Design and execute security testing strategies for web applications, APIs, microservices, mobile applications, and cloud environments.
Perform SAST, DAST, SCA, API security, container security, and infrastructure security testing.
Conduct vulnerability assessments and penetration testing and validate remediation.
Integrate security testing tools and automated security gates into CI/CD pipelines.
Develop security testing automation using Python, Java, JavaScript, or Bash.
Collaborate with Development, QA, DevOps, Cloud, and Security teams to identify and remediate vulnerabilities early.
Implement shift-left security and DevSecOps controls across the SDLC.
Configure and manage security tools for SAST, DAST, SCA, secrets scanning, container scanning, and IaC security.
Perform security testing of Docker/Kubernetes environments.
Test REST and GraphQL APIs, including authentication and authorization mechanisms.
Integrate security checks with Jenkins, GitHub Actions, GitLab CI/CD, Azure DevOps, or similar tools.
Analyze vulnerability findings, prioritize risks, and track remediation through closure.
Develop security test cases, automation frameworks, reports, and security metrics.
Participate in threat modeling and security architecture reviews.
Support security and compliance standards including OWASP Top 10, OWASP ASVS, SANS, NIST, and CIS Controls.
Stay current with emerging security threats, testing methodologies, and DevSecOps tools.