zoho_recruit
Senior Software Engineer - Infosec Compliance
HD Supply
Chennai, IND
Full-time
Senior
Onsite
Discovered 6 days ago
PythonOWASPOWASP WSTGBurp SuiteNmapSQLmap
Free
Job Fit Check
Base Career helps you apply smarter for this job.
?%
Ready to ScanKey skills for this role
PythonOWASPOWASP WSTG
Key Skills for This Role
PythonOWASPOWASP WSTGBurp SuiteNmapSQLmap
Full Job Posting
Requirements
- Strong hands‑on experience conducting manual web application penetration tests
- Deep knowledge of OWASP Web/API/Mobile Top 10 vulnerabilities
- Ability to perform:
- Experience following OWASP WSTG and structured test procedures
- Hands‑on experience testing RESTful APIs using authenticated and unauthenticated contexts
- Ability to test - Authorization controls and role separation, Token handling, API keys, OAuth/JWT misuse, Rate limiting, pagination, and business logic abuse
- Experience integrating API testing into broader application assessments
- Experience testing mobile applications with backend API dependency awareness
- Ability to assess client‑side vs server‑side trust boundaries
- Hands‑on experience performing internal and external infrastructure penetration tests
- Knowledge of - Network service enumeration (SMB, RDP, LDAP, MSSQL, HTTP/S), Firewall, VPN, and cloud endpoint misconfigurations, Active Directory attacks (Kerberoasting, AS‑REP roasting, privilege escalation)
- Ability to validate - Lateral movement paths, Privilege escalation vectors, Credential reuse and weak permissions
- Experience aligning infrastructure testing with PTES methodology
- Strong understanding of PTES phases
- Ability to scope, execute, and document full‑cycle penetration tests
- Experience validating exploitability and business impact, not just scanner findings
- Ability to perform retesting and confirm remediation closure
- Proficient with industry‑standard security testing tools, including: Burp Suite (manual testing, extensions, API testing), Nmap, SQLmap
- Ability to combine automated scanning with manual exploitation for accurate findings
- Experience working within a Secure Software Development Lifecycle (SSDLC)
- Perform architecture reviews and threat modeling (e.g., STRIDE)
- Support static, dynamic, and manual security testing efforts
- Strong experience producing clear, actionable penetration test reports
- Track findings through remediation lifecycle
- Support leadership discussions on risk posture and trends
- Partner with development teams during design, build, and release phases
- Active Directory attack paths (Kerberoasting/AS-REP Roasting, constrained/unconstrained delegation abuse, DCsync/DCshadow) and BloodHound path reduction.
- Practical offensive experience in Azure/Microsoft 365 (Entra ID) and/or A GCP: identity abuse, misconfigured roles/policies, workload identity takeover, OAuth app abuse, cross‑tenant risks.
- Demonstrated ability to consistently identify complex business logic flaws across web, API, and mobile workflows (e.g., multi‑step authorization bypass, chained vulnerabilities)
- Experience chaining low/medium issues into high‑impact attack paths (e.g., IDOR + weak auth + data exposure)
- Advanced web exploitation (SSRF to metadata pivot, deserialization chains, cache poisoning, template injection).
- Deep familiarity with microservices‑based architectures and API‑driven applications.
- Strong understanding of trust boundaries between client, API, and backend systems.
- Experience testing APIs protected by OAuth2, JWT, service tokens, and API gateways
- Ability to advise teams on secure API design patterns, not just findings.
- Experience performing manual mobile security testing beyond automated scanners
- Ability to identify client‑side trust issues vs backend enforcement gaps
- Executive‑ready storytelling: attack path narratives, business impact translation, and remediation roadmaps with risk‑based prioritization.
- Ability to correlate application vulnerabilities with infrastructure weaknesses
- Experience validating attack paths that involve: Network misconfigurations, Privilege escalation, Lateral movement post‑application compromise
- Understanding how cloud, firewalling, and segmentation affect application exposure
- Experience embedding security testing into SSDLC and CI/CD pipelines
- Ability to guide teams on threat modelling, secure design decisions, pre-production security gates.
- Comfort leading remediation discussions and challenging weak fixes constructively
- Experience mentoring junior AppSec or pentesting team members
- Create penetration testing reports as well as review them.
- Working knowledge of security scanning tools such as Snyk or Nessus, with the ability to interpret vulnerability reports and coordinate remediation activities
Benefits
- Be part of a globally recognized leader in the home improvement sector, committed to operational excellence and sustainability
- Opportunity to contribute to a rapidly expanding Global Technology Center (GTC) in Chennai, playing a vital role in global operations
- Exposure to diverse global technology environment and cross-functional team collaborations
- Competitive compensation package and comprehensive benefits
- Clear pathways for career advancement and continuous learning opportunities within a high-performance organization
About HD Supply
Wholesale & Distribution12000 employeesFounded 1974
Industrial distributor of maintenance, repair, and operations products.
Visit company websiteJobs and hiring trendsApply for this job in 1 click
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
More jobs at HD Supply
Field Account Representative (Multi-Family) - Greater Fresno, CA
Fresno, USA
MidFull-time
Discovered 2 days agoView →
Class C CDL Delivery Driver
Northlake, USA
Discovered 2 days agoFull-time
Bulk and Install Delivery Driver
Tolleson, USA
Discovered 2 days agoFull-time
Field Account Representative (Multi-Family) - Greater Fresno, CA
Fresno, USA
Discovered 2 days agoFull-time
Delivery Driver (non CDL)
Orlando, USA
Discovered 2 days agoFull-time
Box Truck Delivery Driver (Non CDL)
Schertz, USA
Discovered 2 days agoFull-time
Delivery Driver (Non-CDL)
, USA
Discovered 2 days agoFull-time
Box Truck Delivery Driver
Schertz, USA
Discovered 2 days agoFull-time
Box Truck Delivery Driver
Hayward, USA
Discovered 2 days agoFull-time