Application Security Tester (OWASP ASVS Level 3)
Website Confidential
Perform application security testing to OWASP ASVS Level 3 across the Digital Trust web, portal, integration, and API components, validating authentication and authorization controls and confirming all concerning findings.
Key Responsibilities:
• Execute static (SAST) and dynamic (DAST) code analysis against in-scope applications to OWASP ASVS Level 3
• Validate authentication and authorization controls, session management, input handling, and data protection
• Test APIs and the BizTalk integration layer connecting Ping Identity to GNB enterprise systems, including AMANDA integrations
• Assess the AMANDA Citizen Portal configuration, roles/permissions, triggers, data flows, and audit logging that support Digital Trust credential actions
• Reproduce and validate concerning findings; document evidence, severity, and remediation guidance
Deliverables:
• Deliverable 3 (Application Security Testing, OWASP ASVS L3), with supporting evidence for the consolidated SRA report
Skills: OWASP ASVS, Application Security Testing, SAST, DAST, API Security, Burp Suite, Security Assessments, Authentication Controls, Authorization Controls, BizTalk, .NET, Java, OWASP API Security Top 10
Location: Fredericton, NB
To apply for this job please visit fokuspro.net.