
AppSec Engineer
Posted Jul 15

Posted Jul 15
This is a fully remote position, open to applicants in Colombia.
β’ Plan, execute, and document penetration tests on web applications, mobile (Android/iOS), and APIs.
β’ Implement methodologies and frameworks (OWASP Web Top 10, OWASP API Security, OWASP MASVS/MSTG, etc.).
β’ Utilize tools such as Burp Suite (or similar), proxies, scanners, fuzzers, and analysis tools.
β’ Design and execute test cases focused on authentication, authorization, session management, input validation, cryptography, and exposure of sensitive data.
β’ Generate reproducible technical Proofs of Concept (PoC) that demonstrate the impact of identified vulnerabilities.
β’ Collaborate with development teams to prioritize, remediate, and retest findings.
β’ Work alongside the AppSec/DevSecOps team on Threat Modeling activities and purple teaming.
β’ Participate in red teaming exercises when required, including advanced attack simulations.
β’ Create clear and actionable reports for both technical and non-technical audiences (engineering, product, management).
β’ Proven experience in penetration testing for web applications, mobile, and/or APIs.
β’ Strong knowledge of OWASP Top 10, OWASP API Security, and OWASP mobile guidelines (MASVS/MSTG).
β’ Proficiency with penetration testing tools: Burp Suite, OWASP ZAP, HTTP proxies, fuzzers, and static/dynamic analysis tools, as well as instrumentation/emulation tools for mobile.
β’ Good understanding of modern authentication/authorization mechanisms (JWT, OAuth2, OIDC, etc.).
β’ Knowledge of networking, HTTP/HTTPS, DNS, and basic security concepts in cloud environments.
β’ Ability to write scripts or small tools in Python, JavaScript, Bash, or other languages for automating tests or exploitation.
β’ Skill in documenting findings clearly, in a structured manner, and focused on remediation.
β’ Work in a trusted environment.
β’ Participate in the mission of financial inclusion.
3M Consultancy
Get handpicked remote jobs straight to your inbox weekly.