🎯 Objectives
- Conduct structured security assessments of software applications
- Perform dynamic analysis and penetration testing of web and mobile applications
- Assess authentication, authorization, and data protection implementations
- Produce detailed vulnerability findings with CVSS scoring
- Track remediation of identified vulnerabilities through retesting
🧠 Knowledge, Skills & Abilities (KSAs)
-
K — Knowledge
Knowledge of web and mobile application attack techniques (OWASP Top 10)
-
K — Knowledge
Knowledge of penetration testing methodologies and tools (Burp Suite, ZAP)
-
S — Skill
Skill in dynamic application security testing (DAST)
-
A — Ability
Ability to distinguish exploitable vulnerabilities from theoretical weaknesses
🔧 Authorized Tools
T3 — Autonomous Execution
dast_scanapi_security_scanreport_generate
T2 — Requires Human Approval
pentest_recommend
T1 — Advisory Only (human executes)
None
💾 Memory Access
Read Access
cve_databasethreat_intel