- 3+ years of experience working in a professional, academic or research environment identifying and remediating security bugs/flaws.
- Strong knowledge of the principles and techniques for both manual and automated application security assessments of desktop and web applications.
- Good knowledge of common web security vulnerabilities (e.g., OWASP Top 10), attack techniques and remediation tactics/strategies.
- Good understanding of common low-level vulnerabilities (e.g. use-after-free and buffer overflows) and common mitigations.
- Good understanding of networking and web technologies (e.g. WebSockets, HTTPS, TCP/IP, UDP) and security controls relevant to them.
- Familiarity with Windows and Linux operating systems fundamentals.
- Familiarity with the software development lifecycle (SDLC) and working knowledge of components to secure the SLDC.
- Practical experience with client network traffic testing tools and techniques e.g., Burp Suite, Fiddler and Bruno.
- Proficiency in C#.
- Excellent communication skills.