10/04/2026
We’re hiring: Application Security Officer (Offensive Security)
If you’re someone who enjoys breaking applications, uncovering real vulnerabilities, and thinking beyond automated tools, this role is for you.
At Eminence Ways, we focus on real-world security testing, not just checklist scanning.
Key Responsibilities:
• Conduct in-depth manual security assessments of web, mobile, and API applications (black box / grey box / authenticated testing)
• Perform advanced pe*******on testing focusing on business logic flaws, authentication/authorization bypass, and vulnerability chaining
• Identify, validate, and exploit vulnerabilities across modern architectures (REST APIs, microservices, cloud-based apps)
• Use both manual techniques and automated tools to discover vulnerabilities beyond standard scanning coverage
• Collaborate with developers and stakeholders to prioritize and remediate security issues effectively
• Prepare high-quality technical reports with clear risk impact and actionable remediation steps
• Stay current with emerging attack techniques, CVEs, and exploitation trends
• Mentor junior testers and contribute to internal knowledge sharing and methodology improvement
Required Skills:
• 2+ years of hands-on experience in application security / pe*******on testing
• Strong understanding of OWASP Top 10 and beyond (IDOR, SSRF, deserialization, race conditions, logic flaws, etc.)
• Deep experience with Burp Suite (Pro), including extensions, manual testing workflows, and request manipulation
• Familiarity with tools such as Nmap, Metasploit, ffuf, nuclei, Wireshark, and custom scripts
• Ability to perform manual testing without relying solely on automated scanners
• Proficiency in at least one scripting language (Python preferred)
• Good understanding of web technologies (HTTP, sessions, tokens, APIs, JWT, OAuth)
• Basic understanding of cloud security concepts (AWS/Azure/GCP) is a plus
• Strong analytical thinking and ability to break complex systems creatively
• Good communication skills for reporting and client interaction
Bonus:
Experience with bug bounty platforms (HackerOne, Bugcrowd, etc.) or real-world vulnerability disclosures is a strong plus.
If you’re ready to work on real-world security challenges and grow in offensive security, we’d like to hear from you.
Apply now:
[email protected]
www.eminenceways.com
*******onTesting