Senior Web App Security Engineer (m/f/d)
Indexed description
Key Responsibilities
Web Application & API Security Testing
- Perform comprehensive manual and automated penetration testing of web applications, APIs, microservices, and internet-facing services.
- Identify vulnerabilities related to authentication, authorization, session management, input validation, and API security.
- Assess applications against recognized security frameworks and industry best practices.
- Evaluate security controls governing file uploads, downloads, storage, and processing workflows.
- Identify risks associated with malicious file handling, content validation, storage isolation, and data exposure.
- Validate role-based and attribute-based access controls across multiple user types and permission levels.
- Identify authorization weaknesses, including Insecure Direct Object References (IDOR), privilege escalation, and unauthorized data access.
- Assess segregation and isolation controls within shared application environments.
- Review authentication and authorization mechanisms, including OAuth 2.0, OpenID Connect (OIDC), SAML, and JWT implementations.
- Test token validation, session handling, replay protection, and identity federation controls.
- Identify weaknesses in identity lifecycle management and access governance.
- Assess critical user journeys and application workflows for logic flaws and abuse cases.
- Identify race conditions, workflow bypasses, automation weaknesses, and inadequate rate-limiting controls.
- Evaluate protections against fraud, abuse, and unauthorized transaction manipulation.
- Produce clear, risk-based security assessment reports with prioritized remediation recommendations.
- Collaborate with stakeholders to validate fixes and perform security re-testing.
- Support secure development practices throughout the software delivery lifecycle.
- Minimum 5 years of hands-on experience conducting web application and API penetration testing.
- Strong understanding of modern attack techniques and security testing methodologies.
- Expert knowledge of:
- OWASP Top 10
- OWASP API Security Top 10
- OWASP Web Security Testing Guide (WSTG)
- Threat modeling and risk-based assessment approaches
- Advanced proficiency with:
- Burp Suite Professional
- Postman
- Web application and API testing tools
- Proven experience identifying and exploiting weaknesses in:
- OAuth 2.0
- OpenID Connect (OIDC)
- JWT
- SAML 2.0
- Strong understanding of secure file processing, archive parsing, storage isolation, and content validation.
- Experience assessing file management controls and secure object storage implementations.
- Experience assessing file-scanning, malware-detection, or Content Disarm and Reconstruction (CDR) solutions.
- Familiarity with security automation and vulnerability assessment tools such as:
- Nuclei
- Semgrep
- OWASP ZAP
- Knowledge of cloud security controls across AWS, Microsoft Azure, and Google Cloud Platform (GCP).
- Understanding of secure architecture principles for internet-facing applications and distributed environments.
- Offensive Security
- OSCP (Offensive Security Certified Professional)
- OSWE (Offensive Security Web Expert)
- PortSwigger
- BSCP (Burp Suite Certified Practitioner)
- Other relevant application security, penetration testing, or cloud security certifications are advantageous.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search