NextRaiseNextRaiseFind jobs
Sign inSign up free
Jobs / Functional Consultant in India
2 months ago
Apply with autofill
Apply with autofill
Sisainfosec·2 months ago
2 months ago

Application Security Professional

Bengaluru, IndiaFull-timeSenior · 7-10 yearsFunctional Consultant

Sign up free to see how well your resume matches this role.

Boost your chances at sisainfosec

How you compare FREE

?
Your scoreYour score: not yet known
→
57
Top 10%Top 10%: 57 out of 100

Top 10% of NextRaise users matched against Functional Consultant roles in India.

PDF or DOCX · no account needed

Apply faster with autofill FREEThe NextRaise extension autofills your application in one click.careers.example.com/applyAutofillingFull namePriya SharmaEmailpriya.sharma@example.comPhone+49 30 1234567LocationBerlGet the extension

About this role

Experience: 7–10 years
Location: Bangalore
Employment Type: Full-time


Role Summary

We are looking for a senior application security professional with strong hands-on expertise in securing web applications, mobile applications, APIs, and modern cloud-native application environments. The role requires the ability to independently lead complex application security assessments, perform secure design reviews, identify critical vulnerabilities, and work closely with engineering teams to drive remediation across the SDLC.


Key Responsibilities

  • Lead security assessments for web applications, mobile applications, APIs, and cloud-based applications.
  • Perform advanced manual and automated security testing across development, staging, and production environments.
  • Conduct security testing for Android and iOS applications, including static analysis, dynamic analysis, runtime testing, reverse engineering, and insecure storage reviews.
  • Assess REST, SOAP, GraphQL, and microservices-based APIs for authentication, authorization, data exposure, injection, rate limiting, and business logic flaws.
  • Perform secure architecture reviews, threat modeling, and risk assessments for critical applications and new product features.
  • Review source code and provide secure coding recommendations to development teams.
  • Support DevSecOps initiatives by integrating SAST, DAST, SCA, secret scanning, and container security tools into CI/CD pipelines.
  • Validate vulnerabilities, define risk ratings, prepare detailed reports, and provide practical remediation guidance.
  • Track findings to closure and validate remediation fixes.
  • Mentor junior security team members and contribute to internal AppSec methodologies, checklists, playbooks, and standards.
  • Engage with development, DevOps, QA, product, and business teams to improve security maturity.


Required Skills

  • Strong hands-on expertise in web application security, mobile application security, and API security testing.
  • Deep understanding of OWASP Top 10, OWASP API Security Top 10, OWASP ASVS, OWASP MASVS, CWE, and CVSS.
  • Advanced knowledge of authentication and authorization mechanisms such as OAuth 2.0, OIDC, SAML, JWT, MFA, RBAC, and ABAC.
  • Experience identifying and exploiting vulnerabilities such as XSS, SQL injection, IDOR, SSRF, CSRF, authentication bypass, insecure deserialization, cryptographic flaws, insecure storage, and business logic issues.
  • Hands-on experience with tools such as Burp Suite, OWASP ZAP, Postman, MobSF, Frida, Objection, JADX, APKTool, ADB, SQLMap, Nuclei, and SoapUI.
  • Ability to perform secure code reviews in languages
  • Good understanding of DevSecOps, CI/CD security, SAST, DAST, SCA, container scanning, and secrets management.
  • Ability to independently lead assessments from scoping to reporting.
  • Strong reporting, communication, stakeholder management, and developer collaboration skills.


Good to Have

  • Experience with cloud application security across AWS, Azure, or GCP.
  • Knowledge of Docker, Kubernetes, and containerized application security.
  • Familiarity with compliance standards such as PCI DSS, ISO 27001, SOC 2, GDPR, or HIPAA.
  • Experience with bug bounty, responsible disclosure, product security, or purple team activities.
  • Certifications such as OSCP, GWAPT, GMOB, GWEB,  eWPT, or eWPTX.

Company

Sisainfosec
Bengaluru, India

Company facts come from this company's own listings. We only show what the postings themselves carry.

Sourced from Sisainfosec's careers site·first seen 7 Aug 2026·last verified 9 Sept 2026·How we source jobs

Similar jobs

  • Engineer - Customer Application Engineering at GE VernovaPallavaram, India–match not yet calculated
  • Sr. Developer - Enterprise Application - Oracle P 4B at GenpactMumbai, India–match not yet calculated
  • Associate Engineer Software Application Engineer - AB Suite at UnisysBengaluru, India–match not yet calculated
  • Workday Functional Consultant (Mid-Senior Level) at ermDelhi NCR, India–match not yet calculated
  • Lead Engineer, Enterprise Application Engineering at myhrabcPune, India–match not yet calculated

Browse more jobs

  • Functional Consultant jobs in India
  • Technical Consultant jobs in India
  • Solutions Consultant jobs in India
  • Implementation Consultant jobs in India
  • Functional Consultant jobs in United States
  • Functional Consultant jobs in Germany