10 and OWASP API Security Top 10.
- Evaluate the security of modern API architectures, including REST and GraphQL, focusing on OAuth, JWT, and authorization flaws.
- Collaborate with development and DevOps teams to advise on secure coding practices and security architecture.
- Conduct forensic analysis of WAF logs to identify new attack vectors and adjust mitigations.
- Stay current with CVEs and threat intelligence to rapidly deploy compensating controls.
Requirements
- Minimum 3+ years of experience in an Application Security or Penetration Testing role.
- Expert-level knowledge of HTTP/HTTPS, TCP/IP, and TLS/SSL.
- Proficiency with security tools such as Burp Suite Professional and OWASP ZAP.
- Solid understanding of attack techniques like SQLi, XSS, SSRF, and Command Injection.
- Strong understanding of API security mechanisms (BOLA, BFLA).
Skills
- Burp Suite Professional
- OWASP Top 10
- REST & GraphQL
- Vulnerability Assessment
- WAF
Nice to Have
- Industry certifications such as OSCP, CEH, CISSP, or GWEB.
- Experience with Bot Management and Layer 7 DDoS mitigation.
- Familiarity with container security and microservices.
- Experience in a client-facing service provider environment.