Role Overview
We are looking for a Cybersecurity & Development Engineer who can work across both cybersecurity and software development. The ideal candidate should be comfortable understanding security vulnerabilities, performing security assessments, developing security-focused applications and tools, and automating repetitive security processes. This role is ideal for someone who enjoys working at the intersection of Application Security, VAPT, Automation, APIs, Web Development, and Security Engineering.
Responsibilities
- Perform Vulnerability Assessment and Penetration Testing (VAPT) for web applications, APIs, networks, and other technology environments.
- Identify, validate, and document security vulnerabilities including OWASP Top 10, API Security risks, authentication/authorization issues, injection vulnerabilities, XSS, SSRF, IDOR, misconfigurations, etc.
- Conduct basic security testing using tools such as Burp Suite, Nmap, Nessus/OpenVAS, OWASP ZAP, Metasploit, and similar security tools.
- Develop internal cybersecurity tools, dashboards, scripts, APIs, and automation solutions.
- Build integrations between security tools, APIs, databases, and internal systems.
- Automate repetitive cybersecurity activities using scripting and programming.
- Develop security checks that can be integrated into CI/CD pipelines.
- Assist in implementing DevSecOps practices.
Requirements
- Strong understanding of VAPT methodologies and OWASP Top 10.
- Familiarity with Burp Suite, Nmap, Nessus / OpenVAS, OWASP ZAP, Metasploit, and Wireshark.
- Strong programming knowledge in at least one of the following: Python, JavaScript / TypeScript, Node.js, Java, PHP, or Go.
- Experience with REST APIs, JSON, Git/GitHub/GitLab, SQL, and authentication mechanisms such as JWT/OAuth.
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field is preferred.
- 1–4 years of experience in cybersecurity, software development, application security, or a related technical role.