Security Tester

Infosys


Job Location:

Bucharest - Romania

Monthly Salary: Not Disclosed
Posted on: 10 hours ago
Vacancies: 1 Vacancy

Job Summary

Senior Application Security Engineer

Basic Purpose
We are seeking an experienced Senior Application Security Engineer with strong expertise in application security testing vulnerability management and DevSecOps advisory services. The successful candidate will lead security assessments support vulnerability remediation efforts advise development teams on secure software development practices and contribute to application security governance risk and compliance initiatives.

Key Responsibilities
Security Testing & Assessment
  • Perform and support application security assessments including SAST DAST SCA penetration testing API security testing and manual security reviews.
  • Conduct security testing of web API cloud and enterprise applications using industry-standard tools and techniques.
  • Validate findings perform false-positive analysis and execute retesting to verify remediation effectiveness.
  • Identify and assess security weaknesses related to authentication authorization input validation business logic insecure design and vulnerable components.
Vulnerability Management & DevSecOps
  • Lead vulnerability management activities including identification prioritization remediation tracking and reporting.
  • Prioritize findings using business impact exploitability exposure threat intelligence and organizational risk criteria.
  • Advise development teams on secure coding practices remediation strategies and secure SDLC implementation.
  • Support integration of security testing and vulnerability management processes into CI/CD pipelines and DevSecOps practices.
Governance Risk & Reporting
  • Support application security policies standards risk assessments threat modeling and secure design reviews.
  • Assist with security compliance and audit-related activities.
  • Develop security dashboards and metrics covering vulnerability trends remediation SLAs MTTR and testing coverage.
  • Communicate security risks and remediation priorities to technical and non-technical stakeholders.


Qualifications & Experience

  • Bachelors or Masters degree in Computer Science Cybersecurity Information Technology or related discipline or equivalent experience.
  • 10 years of experience in Application Security Security Testing Vulnerability Management or related cybersecurity disciplines.
  • Strong hands-on experience with:
    • SAST
    • DAST
    • SCA
    • Penetration Testing
    • API Security Testing
    • Manual Security Assessments
  • Extensive experience using Burp Suite for web and API security testing.
  • Hands-on experience with tools such as:
    • Burp Suite
    • HCL AppScan
    • Sonatype Nexus IQ/Lifecycle
    • Fortify
    • SonarQube
    • Black Duck (or similar SCA tools)
  • Strong understanding of OWASP Top 10 CWE OWASP ASVS Secure SDLC vulnerability management and risk-based prioritization.
  • Experience collaborating with development teams to drive remediation and improve security maturity.
  • Strong written verbal and stakeholder communication skills.
Preferred
  • Experience with Azure Cloud and Azure DevOps.
  • Experience with ServiceNow for vulnerability or incident management workflows.
  • Experience creating security dashboards and reports using Power BI.
  • Knowledge of NIST MITRE ATT&CK CIS Benchmarks threat modeling and application security governance practices.
  • Experience with AI-assisted security solutions security automation or agentic AI technologies.


Preferred Certifications
  • CISSP
  • CSSLP
  • GWAPT
  • GWEB
  • OSCP / OSWE
  • Security
  • SSCP
  • Microsoft Azure Security Certifications (AZ-500 or equivalent)

Overview
Infosys is a global leader in next-generation digital services and consulting. We enable clients in more than 50 countries to navigate their digital transformation.
With over four decades of experience in managing the systems and workings of global enterprises we expertly steer our clients through their digital journey. We do it by enabling the enterprise with an AI-powered core that helps prioritize the execution of change. We also empower the business with agile digital at scale to deliver unprecedented levels of performance and customer delight. Our always-on learning agenda drives their continuous improvement through building and transferring digital skills expertise and ideas from our innovation ecosystem.

All aspects of employment at Infosys are based on merit competence and performance. We are committed to embracing diversity and creating an inclusive environment for all employees. Infosys is proud to be an equal opportunity employer.


Senior Application Security EngineerBasic PurposeWe are seeking an experienced Senior Application Security Engineer with strong expertise in application security testing vulnerability management and DevSecOps advisory services. The successful candidate will lead security assessments support vulnerab...

About Company

Company Logo

Welcome to Infosys Careers for Experienced Professionals As a leading provider of next-generation consulting, technology and outsourcing solutions, we are dedicated to helping organizations in over 46 countries to renew their core and simultaneously innovate into new frontiers. Whilst ... View more

View Profile View Profile