About the role
Owns application-layer and infrastructure-layer security testing execution in full, including scheduled and unannounced rounds, ahead of the client's independent penetration test.
Key Responsibilities
- Execute the full OWASP MASVS-aligned application security test suite.
- Execute the infrastructure/platform security checklist across every component of the technical stack.
- Execute the PCI DSS compliance checklist for cardholder-data handling in the Cards module.
- Design and run unannounced/surprise security testing rounds ahead of the client's independent penetration test — without advance notice to the delivery team being tested.
- Own vulnerability management, cloud security posture review, and identity/access control review.
- Coordinate handoff and findings-sharing with the client's independent security function.
Required Qualifications & Experience
- Verifiable mobile application security testing experience, ideally on a digital banking or fintech platform.
- Working familiarity with OWASP MASVS.
- Comfortable executing adversarial/red-team-style testing on an unannounced basis.
- Named individual required for proposal — a role description without a named, CV-verified person is not a resourcing commitment.
- Mobile application security testing, OWASP MASVS, cloud security posture review (Kubernetes, Docker, Kafka), vulnerability management, red-team/adversarial testing technique