HD Supply
Senior Software Engineer - Digital & Ops
Skills
Job description
As a Senior Software Engineer – Infosec Compliance, you will play a critical role in building, securing, and maintaining engineering solutions that support the organization’s global information security objectives. You will design and deploy monitoring, compliance, and threat detection capabilities that enable continuous assurance and visibility across our tech landscape. Working closely with cross functional teams, you will ensure our security tooling, telemetry, and alerting systems are resilient, scalable, and support a proactive risk posture. Independently perform Web, API, Mobile, and Infrastructure pentests Clearly communicate risk to developers and leadership Own testing quality from execution to reporting to retesting Atleast one relevant certification (OSCP, CRTO, OSWP, OSEP, PNPT or anything similar) Programming, Python, etc. Requirements Strong hands‑on experience conducting manual web application penetration tests Deep knowledge of OWASP Web/API/Mobile Top 10 vulnerabilities Ability to perform: -Application mapping & attack surface discovery -Authentication and authorization testing -Input validation and error handling testing -Client‑side and server‑side attack validation Experience following OWASP WSTG and structured test procedures Hands‑on experience testing RESTful APIs using authenticated and unauthenticated contexts Ability to test - Authorization controls and role separation, Token handling, API keys, OAuth/JWT misuse, Rate limiting, pagination, and business logic abuse Experience integrating API testing into broader application assessments Experience testing mobile applications with backend API dependency awareness Ability to assess client‑side vs server‑side trust boundaries Hands‑on experience performing internal and external infrastructure penetration tests Knowledge of - Network service enumeration (SMB, RDP, LDAP, MSSQL, HTTP/S), Firewall, VPN, and cloud endpoint misconfigurations, Active Directory attacks (Kerberoasting, AS‑REP roasting, privilege escalation) Ability to validate - Lateral movement paths, Privilege escalation vectors, Credential reuse and weak permissions Experience aligning infrastructure testing with PTES methodology Strong understanding of PTES phases Ability to scope, execute, and document full‑cycle penetration tests Experience validating exploitability and business impact, not just scanner findings Ability to perform retesting and confirm remediation closure Proficient with industry‑standard security testing tools, including: Burp Suite (manual testing, extensions, API testing), Nmap, SQLmap Ability to combine automated scanning with manual exploitation for accurate findings Experience working within a Secure Software Development Lifecycle (SSDLC) Perform architecture reviews and threat modeling (e.g., STRIDE) Support static, dynamic, and manual security testing efforts Strong experience producing clear, actionable penetration test reports Track findings through remediation lifecycle Support leadership discussions on risk posture and trends Partner with development teams during design, build, and release phases Preferred Skills Active Directory attack paths (Kerberoasting/AS-REP Roasting, constrained/unconstrained delegation abuse, DCsync/DCshadow) and BloodHound path reduction. Practical offensive experience in Azure/Microsoft 365 (Entra ID) and/or A GCP: identity abuse, misconfigured roles/policies, workload identity takeover, OAuth app abuse, cross‑tenant risks. Demonstrated ability to consistently identify complex business logic flaws across web, API, and mobile workflows (e.g., multi‑step authorization bypass, chained vulnerabilities) Experience chaining low/medium issues into high‑impact attack paths (e.g., IDOR + weak auth + data exposure) Advanced web exploitation (SSRF to metadata pivot, deserialization chains, cache poisoning, template injection). Deep familiarity with microservices‑based architectures and API‑driven applications. Strong understanding of trust boundaries between client, API, and backend systems. Experience testing APIs protected by OAuth2, JWT, service tokens, and API gateways Ability to advise teams on secure API design patterns, not just findings. Experience performing manual mobile security testing beyond automated scanners Ability to identify client‑side trust issues vs backend enforcement gaps Executive‑ready storytelling: attack path narratives, business impact translation, and remediation roadmaps with risk‑based prioritization. Ability to correlate application vulnerabilities with infrastructure weaknesses Experience validating attack paths that involve: Network misconfigurations, Privilege escalation, Lateral movement post‑application compromise Understanding how cloud, firewalling, and segmentation affect application exposure Experience embedding security testing into SSDLC and CI/CD pipelines Ability to guide teams on threat modelling, secure design decisions, pre-production security gates. Comfort leading remediation discussions and challenging weak fixes constructively Experience mentoring junior AppSec or pentesting team members Create penetration testing reports as well as review them. Working knowledge of security scanning tools such as Snyk or Nessus, with the ability to interpret vulnerability reports and coordinate remediation activities Benefits Be part of a globally recognized leader in the home improvement sector, committed to operational excellence and sustainability Opportunity to contribute to a rapidly expanding Global Technology Center (GTC) in Chennai, playing a vital role in global operations Exposure to diverse global technology environment and cross-functional team collaborations Competitive compensation package and comprehensive benefits Clear pathways for career advancement and continuous learning opportunities within a high-performance organization