Sphynx
Information Technology and Services
PenetrationTester/AppSecEngineer
Neural analysis suggests this role is
optimal for Mid+ candidates.
“Penetration Tester / AppSec Engineer at Sphynx. Skills: Penetration testing, Application security, Vulnerability identification. Conduct penetration testing. Perform static application security testing”
Industry & Context.
Analytical skills; Problem-solving skills; Risk analysis; Remediation guidance
What They're Looking For.
Must Have
2 years of professional experience, knowledge of web application security, knowledge of OWASP Top 10, knowledge of common vulnerabilities, Experience with penetration testing tools, Proficiency in scripting languages, Proficiency in programming languages, Understanding of secure software development lifecycle
Nice to Have
OSCP certification, CEH certification, GIAC (GWAPT) certification
What You'll Do.
Conduct penetration testing
Perform static application security testing
Perform dynamic application security testing
Identify security vulnerabilities
Report security vulnerabilities
Provide risk analysis
Provide remediation guidance
Collaborate with development teams
Integrate secure coding practices
Improve security lifecycle
Develop security testing tools
Maintain security testing tools
Stay current with security threats
Stay current with vulnerabilities
Stay current with mitigation techniques
Assist in designing security policies
Assist in implementing security policies
Assist in designing security standards
Assist in implementing security standards
How You'll Work.
Team & Collaboration
Collaborate with development teams
Full Job Description
The Penetration Tester / Application Security (AppSec) specialist at Sphynx is responsible for identifying and addressing security vulnerabilities within applications and systems, as well as perform penetration tests for our clients. This role involves performing penetration tests, security assessments, and providing actionable recommendations to enhance the overall security posture. ### Responsibilities * Conduct penetration testing on web, mobile, and network applications to identify security risks. * Perform static and dynamic application security testing and code reviews. * Identify and report security vulnerabilities, providing detailed risk analysis and remediation guidance. * Collaborate with development teams to integrate secure coding practices and improve the security lifecycle. * Develop and maintain security testing tools and documentation. * Stay current with emerging security threats, vulnerabilities, and mitigation techniques. * Assist in designing and implementing application security policies and standards. **Requirements** * Bachelor's degree in Computer Science, Cybersecurity, or related field. * At least 2 years of professional experience in penetration testing and application security assessments. * Strong knowledge of web application security, OWASP Top 10, and common vulnerabilities. * Experience with penetration testing tools such as Burp Suite, Metasploit, Nessus, or similar. * Proficiency in scripting and programming languages (e.g., Python, JavaScript). * Understanding of secure software development lifecycle (SDLC). * Excellent analytical, problem-solving, and communication skills. * Relevant certifications such as OSCP, CEH, or GIAC (GWAPT) are highly desirable. **Benefits** * Competitive remuneration package adjusted to proven skills and experience; * Excellent working conditions; * Exposure to training and professional development capabilities, including the ability to engage in cutting-edge research; * Exposure to international client
Applying for this Penetration Tester / AppSec Engineer role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
ANONYMOUS · UNFILTERED
What do employees actually say about Sphynx?
Real rants from real employees. Read before you apply.