Strong knowledge of OWASP Top 10 vulnerabilities Experience with penetration testing tools (Burp Suite, OWASP ZAP, Metasploit) API and authentication security testing (including JWT validation) Vulnerability assessment and secure code review Ability to produce detailed reports with remediation recom