Application Security Engineer - Red Team

Air India
Posted on
Air India logo

Experience
7 - 10 yrs
Job Location
Gurugram, India
Vacancy
1
Designation
Application Security Engineer
Job Type
Not specified

Job Description

1. Job Purpose


  • To lead and execute advanced Red Team operations and vulnerability assessments across mobile, web, and API platforms. The role demands deep technical expertise in offensive security, threat simulation, and secure architecture review, with a strong focus on automation, scalability, and real-world attack emulation.

2. Key Accountabilities


Strategic Activities

Red Team Operations

  • Design and execute full-scope Red Team engagements simulating real-world adversaries across enterprise, cloud, and AI/LLM environments.
  • Develop custom tooling and TTPs aligned with MITRE ATT&CK and MITRE ATLAS frameworks.
  • Conduct adversary emulation covering initial access, privilege escalation, lateral movement, and Active Directory/cloud exploitation.
  • Perform AI/LLM red teaming prompt injection, jailbreaking, agentic/tool-abuse, and RAG pipeline attacks per OWASP LLM Top 10.
  • Collaborate with Blue Team/SOC to validate detection coverage and drive purple team improvements.
  • Present attack narratives and risk-prioritized findings to technical and executive stakeholders.
  • Mentor junior red teamers and contribute to the team's engagement methodology and KPI framework.

Vulnerability Assessment & Penetration Testing


  • Perform manual and automated VAPT for mobile apps (Android/iOS), web applications, and APIs.
  • Identify and exploit vulnerabilities including OWASP Top 10, business logic flaws, and zero-days.

Mobile Security

  • Reverse engineer mobile apps and analyze traffic, storage, and authentication mechanisms.
  • Use tools like Frida, MobSF, Burp Suite, and custom scripts for dynamic/static analysis.

API & Web Security

  • Test REST, GraphQL, and SOAP APIs for authentication, authorization, and data leakage issues.
  • Perform advanced web app testing including SSRF, RCE, IDOR, and client-side vulnerabilities.

Reporting & Collaboration

  • Deliver high-quality technical reports and executive summaries.
  • Work closely with engineering, product, and security teams to drive remediation and secure design.

Team Management

  • Manage a team and coach them on tasks to ensure successful achievement of goals.
  • Monitor efforts, performance, and task demands and guide the team to achieve cohesiveness.

Any other additional responsibility could be assigned to the role holder from time to time as a standalone project or regular work. The same would be suitably represented in the Primary responsibilities and agreed between the incumbent, reporting officer and HR.


3. Skills Required for the role

  • Professional certifications play a significant role in the qualifications for a security engineer.
  • Certifications demonstrate expertise in specific areas of cybersecurity and are often required or strongly preferred by employers.
  • Detail oriented
  • Passion for cybersecurity
  • Analytical Skills
  • Problem Solving Mindset

4. Key Performance Indicators

  • Cybersecurity and Risk Management
  • Vulnerability Management
  • Compliance Adherence
  • Security Awareness Training Effectiveness

5. Key Interfaces

Internal Interfaces

Team Leads & Management


  • Provide updates and gain recommendations on security risks, compliance status, and strategic initiatives.

IT, DevOps & Application Teams


  • Collaborate closely with IT, DevOps teams to implement security issues/observation and get it validated.
  • Coordinate to ensure the security of applications, including web, API and mobile.

External Interfaces

Regulatory Authorities


  • Interface with regulatory authorities to ensure compliance with security regulations and standards, and to address any inquiries or audits related to security practices.

Third Party Vendor


Collaborate with vendors to evaluate security tool to address any security concerns or vulnerabilities.


6. Educational and Experience Requirements

Minimum Education Requirement


  • A bachelors degree in computer science, Information Technology, Cybersecurity, or a related field is commonly required. Some employers may accept equivalent work experience in lieu of a degree.

Minimum Requirement Desired

Experience


  • 5-7+ years of experience
  • Advanced degrees such as a masters degree or Ph.D. in Cybersecurity or a related field may be preferred for senior or specialized roles.
  • Certification required CRTP, OSCP, OSCE, GPEN, CEH
  • Understanding of network protocols, architecture, and security measures. Proficiency in configuring and managing firewalls, routers, switches, and other network security devices along with application security testing which includes web/ API and mobile.
  • Knowledge of various operating systems (Windows, Linux, Unix, etc.) and their security features.
  • Proficiency in vulnerability assessment tools and techniques to identify, prioritize, and remediate security vulnerabilities across systems and networks.

No Referrers Available

There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.