Conduct manual penetration testing of web applications, REST/GraphQL APIs, and WebSockets.
Identify vulnerabilities aligned with OWASP Top 10 and OWASP API Security Top 10.
Test financial and trading-specific business logic, including transaction manipulation, race conditions, authorization flaws, price manipulation, and session-related vulnerabilities.
Perform vulnerability exploitation and validation using Burp Suite and other offensive security tools.
Develop custom scripts and techniques to identify vulnerabilities that automated scanners may miss.
Assess authentication, authorization, session management, input validation, API security, and transaction flows.
Produce detailed penetration testing reports with reproducible steps, risk ratings, business impact, and practical remediation recommendations.
Work closely with Development, DevSecOps, and Infrastructure teams to validate vulnerability remediation.
Conduct retesting to ensure identified vulnerabilities have been properly resolved.
Support continuous improvement of application security testing methodologies and security controls.
Ensure security testing activities are conducted with minimal impact on trading systems and business operations.
Desired Candidate Profile
Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field.
3+ years of hands-on experience in web application and API penetration testing.
Strong practical knowledge of web application security and penetration testing methodologies.
Advanced hands-on experience with Burp Suite and common offensive security tools.
Strong understanding of OWASP Top 10, OWASP API Security Top 10, authentication, authorization, session management, and business logic vulnerabilities.
Experience testing REST APIs, GraphQL, WebSockets, and modern web applications.
Strong scripting/programming skills in Python, JavaScript, Bash, or similar languages.
Understanding of AWS and/or Microsoft Azure environments and cloud-based web service architectures.
Ability to independently manage penetration testing engagements from scoping and testing through reporting and remediation validation.
Strong analytical, problem-solving, and reporting skills.