Job Description
Role: Application Security
Role Overview
We are looking for a hands-on Application Security expert to lead enterprise-scale security assessments across Web, Mobile, API, and Thick Client applications. The role focuses on advanced penetration testing, secure code reviews, DevSecOps, AppSec automation, and technical remediation. This is an individual contributor / technical leadership role, not a people-management position.
Key Responsibilities
- Lead Black Box, Grey Box & White Box penetration testing and vulnerability assessments.
- Perform security testing across Web, iOS/Android, APIs & Thick Client applications.
- Identify and validate vulnerabilities including OWASP Top 10, Authentication/Authorization, Injection, Business Logic & Mobile security issues.
- Conduct SAST, DAST, SCA and manual/automated secure code reviews.
- Design and implement Secure SDLC & DevSecOps practices.
- Build AppSec automation/scripts and customized security assessment frameworks.
- Provide code-level remediation guidance and work closely with Engineering/DevSecOps teams.
- Research emerging threats, attack techniques and zero-day vulnerabilities.
- Prepare risk-based security reports and present findings to engineering leadership/executives.
Must-Have Skills
- 5+ years of dedicated hands-on experience in Application Security / Cybersecurity.
- Strong experience in Web, Mobile, API & Thick Client Security Testing.
- Hands-on Penetration Testing & Secure Code Review experience.
- Strong knowledge of OWASP Top 10, SANS & Secure SDLC.
- Tools: Burp Suite, OWASP ZAP, Postman, Snyk/Checkmarx/Veracode/BlackDuck or equivalent.
- Mobile Security: MobSF, Frida, jadx, apktool, IDA or equivalent.
- Network Security: Nmap, Wireshark, Metasploit, Nessus/OpenVAS.
- Programming/Scripting: Python, Java, JavaScript, SQL & Bash/Shell.
- Strong stakeholder management and ability to influence engineering teams without direct people management.
Preferred Certifications
OSCP / OSWE / CISSP / CSSLP / CEH or relevant Mobile/AppSec certifications.
Ideal Candidate
A deeply technical, hands-on AppSec professional who has independently executed penetration testing, secure code reviews, AppSec automation and DevSecOps integrations across complex application environments.
No Referrers Available
There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.
