As a Junior Security Analyst specializing in WEB, Network or Mobile Penetration Testing, you will assist in identifying vulnerabilities and assessing the security posture of mobile applications. You will work under the guidance of senior team members, helping to conduct mobile penetration tests, analyze mobile application security, and contribute to delivering high-quality security assessments for mobile platforms.
Skills
- Burp Suite
- Frida
- MobSF
- API
- SQL
- OWASP ZAP
Requirements
- Job Role Junior Security Analyst -WEB, NETWORK, MOBILE TESTING
- Job Type Full Time
- Workplace Type Onsite
- Industry
Computer and Network Security
Secondary locations
Not provided
Responsibilities
Mobile penetration tests Responsibility:
Key Responsibilities, Deliverables / Outcomes:
- Assist in performing mobile penetration tests on both iOS and Android applications (manual and automated).
- Identify, exploit, and document vulnerabilities such as insecure data storage, improper session management, and API vulnerabilities under guidance.
- Conduct vulnerability assessments on mobile applications using both manual testing techniques and automated tools.
- Use tools like Burp Suite, Frida, MobSF, and other mobile-specific security tools for mobile application testing.
- Assist in testing APIs used by mobile applications for security flaws such as broken authentication, insecure communication, and authorization vulnerabilities.
- Analyze mobile application architectures and workflows to identify potential security risks related to data leakage, insecure code, and other mobile-specific vulnerabilities.
- Document security findings, weaknesses, and suggested remediation steps in detailed reports.
- Collaborate with senior team members to refine findings and ensure professional-grade reports are delivered to clients.
- Ensure that mobile testing tools and systems are kept up-to-date to maximize efficiency and to address emerging mobile security threats and vulnerabilities.
- Stay updated with the latest trends in mobile application security, emerging vulnerabilities, exploits, and penetration testing techniques.
- Participate in internal training sessions, contribute to team knowledge sharing, and enhance your expertise in mobile application security.
- Follow industry standards, such as OWASP Mobile Security Testing Guide and OWASP
- Mobile Top 10, and other relevant guidelines during mobile security assessments.
- Adhere to internal and client-specific security policies to ensure compliance with industry best practices and security regulations
Web Penetration Testing Responsibility:
Key Responsibilities, Deliverables / Outcomes:
- As a Junior Security Analyst specializing in Web Penetration Testing, you will assist in identifying
- vulnerabilities and assessing the security posture of web applications. You will work closely with senior team members to enhance your skills, perform web penetration testing, and contribute to delivering high-quality security assessments.
- Assist in performing web application penetration tests (both manual and automated) on internal and external web applications.
- Identify, exploit, and document web vulnerabilities (e.g., SQL injection, XSS, CSRF, etc.) under guidance.
- Conduct vulnerability assessments using automated web application testing tools like OWASP ZAP, Burp Suite, and other relevant tools.
- Analyze web application architectures and workflows to identify security risks.
- Document findings, security weaknesses, and suggested remediation steps in detailed reports.
- Collaborate with senior team members to refine findings and deliver professional-grade reports to clients.
- Utilize tools such as Burp Suite, OWASP ZAP, Nikto, and Nmap for web security testing.
- Ensure that testing tools and systems are kept up-to-date to ensure efficiency and coverage of emerging vulnerabilities.
- Stay updated with the latest web security threats, exploits, and penetration testing techniques.
- Participate in internal training sessions, contribute to team knowledge sharing, and expand your knowledge of web application security.
- Follow industry standards such as OWASP Top 10, PTES, and other relevant guidelines during assessments.
- Adhere to internal and client-specific security policies, ensuring compliance with industry best practices and security regulation.
Network Penetration Testing:
Key Responsibilities, Deliverables / Outcomes:
- As a Junior Security Analyst specializing in Network Penetration Testing, you will assist in identifying vulnerabilities and assessing the security posture of networks and systems. You will work closely with senior team members to enhance your skills and deliver high-quality security assessments.
- Assist in performing internal and external network penetration tests.
- Identify, exploit, and document network vulnerabilities under guidance.
- Conduct vulnerability assessments using automated tools.
- Document findings, recommendations, and remediation steps in detailed reports.
- Collaborate with the team to refine and deliver professional-grade reports to clients.
- Use tools such as Nmap, Metasploit, Burp Suite, and Wireshark for penetration testing and analysis.
- Ensure tools and systems are updated for maximum efficiency and accuracy.
- Stay updated with the latest security threats, exploits, and penetration testing techniques.
- Participate in internal training sessions and contribute to knowledge sharing.
- Follow industry standards like OWASP, NIST, and PTES during assessments.
- Adhere to internal and client-specific security policies and procedures.
Other Requirements
- The ideal candidate should have hands-on experience with security testing tools such as Burp Suite, Frida, MobSF, OWASP ZAP, Nikto, and Nmap.
- Proficiency in testing web, network, and mobile applications for vulnerabilities is essential, with a solid understanding of API security and SQL injection.
- The candidate must be familiar with identifying and mitigating security threats, ensuring compliance with industry standards, and performing vulnerability assessments.
- Strong problem-solving skills and attention to detail are a must for success in this role.
Good to have
Not provided
About the Company
ValueMentor is a full-fledged Cyber Security Partner helping organizations worldwide to effortlessly manage cyber risks. We offer Risk & Compliance Services, Security Testing & Managed Security Services.