Skip to main content
Technology

Sr Specialist Cybersecurity - Penetration Testing

Hyderabad, India

Apply now

Job Description:

About the Company:

At AT&T, we’re connecting the world through the latest tech, top-of-the-line communications and the best in Communication. Our groundbreaking digital solutions provide intuitive and integrated experiences for millions of customers across online, retail and care channels. Join our mission to deliver compelling communication and entertainment experiences to customers around the world as we continue to evolve as a technology-powered, human-centered organization. As part of our team, you’ll transform the way we deliver a seamless customer experience with digital at the center of all you do. In our world, digital is much larger than just an eCommerce channel, we are transforming all channels to digitally perform as one team to create a better customer experience. As we move into 2024, the digital transformation will revolutionize the digital space and you can build a career that will propel your future.

About the Job:

This position is a Sr Specialist Cyber Security for performing advanced application security testing in Cyber Security Organization with strong technical knowledge of development practices/language knowledge, identify test methods to effectively identify exploitable vulnerabilities in the full technology stack of target applications.  Grey box testing of applications that includes both unauthenticated perimeter hardening attack scenarios as well as authenticated privilege escalation attacks that enumerate complex attack chain vulnerabilities.

Experience Level: 8+ years

Location: Hyderabad or Bengaluru

Roles and Responsibilities:

  • Perform SAST/SCA/DAST scans using industry vulnerability scanner
    • SAST/SCA – Veracode, using supplied compiled binary, configure scan platform to correct scan for both static code CWE’s as well as SCA derived CVEs.   Work will include coordination with app owner to ensure all branches of code are included in compiled binary file.
    • DAST – Work begins with crawling the target application to identify existing directory and file structure.  Once identified, execute DAST scan using HCL product to identify dynamic issue only visible during code execution.
    • Adversary based approach to test plan development.
    • EcoSystem Testing
  • During testing process, tester MUST ensure application is not degraded and/or taken out of service due to scanning activities.
  • Tester must ensure results from scanner are present in VM reporting platforms and visible to approved app users.
  • Perform manual validation and false-positive analysis on the automated scan results.   
  • Provide remediation support will analyze the top-rated vulnerabilities along with provide support to application teams on remediation strategies from identified risks. 
  • Execute scan retest by performing revalidation tests of previously identified critical and high severity vulnerabilities as requested by the client application teams. 

Primary / Mandatory skills:

Overall – 8+ years of IT experience

  • 7+ years of application security experience
  • 5+ years of Application Security testing experience
  • 3+ years of penetration testing experience
  • Bachelor's degree required.
  • Deep familiarity with the OWASP Top 10 and other security concerns for web applications
  • Deep Understanding of OWASP Application Security Verification Standards (ASVS)
  • Deep understanding of SAST, DAST, SCA Scanning practices
  • Experience in scanning leveraging Veracode, Appscan.or other enterprise tools.
  • Understand how to interpret and assess CVEs (Common Vulnerability and Exposures) and CWEs (Common Weakness Enumeration) as found by scanning tools.
  • Understanding of SAST, DAST tools and dependency scanning tools
  • Experience working/integrating with secret management systems.
  • Advanced knowledge of front-end and back-end web application development in at least one technology stack (.NET, Java, PHP, Ruby/Rails, Angular, Node.js, etc.)
  • Track record of staying current with trends, techniques, tools, and processes that drive improvement of security posture of applications.
  • Strong documentation skills
  • Excellent verbal and written communication skills, with proven technical writing abilities (English language proficiency required)
  • Team-oriented thinking with demonstrated ability to produce high-quality work as part of a fast-paced, dynamic team.
  • Proven ability to communicate, collaborate, and present effectively with teams and individuals in different disciplines or areas. 

Technical Skills: SAST, DAST, SCA and penetration testing

Additional information (if any): Flexible to provide coverage in US morning hours upon need.

Certification: CSSLP or equivalent

Weekly Hours:

40

Time Type:

Regular

Location:

IND:AP:Hyderabad / Atria Building, Plot 17 - Adm: Atria Building, Plot No 17

It is the policy of AT&T to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, AT&T will provide reasonable accommodations for qualified individuals with disabilities.

Job ID R-46607 Date posted 12/09/2024
Apply now

Benefits

Your needs? Met. Your wants? Considered. Take a look at our comprehensive benefits.

  • Paid Time Off
  • Tuition Assistance
  • Insurance Options
  • Discounts
  • Training & Development

Learn more about benefits

Our hiring process

Apply Now

Confirm your qualifications align with the job requirements and submit your application.

Assessments

You may be required to complete one or more assessments, depending on the role.

Interview

Get ready to put your best foot forward! More than one interview may be necessary.

Conditional Job Offer

We’ll reach out to discuss a conditional job offer and the next steps to joining the team.

Background Check

Timing is important – complete the necessary actions to proceed with onboarding.

Welcome to the Team!

Congratulations! It’s time to experience #LifeAtATT.

Check your email (and SPAM) throughout the process for important messages and next steps.

Connect today

Didn’t find what you were looking for here? Sign up for our job alerts so we can connect and share the latest.

Welcome to the Talent Network

We’ve always got a ton of awesome things going on – like the latest job openings, events and offerings. But how can you stay on top of it all? That’s easy. Just connect to our Talent Network.

An * indicates a required field.

Interested InSelect a job category from the list of options. Select a location from the list of options. Finally, click “Add” to create your job alert.

  • Technology, Hyderabad, Telangana, IndiaRemove
  • Cybersecurity, Hyderabad, Telangana, IndiaRemove

AT&T Info and Alerts. Max 12 messages/month Privacy Policy (opens in new tab). You may opt-out at anytime by sending STOP to short code 20013. Msg & data rates may apply.

By submitting your information, you acknowledge that you have read our privacy policy (opens in new tab) and consent to receive email communication from AT&T for our U.S. Talent Network

Don't Miss Out

Join our Talent Network to be the first to know about new job openings, special announcements and behind-the-scenes information.

Skip, I’d rather go straight to the application

AT&T Info and Alerts. Max 12 messages/month Privacy Policy (opens in new window). You may opt-out at anytime by sending STOP to short code 20013. Msg & data rates may apply.

By submitting your information, you acknowledge that you have read our privacy policy (opens in new window) and consent to receive email communication from AT&T for our U.S. Talent Network.