Senior Security Consultant - New Delhi, India - Claranet

    Claranet
    Claranet New Delhi, India

    2 weeks ago

    Default job background
    Description
    About The Role


    Role summaryOur consultants work on everything from client projects to development work and training, dealing with large corporate penetration tests to gaining credit for published advisories.

    Technical excellence and customer service are key to our work, you will be passionate about finding vulnerabilities while being happy liaising with customers.

    Our team is growing, and we need inspiring people to join us and help us to continue to build a world leading cyber security operation whilst benefiting from the opportunity to fulfil their potential.

    Based in INDIA, this work will lead on penetration testing, SDLC projects including on-site work, but will have the opportunity to work on projects with worldwide clients, and will form part of our global team of penetration testers who share research, tooling, experience and collaborate freely on projects.

    As a respected training provider and the leading provider of training at Black Hat conferences, our penetration testers also have the option of developing training skills and delivering security training, to both private customers, at our own events, and at leading international conferences.


    Essential duties & responsibilities:
    Work with multiple application development teams within the client organisation, to ensure secure development of applications.
    Perform web application penetration testing, infrastructure penetration testing, code reviews and/or mobile application penetration testing.
    Exploit vulnerabilities identified in client systems.
    Communicate vulnerabilities to clients.
    Manage project related tasks as per communicated deadlines.

    Participate in project conference calls and lead the technical content on the callDevelop a broad and deep technical understanding of applications, services and architectures pertaining to the client application organisation.

    Interpret results from exercises such as code review and penetration testing stakeholders, and advise on remediation and mitigation as well as incorporate learnings into future designsDevelop documentation, and a knowledge base to be used by developers for implementing secure coding practicesResearch and maintain knowledge of changing landscape of application security, latest threats, and attacker tools, techniques and proceduresProvide recommendations for missing application security controlsSupport and provide consultation to development teams in the area of application securityOccasional travel to client locations might be requiredDesirable:
    Be willing and able to engage customers on broader security problems, including scoping bespoke programs of work.

    About You

    Essential:5+ years of experience in information security2+ years of client-facing consulting work experience performing penetration testing.

    Knowledge of common application security flaws, threat modelling, security controls and common security librariesUnderstanding of security engineering principles including cryptography, access control, system security, and security operationsExperience working with Developer organisationsExperience with code scanning (SAST, DAST) tools for Javascript, Java, and Python languages and relevant frameworks.

    Programming language skills such as Java, . NET, C or C++ (nice to have).Excellent communication skills (written and verbal) with an ability to explain complex topics in a clear and concise manner to both technical and non-technical audiencesBasics to intermediate development and scripting skills in at least one programming languageKnowledge of cloud services and cloud security controlsExperience with pen testing (plus)Experience with code reviews (plus)