TymblHub

© 2026 TymblHub

Senior Security Specialist

Lennox India Technology Centre (LITC)
Posted on
Lennox India Technology Centre (LITC) logo

Experience
6 - 11 yrs
Job Location
Chennai, India
Vacancy
1
Designation
Senior Security Specialist
Job Type
Not specified

Job Description

We are seeking a highly skilled Senior Security Specialist (IC3) with 6-9 years of experience in Application Security & Penetration Testing (VAPT), and security testing methodologies. The ideal candidate should possess strong expertise in DAST, API Security Testing, Mobile Application Security Testing (MAST), and hands-on exposure to AI-driven security testing and AI security risks. This role will work closely with development, DevOps, architecture, and product teams to identify, assess, and remediate security vulnerabilities throughout the SDLC.

Key Responsibilities

Application Security

  • Perform end-to-end application security assessments for web, mobile, and API applications.
  • Conduct threat modeling, secure design reviews, and architecture assessments.
  • Validate security controls and identify vulnerabilities using manual and automated techniques.
  • Review remediation recommendations and support development teams during vulnerability closure.

DAST (Dynamic Application Security Testing)

  • Conduct DAST assessments using tools such as:
    • Burp Suite Enterprise/Professional
    • Invicti (Netsparker)
    • Checkmarx
  • Analyze and validate findings to eliminate false positives.
  • Support tuning and optimization of DAST tools.
  • Develop DAST scanning standards, processes, and reporting mechanisms.

API Security

  • Perform API security testing against REST, SOAP, GraphQL, and Microservices architectures.
  • Validate API security controls including:
    • Authentication & Authorization
    • OAuth 2.0 / OIDC
    • JWT Security
    • Rate Limiting
    • Input Validation
    • API Abuse Scenarios
  • Conduct testing aligned with:
    • OWASP API Security Top 10
    • OWASP ASVS
    • OWASP Testing Guide
  • Utilize tools such as:
    • Postman
    • Burp Suite
    • OWASP ZAP
    • ReadyAPI

Mobile Application Security Testing (MAST)

  • Perform Android and iOS application security assessments.
  • Conduct dynamic mobile application testing.
  • Assess data storage, encryption, certificate pinning, and API security implementations.
  • Use security tools such as:
    • MobSF
    • NowSecure
    • Burp Suite

VAPT Activities

  • Conduct vulnerability assessments and penetration tests.
  • Validate exploitability and business impact of identified vulnerabilities.
  • Prepare detailed technical and executive reports.
  • Track remediation and support closure verification activities.
  • Collaborate with development teams to reduce recurring vulnerabilities.

AI Security & Emerging Technologies

  • Assess security risks associated with AI/LLM-powered applications.
  • Understand and evaluate:
    • Prompt Injection
    • Data Leakage Risks
    • Model Poisoning
    • Insecure Plugin Integrations
    • Excessive Agency
    • Sensitive Information Disclosure
  • Familiarity with:
    • OWASP Top 10 for LLM Applications
    • GenAI Security Best Practices
    • Secure AI Development Lifecycle
  • Utilize AI-assisted security testing tools to improve assessment efficiency.

Secure SDLC Integration

  • Collaborate with development and DevOps teams.
  • Support security gates within CI/CD pipelines.
  • Participate in security reviews and release approvals.

 

Required Technical Skills

Security Testing

  • DAST
  • API Security Testing
  • Mobile Application Security Testing (MAST)
  • Web Application Penetration Testing
  • Vulnerability Assessment

Security Frameworks

  • OWASP Top 10
  • OWASP API Security Top 10
  • OWASP Mobile Top 10
  • OWASP ASVS
  • CWE/SANS Top 25
  • MITRE ATT&CK

Security Tools

  • Burp Suite
  • Invicti/Netsparker
  • OWASP ZAP
  • Postman
  • MobSF
  • NowSecure
  • Frida
  • Objection
  • Kali Linux Toolset

Scripting

  • Python
  • PowerShell
  • Bash
  • JavaScript (basic understanding)

Cloud & DevSecOps (Preferred)

  • Azure / AWS Security Basics
  • CI/CD Security Concepts
  • Container Security Exposure

Required Qualifications

  • Bachelor’s degree in computer science, Cyber Security, Information Technology, or a related field.
  • 6-9 years of experience in Application Security, VAPT, or Security Testing.
  • Strong understanding of web, mobile, and API security principles.
  • Experience interacting with development and architecture teams.
  • Excellent analytical, problem-solving, and communication skills.

Preferred Certifications

  • CEH
  • GWAPT
  • GPEN
  • OSCP
  • eMAPT
  • Certified API Security Analyst

Success Measures

  • Reduction in critical and high-risk vulnerabilities.
  • Timely completion of security assessments.
  • Improved remediation closure rates.
  • Increased adoption of secure coding practices.
  • Effective integration of AppSec controls within SDLC and DevSecOps pipelines.
  • Successful identification and mitigation of AI/LLM security risks.

Nice to Have

  • Exposure to SAST and SCA tools (Fortify, Checkmarx, Veracode, Mend, GHAS).
  • Experience with AI-assisted code review and security assessment tools.
  • Security automation and reporting dashboard experience.
  • Experience working in enterprise-scale AppSec programs.