Urgent requirement ofSecurity Analyst- Contract - Melbourne
Requirements
Must conduct a comprehensive Vulnerability Assessment and Penetration Testing (VAPT) on Web applications, APIs, Data Science apps (advantage)
Conduct manual security testing to complement automated scans.
Exploit vulnerabilities after vulnerability scan & classification of vulnerabilities according to agreed standard (OWASP, CVSS, etc.)
Report vulnerabilities based on criticality after scanning and exploitation.
Integrate automated security testing tools, including SAST, DAST, and SCA, into the CI/CD pipeline.
Assist application team with clarification required to fix identified vulnerabilities.
Provide security inputs and security assessments as feasible for the following activities.
Experience in manual penetration testing – Web Application, API (minimum requirements), Data Science apps (advantage).
Knowledge of Threat Modelling STRIDE methodology (at least basic knowledge).
Experience or knowledge in architecture review for applications hosted in Google Cloud (at least basic knowledge).
Tools: BurpSuite, Postman, Kali Linux/Parrot OS, Linux understanding.
Duration:6 months and possible extension.
Eligibility:Australian/NZ Citizens/PR Holders only.
J-*-Ljbffr