Application Security Engineer
Security AnalystKey Responsibilities (with Technologies): Conduct in-depth security testing on front-end web and mobile apps to uncover vulnerabilities and enforce strong security controls. Technologies: OWASP ZAP, Burp Suite, MobSF, Appium, Selenium, Postman, Charles Proxy Partner with the GraphQL (GQL) team to integrate security protocols and ensure secure data flow. Technologies: GraphQL, Postman, Insomnia, JWT, OAuth 2.0, API Gateway, Kong Apply knowledge of eSIM, SIM/device swaps to identify and mitigate telecom-specific threats. Technologies: eUICC, GSMA standards, SIMalliance tools, Wireshark, QXDM, QCAT Analyze business logic and coding practices to uncover fraud risks; validate scenarios through end-to-end testing. Technologies: Splunk, Kibana, ELK Stack, Python, SQL, Fraud Management Systems (e.g., Actimize, SAS) Adopt a hacker's mindset to identify abuse cases and differentiate between legitimate and malicious user journeys. Technologies: Kali Linux, Metasploit, Burp Suite, OWASP Juice Shop, Threat Modeling Tools (e.g., Microsoft Threat Modeling Tool) Use real-world breach tactics to refine testing strategies. Technologies: SET (Social-Engineer Toolkit), Gophish, OSINT tools (e.g., Maltego, Recon-ng) Utilize tools to track secure data flow and support fraud/security initiatives. Technologies: Wireshark, Fiddler, tcpdump, Splunk, ELK Stack Develop and maintain security policies, procedures, and training. Technologies: NIST, ISO/IEC 27001, CIS Benchmarks, Confluence, SharePoint Apply industry best practices and technologies to secure software and business processes. Technologies: OWASP ASVS, DevSecOps pipelines (e.g., Jenkins, GitHub Actions), Snyk, SonarQube Evaluate compliance with industry standards and recommend improvements. Technologies: Nessus, OpenVAS, Qualys, Compliance Management Tools (e.g., RSA Archer) Regularly assess and adapt security measures to evolving threats. Technologies: Threat intelligence platforms (e.g., Recorded Future, MISP), CVE databases, SIEM tools Build automated security checks using BDD frameworks like Karate or similar tools. Technologies: Karate, Cucumber, Selenium, Cypress, Jenkins, GitLab CI/CD