Talakunchi·6 hours ago
6 hours agoBe an early applicant
Sr Security Consultant – Web, Mobile, API & SCR
Sign up free to see how well your resume matches this role.
What you'll do
- Perform Web Application Security Testing based on OWASP Top 10 and industry-standard methodologies.
- Conduct Mobile Application Security Testing for Android/iOS.
- Perform API Security Testing using Burp Suite, Postman, OWASP ZAP, etc.
- Conduct Secure Code Review (SCR) and identify insecure coding practices.
- Identify and validate vulnerabilities related to authentication, authorization, access control, injection, session management, sensitive data, business logic and API security.
- Perform vulnerability retesting and remediation validation.
- Prepare detailed VAPT/security assessment reports with evidence, impact and remediation recommendations.
- Perform/support security testing of UPI/payment applications, including API security, transaction flows, authentication, authorization and business logic.
- Support PCI-DSS and other security audits with VAPT reports, evidence, remediation and retest documentation.
- Coordinate with development/application teams for vulnerability remediation and closure.
- Handle client queries and participate in security review meetings.
- Coordinate day-to-day activities of junior security testers.
What they're looking for
- 3–6 years of hands-on Application Security / VAPT experience.
- Strong experience in Web, API and Mobile Security Testing.
- Hands-on experience in Secure Code Review.
- Strong knowledge of OWASP Top 10 and application security fundamentals.
- Understanding of JWT, OAuth, API authentication/authorization and business logic vulnerabilities.
- Hands-on experience with Burp Suite, Postman, MobSF and OWASP ZAP.
- Good technical report writing, communication and stakeholder management skills.
- Bachelor's degree in Computer Science / IT / Cybersecurity or equivalent.
- Ability to work in a structured, compliance-driven BFSI environment.
Nice to have
- Experience in BFSI, UPI/payment applications and security compliance.
- Exposure to Frida / Objection is an advantage.
- Team coordination/mentoring experience preferred.
- Certifications: eWPT / eMAPT, CEH, OSCP / OSWE, CREST or equivalent.
Summarised by NextRaise from the employer’s description, which follows in full below.
Full description from employer
Role Overview
We are looking for an experienced Application Security Tester with 3–6 years of hands-on experience in Web, Mobile, API Security Testing and Secure Code Review (SCR). Experience in BFSI, UPI/payment applications and security compliance will be preferred.
The candidate should have strong technical skills along with exposure to team coordination, client interaction and audit support.
Key Responsibilities
- Perform Web Application Security Testing based on OWASP Top 10 and industry-standard methodologies.
- Conduct Mobile Application Security Testing for Android/iOS.
- Perform API Security Testing using Burp Suite, Postman, OWASP ZAP, etc.
- Conduct Secure Code Review (SCR) and identify insecure coding practices.
- Identify and validate vulnerabilities related to authentication, authorization, access control, injection, session management, sensitive data, business logic and API security.
- Perform vulnerability retesting and remediation validation.
- Prepare detailed VAPT/security assessment reports with evidence, impact and remediation recommendations.
- Perform/support security testing of UPI/payment applications, including API security, transaction flows, authentication, authorization and business logic.
- Support PCI-DSS and other security audits with VAPT reports, evidence, remediation and retest documentation.
- Coordinate with development/application teams for vulnerability remediation and closure.
- Handle client queries and participate in security review meetings.
Team Handling & Coordination
- Coordinate day-to-day activities of junior security testers.
- Allocate testing tasks and track assessment deliverables and timelines.
- Review vulnerability findings and reports for quality and technical accuracy.
- Mentor junior team members on application security testing and vulnerability validation.
- Coordinate with project managers, developers, application owners and client stakeholders.
- Support multiple security assessments and track remediation/closure.
Audit & Compliance Support
- Support PCI-DSS audits/assessments and client security compliance requirements.
- Prepare audit evidence including VAPT reports, scope, methodology, findings, remediation and retest results.
- Coordinate with auditors and stakeholders for security testing-related queries.
- Maintain assessment documentation and evidence for audit readiness.
Required Skills
- 3–6 years of hands-on Application Security / VAPT experience.
- Strong experience in Web, API and Mobile Security Testing.
- Hands-on experience in Secure Code Review.
- Strong knowledge of OWASP Top 10 and application security fundamentals.
- Understanding of JWT, OAuth, API authentication/authorization and business logic vulnerabilities.
- Hands-on experience with Burp Suite, Postman, MobSF and OWASP ZAP.
- Exposure to Frida / Objection is an advantage.
- BFSI, UPI/payment application and PCI-DSS exposure preferred.
- Good technical report writing, communication and stakeholder management skills.
- Team coordination/mentoring experience preferred.
Certifications – Preferred
- eWPT / eMAPT
- CEH
- OSCP / OSWE
- CREST or equivalent
Practical hands-on experience will be preferred over certification alone.
Qualification
- Bachelor's degree in Computer Science / IT / Cybersecurity or equivalent.
- Strong analytical, communication and documentation skills.
- Ability to work in a structured, compliance-driven BFSI environment.
Company
Talakunchi
Mumbai, India
Company facts come from this company's own listings. We only show what the postings themselves carry.