Application Security Engineer

Kotak Mahindra Bank
Posted on
Kotak Mahindra Bank logo

Experience
2 - 5 yrs
Job Location
Bengaluru, India
Vacancy
1
Designation
Application Security Engineer
Job Type
Not specified

Job Description

Application Security Engineer


Role


Were seeking an Application Security Engineer to identify, validate, and track vulnerabilities across web, APIs, mobile, and backend systems. You’ll perform app/API/database security testing, analyse changes for risk, coordinate fixes with developers, and help uplift secure development practices.


What we offer

• Technology-first culture focused on secure, reliable digital banking

• Hands-on exposure to modern stacks, tools, and cloud services

• Collaboration with product, engineering, and platform teams

• Meaningful work improving customer trust and product resilience


What we ask for

• Test: web apps, REST/GraphQL APIs, mobile (Android/iOS), backend & databases

• Identify: SQLi, XSS, CSRF, Broken Auth/Access, business logic issues • Assess SSL/TLS configs; flag weak ciphers/protocols/misconfigs

• Assist basic cloud reviews (AWS/Azure/GCP): IAM, storage, API gateways

• Document vulns with repro steps; validate fixes; track remediation

• Review new features/changes for security impact before release


Technical Skills:

• Must Have:

o OWASP Top 10, API security fundamentals, HTTP/HTTPS

o Tools: Burp Suite, OWASP ZAP, SQLMap, Postman, Nmap (basic)

o Auth concepts: OAuth, JWT, sessions


• Good to Have:

o Mobile app security basics; cloud security fundamentals

o Python/Bash scripting; familiarity with DevSecOps tooling

o Banking/FinTech exposure Preferred qualifications


• Bachelors in CS/Cybersecurity/Information Security • Certifications: CEH / eJPT / Security+

No Referrers Available

There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.