Company

Oscar TechnologySee more

addressAddressBirmingham, West Midlands
type Form of workContract
salary Salary24/06/2024
CategoryAccounting & Finance

Job description

The following is an overview of the Thick Application Penetration Test:

  • Will evaluate the application for security vulnerabilities from the perspective of an authenticated user. If multiple user types exist, then will perform testing using each type. During the testing, manual and automated processes leverage commercial, open source, and proprietary software. All automated tests will be manually verified to minimize false positives.
  • The penetration test will target common thick application attack vectors such as the file system, the registry, system memory, network communications, and graphical user interfaces.

Specific areas of focus will include, but are not limited to:

Static Analysis: During the static analysis phase of testing, will review the follow areas:

  • Service account roles and permissions (client, application server, database server)
  • Application file, folder, and registry permissions
  • Application service, provider, WMI subscription, task, and other permissions
  • Assembly compilation security flags
  • Protection of data in transit
  • Hardcoded sensitive data and authentication tokens (passwords, private keys, etc.)
  • Hardcoded encryption material (keys, IVs, etc.)
  • Use of insecure encryption and hashing algorithms
  • Database user roles and permissions
  • Database and server configurations

Dynamic Analysis: During the dynamic analysis phase of testing, will test and review the following areas:

  • Authentication and authorization controls enforced on the client and server
  • Application user roles and permissions
  • Application workflow logic between GUI elements
  • Web Services utilized by the application using web application testing methodology
  • File system changes including file and folder creation, deletion, and modification
  • Registry changes including creation, deletion, and modification of keys and values
  • Application objects and information stored in memory during runtime
  • Use of insecure encryption and hashing algorithms
  • Network protocols utilized by the application (SMB, FTP, TFTP, etc.)
  • Database connections

After identifying the strengths and weaknesses of the thick application(s) and Client's development and security program processes, will suggest strategies for improvement and assign priority to deficiencies based on potential business impact and likelihood of process failure or exploitation. Will also collaborate with stakeholders so that notable findings may then be analyzed and compared against program goals and compliance requirements.

NoCode Developer | 3 Months | Outside IR35 £400 - 500 p/d | Remote

An opportunity for an experienced NoCode Developer to join a growing, innovative company within the environmental sector.

You will get complete autonomy of the full project that involves creating a platform that will go to a range of direct consumers.

Requirements:

- West Midlands based - can be 100% remote

- NoCode experience (Bubble, Zoho, Fliplet etc) (no preference on platform)

- Strong communication and leadership skills

Desirable:

  • UX/UI skills/experience
  • Figma

This is initially a 3 month contract but it is likely to be extended.

Apply now and don't miss out!

Oscar Associates (UK) Limited is acting as an Employment Business in relation to this vacancy.

To understand more about what we do with your data please review our privacy policy in the privacy section of the Oscar website.

Refer code: 3438434. Oscar Technology - The previous day - 2024-06-24 23:30

Oscar Technology

Birmingham, West Midlands
Popular Developer jobs in top cities

Share jobs with friends

Related jobs

Nocode Developer | 3 Months | Outside|£400 - 500 P/D | Remote

Software Developer

Restore Digital

West Midlands, England

just now - seen

ServiceNow Developer

Page Group

Salary negotiable

West Midlands, England

just now - seen

Senior Software Developer

In Technology Group Limited

West Midlands, England

just now - seen

Salesforce developer

Meraki Talent Limited

West Midlands, England

just now - seen

SQL Developer

Harnham - Data & Analytics Recruitment

£50,000 - £60,000 per annum

West Midlands, England

just now - seen

Graduate Software Developer

Itss Recruitment Ltd

£25,000 - £35,000 per annum

West Midlands, England

just now - seen

Power Platform Developer

Nextech

£30,000 - £35,000 per annum

West Midlands, England

just now - seen

Power Platform Developer - D365

Gleeson Recruitment Group

West Midlands, England

just now - seen

Backend Developer

Chapman Tate Associates

£30,000 - £40,000 per annum

West Midlands, England

just now - seen

D365 CE Support Developer SC Cleared

Advanced Resource Managers Limited

£65,000 - £75,000 per annum

West Midlands, England

just now - seen

Web Developer

Pertemps Redditch Commercial

£30,000 - £38,000 per annum

West Midlands, England

just now - seen

Fullstack Java Developer

Applause It

West Midlands, England

5 minutes ago - seen

PHP Developer | PHP | SQL | JavaScript | jQuery

Oscar Technology

£38K per annum

Birmingham, West Midlands

60 minutes ago - seen

Lead Full Stack Developer | Laravel | Vue.js | JavaScript |

Oscar Technology

£50K per annum

Coventry, West Midlands

60 minutes ago - seen

Fullstack Java Developer

Applause It

£60000 - £65000

Wolverhampton, West Midlands

an hour ago - seen

Aftersales Business Developer

Undisclosed Company

£30000 - £35000 per annum + Plus Bonus

Coventry, West Midlands

2 hours ago - seen

Aftersales Business Developer

Manpower Uk Ltd

Coventry, West Midlands

4 hours ago - seen

Junior Software Developer

Counter Terrorism Policing

£50,000 - £60,000

Birmingham, West Midlands

7 hours ago - seen