8+ years of Information Security experience with demonstrated expertise in offensive security and penetration testing.
5+ years of hands-on mobile application security testing for Android and iOS platforms.
Strong knowledge of OWASP Top 10, API Security Top 10, SANS Top 25, OWASP MASVS, and MASTG frameworks.
Advanced experience conducting manual penetration testing, exploit chaining, business logic testing, and access control assessments.
Expert proficiency with Burp Suite Pro, Postman, Insomnia, Nmap, Metasploit, Kali Linux, and related security testing tools.
Experience assessing security within AWS, Azure, Kubernetes, containers, and cloud-native security platforms.
Strong scripting and automation skills using Python, PowerShell, Bash, Ruby, or Go.
Deep understanding of HTTP/S, REST APIs, OAuth, SAML, JWT, TCP/IP, DNS, firewalls, IDS/IPS, and application architecture.
Knowledge of AI and Machine Learning security risks, including prompt injection, insecure model access, API abuse, and data leakage concerns.
Familiarity with PCI-DSS, HIPAA, NIST 800-53, ISO 27001, FedRAMP, and other security compliance frameworks.
Excellent communication skills with the ability to present findings to technical teams, business stakeholders, and executive leadership.