- Company Name
- COGNIZANT
- Job Title
- Penetration/Security Tester
- Job Description
-
**Job Title:** Penetration/Security Tester
**Role Summary:**
Conduct comprehensive penetration testing of APIs and web applications, identify security weaknesses, document findings, and collaborate with development teams to remediate vulnerabilities while ensuring compliance with industry standards such as OWASP, CREST, ISO 27001, and PCI‑DSS.
**Expectations:**
• Deliver high‑quality, repeatable test plans and detailed vulnerability reports with clear risk ratings.
• Communicate findings effectively to technical and non‑technical stakeholders.
• Advocate continuous improvement of security testing processes and tooling.
• Retest fixed issues and validate remediation effectiveness.
**Key Responsibilities:**
- Review design and interface documents to define testing scope.
- Prepare test plans, scenarios, and rules of engagement in line with CREST and OWASP.
- Perform API penetration tests (REST, GraphQL, SOAP) focusing on authentication, authorization, and business‑logic flaws.
- Conduct UI/Web application tests for XSS, CSRF, SQL Injection, click‑jacking, session management, CSP/CORS, and other common vulnerabilities.
- Document security issues with reproducible steps, evidence, and remediation recommendations.
- Log defects in tracking tools and collaborate with development teams for timely resolution.
- Provide regular status updates to stakeholders and proactively raise risks or challenges.
- Create comprehensive test reports with executive summaries, technical details, and CVSS‑based risk ratings.
- Support re‑testing and validate remediation effectiveness.
- Ensure adherence to OWASP ASVS, API Top 10, ISO 27001, PCI‑DSS, and other relevant compliance frameworks.
- Recommend security best practices and contribute to evolving testing methodologies.
**Required Skills:**
- CREST‑backed penetration testing expertise (API & UI/Web).
- Deep knowledge of OWASP Top 10, OWASP API Top 10, ASVS, CVSS scoring, CREST methodologies.
- Proficient with Burp Suite Pro, OWASP ZAP, Postman, SoapUI, Nmap, Metasploit, SQLMap, jwt‑tool, Kali Linux toolset.
- API security: REST/GraphQL/SOAP testing, OAuth2/OIDC, JWT, rate limiting, BOLA/BFLA.
- Web security: XSS, CSRF, SQL Injection, click‑jacking, session management, CSP/CORS.
- Strong documentation and reporting: test plans, risk logs, vulnerability reports.
- Familiarity with ISO 27001, PCI‑DSS, NIST guidelines.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent professional experience).
- CREST certification (CRT, CPT, CPSA) or equivalent security testing certification.