Application Penetration Tester - CME India Technology And Support Services Pvt Ltd

Date Posted: Nov 27, 2019
190 days ago
Login to View Salary
Applied : 500
Views (10)

Job Detail

  • Location:
    Bengaluru, Karnataka, India
  • Company:
  • Type:
    Full Time/Permanent
  • Shift:
    First Shift (Day)
  • Career Level:
    Programming & Design
  • Positions:
  • Experience:
    5 Year
  • Gender:
    Male / Female
  • Degree:
  • Apply Before:
    Jun 30, 2020

Job Description


The Application Penetration Tester is responsible for performing manual application security assessments (application pentests) and communicating any findings to the Development and QA teams. Additionally, the engineer will provide application design support and security best practice guidance, in the form of consultations, to various Development teams and Business stakeholders.

You will work with a team of highly skilled Application Security Engineers that are responsible with testing the security of CME Group's applications and services. This is a great environment to get exposure to a wide array of technologies and progress your application security career, while providing value to CME and helping to ensure that our applications are designed and coded in a secure fashion.


* 3+ years' experience performing blackbox and/or whitebox application penetration testing (Web, Mobile, Thick clients), or the ability to demonstrate equivalent knowledge.
* Excellent skills with application security testing tools such as: Burpsuite, OWASP ZAP, SQLMap, IDA Pro, Kali, etc.
* Knowledge on how to perform manual application source code security reviews for various languages such as: Java, .Net (C#, VB#), C++.
* Experience with UNIX or Linux.
* Experience with scripting languages such as: Python, bash, Powershell, etc.
* Have a passion for application security, willingness to continue growing your skills in this domain, and be able to share your passion and learnings with teammates.
* Self-motivated and a self-starter. If you have a question, be pro-active in finding the answer and communicate your learnings with teammates.
* Excellent oral and written communications skills.

Nice to have:

* Experience with containers (Docker, Kubernetes) is a plus.
* Experience with DevSecOps and Continuous Integration/Continuous Delivery (CI/CD) is a plus.
* OSCP/OSWE, GWAPT, GMOB, GPYC, or other relevant security certifications are a plus.

Principal Accountabilities
* Perform manual application penetration testing at key points in the Software Development Life Cycle (SDLC).
* Produce documentation (reports) and present the findings discovered during your security assessments.
* Provide application security consulting services at critical points in the SDLC.
* Have an interest in continuing your education and staying current within the application security domain.

Required Candidate profile


A Bachelor's or Master's degree in Computer Science, Information Systems or other related discipline is required; or equivalent combination of education and relevant proven work experience.

Salary: Not Disclosed by Recruiter
Industry: Banking Financial Services Broking
Functional Area: IT Software - Application ProgrammingMaintenance
Role Category: Programming & Design
Role: Testing Engineer
Employment Type: Full Time, Permanent


Company Overview

Bengaluru, Karnataka, India

CME Group is the world’s leading and most diverse derivatives marketplace, handling 3 billion contracts worth approximately $1 quadrillion annually (on average). The company provides a marketplace for buyers and sellers, bringing together individuals... Read More

Related Jobs

Google Map

Set Job Alert

We use cookies to improve your experience. By continuing to browse the site, you agree to our Privacy Policy & Cookie Policy.