Kotak Mahindra Bank – Software Test Engineering II-SUPPORT SERVICES-Applications-CTB

May 8, 2025
6 ₹ LPA - 10 ₹ LPA / year

Job Description

The successful candidate will have a strong background in penetration testing, including experience with various tools and techniques used to identify vulnerabilities in web applications and APIs. The ideal candidate will be able to analyze complex systems, identify potential security risks, and provide actionable recommendations for remediation.
Conduct thorough penetration testing of web applications and REST APIs using a variety of tools and techniques
Identify vulnerabilities in web applications, including but not limited to:
SQL injection
Cross-Site Scripting (XSS)
Cross-Site Request Forgery (CSRF)
Authentication and authorization weaknesses
Session management issues
Test REST APIs for security vulnerabilities, including but not limited to:
Input validation and sanitization
Error handling and logging
Authentication and authorization mechanisms
Data encryption and transmission
Analyze results and provide detailed reports outlining findings, recommendations for remediation, and estimated timeframes for implementation
Collaborate with development teams to ensure identified vulnerabilities are addressed and remediated in a timely manner
Stay up-to-date with the latest security threats, tools, and techniques through ongoing training and professional development

Responsibilities
3+ years of experience in penetration testing, with a focus on web applications and REST APIs Strong understanding of web application security concepts, including but not limited to: OWASP Top 10 Web Application Security Risks (WASR) Secure Coding Practices Experience with various penetration testing tools, including but not limited to: Burp Suite ZAP Nmap AJP SQL injection tools (e.g. sqlmap) Strong understanding of REST API security concepts, including but not limited to: API Security Frameworks (e.g. OAuth 2.0) Data encryption and transmission protocols (e.g. HTTPS) Authentication and authorization mechanisms (e.g. JWT) Experience with scripting languages (e.g. Python, Ruby) is a plus Strong analytical and problem-solving skills Excellent communication and reporting skills