Application Security Consultant

ERM Placement Services

Kolkata District

On-site

INR 2,800,000 - 4,000,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

ERM Placement Services is seeking an experienced Application Security Consultant in Bangalore to strengthen the security posture across the SDLC. You will perform security assessments, code reviews, and threat modeling, collaborating with development, architecture, DevOps, and security teams to ensure secure design and deployment.

The ideal candidate has hands-on experience with vulnerability assessments, secure coding practices, and strong knowledge of OWASP Top 10 and API security.

Qualifications

  • 6-8 years of experience in Application Security, Secure Code Review, or Security Consulting.
  • Strong understanding of Web, Mobile, and API security.
  • Hands-on experience with vulnerability assessments and secure code reviews.
  • Knowledge of OWASP Top 10 and API Security Top 10.

Responsibilities

  • Perform comprehensive security assessments of web, mobile, and API components.
  • Review application security controls and provide remediation guidance to development teams.
  • Conduct threat modeling and SSDLC alignment for projects.
  • Prepare technical reports and present findings to stakeholders.
  • Collaborate with DevOps, architecture, and security teams to embed security in development workflows.

Skills

Application Security
Secure Code Review
Vulnerability Assessments
Threat Modeling
SSDLC
OWASP Top 10
OAuth/SAML/OpenID Connect
JWT
Encryption
Communication

Education

B.E./B.Tech / B.S / MCA / M.Tech / MBA

Tools

Secure SDLC tooling

Job description

Job Title: Application Security Consultant
Experience: 6-8 Years
Location: Bangalore
Education: B.E. / B.Tech / B.S / MCA / M.Tech / MBA

Role Overview

We are seeking an experienced Application Security Consultant to strengthen the security posture of enterprise applications throughout the Software Development Life Cycle (SDLC). The ideal candidate will have hands-on experience in application security assessments, secure code review, vulnerability validation, and providing remediation guidance to development teams. The role requires close collaboration with development, architecture, DevOps, and security teams to ensure applications are designed and deployed securely.

Key Responsibilities
  • Perform comprehensive security assessments of web applications, mobile applications, APIs, and related components.
  • Identify security vulnerabilities through manual testing, automated scanning, secure code review, and analysis of application security controls.
  • Review application security controls, including:
    • Authentication and Authorization
    • Session Management
    • Input Validation
    • Cryptography and Encryption
    • Secure Configuration
    • Error Handling and Logging
  • Conduct application architecture reviews and assist in threat modeling exercises to identify potential security risks.
  • Provide secure coding recommendations and remediation guidance to development teams.
  • Validate the effectiveness of remediation activities by performing re-assessments and verification testing.
  • Support Secure Software Development Life Cycle (SSDLC) initiatives and release assurance processes.
  • Collaborate with developers, architects, DevOps, and infrastructure teams to integrate security into development workflows.
  • Identify, prioritize, and communicate application security risks with clear mitigation recommendations.
  • Ensure application security practices align with organizational security standards, policies, and compliance requirements.
  • Prepare detailed technical reports and present findings to technical and business stakeholders.
  • Stay updated with emerging application security threats, vulnerabilities, attack techniques, and industry best practices.
Required Skills & Experience
  • 6-8 years of experience in Application Security, Secure Code Review, or Security Consulting.
  • Strong understanding of Web, Mobile, and API security.
  • Hands-on experience performing:
    • Vulnerability Assessments
    • Secure Code Reviews
    • Manual Security Testing
    • Application Security Reviews
  • Strong knowledge of:
    • OWASP Top 10
    • OWASP API Security Top 10
    • Secure SDLC (SSDLC)
    • Threat Modeling
    • Secure Coding Practices
  • Understanding of common application vulnerabilities such as:
    • SQL Injection
    • Cross-Site Scripting (XSS)
    • Cross-Site Request Forgery (CSRF)
    • Broken Authentication
    • Server-Side Request Forgery (SSRF)
    • Insecure Deserialization
    • Security Misconfiguration
  • Familiarity with authentication protocols such as OAuth, SAML, OpenID Connect, and JWT.
  • Knowledge of encryption standards, certificate management, and secure communication protocols.
  • Experience validating remediation and working with development teams to resolve security findings.
  • Strong analytical, communication, and stakeholder management skills.
Mandatory Certification (Any One)*
  • GIAC Web Application Penetration Tester (GWAPT)
  • GIAC Web Application Defender (GWEB)
  • Certified AppSec Practitioner (CASS)
  • Certified Ethical Hacker (CEH)
  • EC-Council Certified Security Analyst (ECSA)
  • Licensed Penetration Tester (LPT)
  • Offensive Security Certified Professional (OSCP)
Mandatory Certification (Any One)*
  • GIAC Web Application Penetration Tester (GWAPT)
  • GIAC Web Application Defender (GWEB)
  • Certified AppSec Practitioner (CASS)
  • Certified Ethical Hacker (CEH)
  • EC-Council Certified Security Analyst (ECSA)
  • Licensed Penetration Tester (LPT)
  • Offensive Security Certified Professional (OSCP)
  • Offensive Security Certified Expert (OSCE)
  • Certified Information Security Manager (CISM)
  • Certified Information Systems Security Professional (CISSP)
  • Certificate of Cloud Security Knowledge (CCSK)
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Consultant
Application Security Consultant

ERM Placement Services • Delhi

On-site
INR 1,200,000 - 1,800,000
Application Security
Application Security

Airtel • India

On-site
INR 1,200,000 - 2,400,000
Security-focused culture
Security Expert (Application / Web Security) (Min 5 Years)
Security Expert (Application / Web Security) (Min 5 Years)

AagatiServe Pvt Ltd • India

On-site
INR 1,000,000 - 1,500,000
Application Security Analyst
Application Security Analyst

Tata Consultancy Services • Mumbai

On-site
INR 900,000 - 1,500,000
Application Security Consultant
Application Security Consultant

Securityboat • Mumbai

On-site
INR 1,200,000 - 2,000,000
Flexible engagements
Competitive compensation
Collaborative cybersecurity team
+1
Security Analyst – Application Security VAPT
Security Analyst – Application Security VAPT

JUARA IT SOLUTIONS • Chennai District

On-site
INR 900,000 - 1,300,000
L3 - Tech & Digital - Infosec Application Security Engineer - BACL
L3 - Tech & Digital - Infosec Application Security Engineer - BACL

bajajauto • Pune District

On-site
INR 1,200,000 - 1,800,000
Application Security Engineer
Application Security Engineer

US Software Group Inc • Bengaluru

Hybrid
INR 9,033,000 - 11,744,000
Application Security Consultant
Application Security Consultant

SecurityBoat Cybersecurity Solutions Private Limited • Mumbai

On-site
INR 1,200,000 - 2,200,000
Competitive compensation
Specialized cybersecurity team
Professional development
Senior Security Consultant
Senior Security Consultant

Payatu Technologies Pvt Ltd • Pune District

On-site
INR 1,800,000 - 3,200,000