





Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Tier-1 brand, metro location, and mid-level requirement increase competition, but niche pentesting skills moderate density.
Specialized penetration-testing skills, certifications, and compliance focus limit cross-industry transferability.
Explicit 4+ years, required security certifications, and PCI DSS compliance indicate strict shortlisting.
Lead manual and automated application- and network-layer penetration testing to identify security vulnerabilities across cloud infrastructure and applications.
Validate segmentation controls for Cardholder Data Environment annually and post-changes to ensure data isolation compliance.
Document, risk-rate findings, provide remediation guidance, and re-test vulnerabilities to maintain security posture and compliance (e.g., PCI DSS, SOC).
Minimum 4+ years of hands-on penetration testing or application security engineering experience.
Proficiency in scripting/programming (Python, Go, Ruby, or Bash) and deep knowledge of web attacks (SQLi, XSS, CSRF, XXE).
Experience with security testing tools like BurpSuite Enterprise, SAST, DAST, IAST, and understanding of network protocols (TCP/IP, DNS, HTTP/S, TLS, IPSEC).
Relevant certifications required (e.g., OSCP, CEH, OSWE, or CISSP).
Experienced in leading technical security assessments with measurable impact on vulnerability remediation and compliance.
Skilled in communicating complex security findings to both technical and non-technical stakeholders.
Familiar with bug bounty triage, cloud orchestration (Terraform, Google Deployment Manager), containerization (Docker, Kubernetes), and compliance frameworks preferred but not mandatory.