Application Security

Airtel

India

On-site

INR 1,200,000 - 2,400,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Security-focused culture

Job summary

Airtel is seeking a hands-on Application Security expert to lead enterprise-scale security assessments across Web, Mobile, API and Thick Client applications. You will drive advanced penetration testing, secure code reviews, DevSecOps integration and AppSec automation in an individual contributor/technical leadership role.

You will guide remediation with Engineering teams, build automated frameworks, and stay ahead of emerging threats and vulnerabilities.

Qualifications

  • 5+ years of dedicated hands-on experience in Application Security / Cybersecurity.
  • Strong knowledge of Web, Mobile, API & Thick Client Security Testing.
  • Hands-on Penetration Testing & Secure Code Review experience.
  • Strong knowledge of OWASP Top 10, SANS & Secure SDLC.

Responsibilities

  • Lead Black Box, Grey Box & White Box testing and vulnerability assessments.
  • Test Web, iOS/Android, APIs & Thick Client applications for security issues.
  • Identify and validate vulnerabilities including OWASP Top 10, auth, injection, and mobile security.
  • Conduct SAST, DAST, SCA and manual/automated secure code reviews.
  • Design and implement Secure SDLC & DevSecOps practices.
  • Build AppSec automation/scripts and customized assessment frameworks.
  • Provide code-level remediation guidance with Engineering/DevSecOps teams.
  • Research emerging threats and zero-day vulnerabilities.
  • Prepare risk-based security reports and present findings to leadership.

Skills

Application Security
Web Security Testing
Mobile Security Testing
API Security Testing
Secure SDLC
DevSecOps
Penetration Testing
Secure Code Review
Threat Modelling
Stakeholder Influence

Tools

Burp Suite
OWASP ZAP
Postman
Snyk
Checkmarx
Veracode
BlackDuck
MobSF
Frida
jadx
apktool
IDA
Nmap
Wireshark
Metasploit
Nessus
OpenVAS
Python
Java
JavaScript
SQL
Bash/Shell

Job description

Role: Application Security
Role Overview

We are looking for a hands-on Application Security expert to lead enterprise-scale security assessments across Web, Mobile, API, and Thick Client applications. The role focuses on advanced penetration testing, secure code reviews, DevSecOps, AppSec automation, and technical remediation. This is an individual contributor / technical leadership role, not a people-management position.

Key Responsibilities
  • Lead Black Box, Grey Box & White Box penetration testing and vulnerability assessments.
  • Perform security testing across Web, iOS/Android, APIs & Thick Client applications.
  • Identify and validate vulnerabilities including OWASP Top 10, Authentication/Authorization, Injection, Business Logic & Mobile security issues.
  • Conduct SAST, DAST, SCA and manual/automated secure code reviews.
  • Design and implement Secure SDLC & DevSecOps practices.
  • Build AppSec automation/scripts and customized security assessment frameworks.
  • Provide code-level remediation guidance and work closely with Engineering/DevSecOps teams.
  • Research emerging threats, attack techniques and zero-day vulnerabilities.
  • Prepare risk-based security reports and present findings to engineering leadership/executives.
Must-Have Skills
  • 5+ years of dedicated hands-on experience in Application Security / Cybersecurity.
  • Strong experience in Web, Mobile, API & Thick Client Security Testing.
  • Hands-on Penetration Testing & Secure Code Review experience.
  • Strong knowledge of OWASP Top 10, SANS & Secure SDLC.
  • Tools: Burp Suite, OWASP ZAP, Postman, Snyk/Checkmarx/Veracode/BlackDuck or equivalent.
  • Mobile Security: MobSF, Frida, jadx, apktool, IDA or equivalent.
  • Network Security: Nmap, Wireshark, Metasploit, Nessus/OpenVAS.
  • Programming/Scripting: Python, Java, JavaScript, SQL & Bash/Shell.
  • Strong stakeholder management and ability to influence engineering teams without direct people management.
Preferred Certifications

OSCP / OSWE / CISSP / CSSLP / CEH or relevant Mobile/AppSec certifications.

Ideal Candidate

A deeply technical, hands-on AppSec professional who has independently executed penetration testing, secure code reviews, AppSec automation and DevSecOps integrations across complex application environments.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Consultant
Application Security Consultant

Securityboat • Mumbai

On-site
INR 1,200,000 - 2,000,000
Flexible engagements
Competitive compensation
Collaborative cybersecurity team
+1
Application Security Engineer
Application Security Engineer

Basebiz • Bengaluru

On-site
INR 1,800,000 - 2,800,000
Application Security Engineer
Application Security Engineer

Whitefield Careers • Bengaluru

On-site
INR 800,000 - 1,200,000
Application Security Engineer
Application Security Engineer

Basebiz • Chennai District

On-site
INR 1,200,000 - 1,800,000
Software Engineer
Software Engineer

Cloudxtreme • Bengaluru, Hyderabad

Hybrid
INR 900,000 - 1,500,000
Mobile Application Security Lead (AppSec)
Mobile Application Security Lead (AppSec)

ESP Engineered • Mumbai

On-site
INR 1,500,000 - 2,500,000
Application Security Lead | Offshore
Application Security Lead | Offshore

Photon • Hyderabad

On-site
INR 850,000 - 1,800,000
Application Security Engineer
Application Security Engineer

Ola • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Application Security Engineer
Application Security Engineer

DigiCert • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Generous time off policies
Top shelf benefits
Education, wellness, and lifestyle support
Application Security Engineer
Application Security Engineer

Basebiz • Pune District

On-site
INR 1,800,000 - 3,000,000