Security QA Engineer (Penetration Testing Focus) @ Innowise
Core
Perform penetration testing and vulnerability assessments of web applications, APIs, mobile apps, and infrastructure to identify security flaws and provide remediation.
Role type
Security QA Engineer (Penetration Testing Focus)
Builds
Secure web applications, APIs, mobile apps, and infrastructure
Domain
Cybersecurity / Application Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
mobile application penetration testing, infrastructure penetration testing, Secure Software Development Lifecycle (SSDLC), bug bounty program participation, Capture The Flag (CTF) competition experience, OWASP WSTG methodologies, OWASP Top 10 knowledge, vulnerability exploitation techniques, Kali Linux, Burp Suite, Metasploit, Nmap (NSE), Acunetix
Preferred skills
OSCP, CEH, modern AI tools usage
Technologies
Kali Linux, Burp Suite, Metasploit, Nmap (NSE), Acunetix
Responsibilities
Perform penetration testing and vulnerability assessments of web applications and APIs, Document identified vulnerabilities and provide clear, detailed remediation recommendations, Support product owners and development teams in vulnerability remediation efforts, Apply established security testing methodologies such as OWASP WSTG, Demonstrate strong knowledge of the OWASP Top 10 and common web application vulnerabilities, Possess deep understanding of various vulnerability types, their root causes, exploitation techniques, and remediation approaches, Effectively use application security testing software and common penetration testing tools
Seniority
Mid-level to Senior, hands-on IC