{bc}
zoho_recruit

Senior Software Engineer - Infosec Compliance

HD Supply
Chennai, IND
Full-time
Senior
Onsite
Discovered 6 days ago
PythonOWASPOWASP WSTGBurp SuiteNmapSQLmap
Free

Job Fit Check

Base Career helps you apply smarter for this job.

?%
Ready to Scan

Key skills for this role

PythonOWASPOWASP WSTG
Smart Apply

Full Job Posting

Requirements

  • Strong hands‑on experience conducting manual web application penetration tests
  • Deep knowledge of OWASP Web/API/Mobile Top 10 vulnerabilities
  • Ability to perform:
  • Experience following OWASP WSTG and structured test procedures
  • Hands‑on experience testing RESTful APIs using authenticated and unauthenticated contexts
  • Ability to test - Authorization controls and role separation, Token handling, API keys, OAuth/JWT misuse, Rate limiting, pagination, and business logic abuse
  • Experience integrating API testing into broader application assessments
  • Experience testing mobile applications with backend API dependency awareness
  • Ability to assess client‑side vs server‑side trust boundaries
  • Hands‑on experience performing internal and external infrastructure penetration tests
  • Knowledge of - Network service enumeration (SMB, RDP, LDAP, MSSQL, HTTP/S), Firewall, VPN, and cloud endpoint misconfigurations, Active Directory attacks (Kerberoasting, AS‑REP roasting, privilege escalation)
  • Ability to validate - Lateral movement paths, Privilege escalation vectors, Credential reuse and weak permissions
  • Experience aligning infrastructure testing with PTES methodology
  • Strong understanding of PTES phases
  • Ability to scope, execute, and document full‑cycle penetration tests
  • Experience validating exploitability and business impact, not just scanner findings
  • Ability to perform retesting and confirm remediation closure
  • Proficient with industry‑standard security testing tools, including: Burp Suite (manual testing, extensions, API testing), Nmap, SQLmap
  • Ability to combine automated scanning with manual exploitation for accurate findings
  • Experience working within a Secure Software Development Lifecycle (SSDLC)
  • Perform architecture reviews and threat modeling (e.g., STRIDE)
  • Support static, dynamic, and manual security testing efforts
  • Strong experience producing clear, actionable penetration test reports
  • Track findings through remediation lifecycle
  • Support leadership discussions on risk posture and trends
  • Partner with development teams during design, build, and release phases
  • Active Directory attack paths (Kerberoasting/AS-REP Roasting, constrained/unconstrained delegation abuse, DCsync/DCshadow) and BloodHound path reduction.
  • Practical offensive experience in Azure/Microsoft 365 (Entra ID) and/or A GCP: identity abuse, misconfigured roles/policies, workload identity takeover, OAuth app abuse, cross‑tenant risks.
  • Demonstrated ability to consistently identify complex business logic flaws across web, API, and mobile workflows (e.g., multi‑step authorization bypass, chained vulnerabilities)
  • Experience chaining low/medium issues into high‑impact attack paths (e.g., IDOR + weak auth + data exposure)
  • Advanced web exploitation (SSRF to metadata pivot, deserialization chains, cache poisoning, template injection).
  • Deep familiarity with microservices‑based architectures and API‑driven applications.
  • Strong understanding of trust boundaries between client, API, and backend systems.
  • Experience testing APIs protected by OAuth2, JWT, service tokens, and API gateways
  • Ability to advise teams on secure API design patterns, not just findings.
  • Experience performing manual mobile security testing beyond automated scanners
  • Ability to identify client‑side trust issues vs backend enforcement gaps
  • Executive‑ready storytelling: attack path narratives, business impact translation, and remediation roadmaps with risk‑based prioritization.
  • Ability to correlate application vulnerabilities with infrastructure weaknesses
  • Experience validating attack paths that involve: Network misconfigurations, Privilege escalation, Lateral movement post‑application compromise
  • Understanding how cloud, firewalling, and segmentation affect application exposure
  • Experience embedding security testing into SSDLC and CI/CD pipelines
  • Ability to guide teams on threat modelling, secure design decisions, pre-production security gates.
  • Comfort leading remediation discussions and challenging weak fixes constructively
  • Experience mentoring junior AppSec or pentesting team members
  • Create penetration testing reports as well as review them.
  • Working knowledge of security scanning tools such as Snyk or Nessus, with the ability to interpret vulnerability reports and coordinate remediation activities

Benefits

  • Be part of a globally recognized leader in the home improvement sector, committed to operational excellence and sustainability
  • Opportunity to contribute to a rapidly expanding Global Technology Center (GTC) in Chennai, playing a vital role in global operations
  • Exposure to diverse global technology environment and cross-functional team collaborations
  • Competitive compensation package and comprehensive benefits
  • Clear pathways for career advancement and continuous learning opportunities within a high-performance organization

Apply for this job in 1 click

Skip the repetitive application forms

Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.

Sarah M.James T.Maya R.

Trusted by over 500,000 job seekers on Base Career

Start Free Today

More from this employer

More jobs at HD Supply