Application Security Consultant

Securityboat

Mumbai

On-site

INR 1,200,000 - 2,000,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Flexible engagements
Competitive compensation
Collaborative cybersecurity team
Professional development opportunities

Job summary

Securityboat in Mumbai is seeking a highly skilled Application Security Consultant to join our Offensive Security team. The role focuses on hands-on penetration testing of Web, Mobile, API, and Thick Client applications, and requires thinking like an attacker to identify complex vulnerabilities.

You will perform end-to-end assessments, craft actionable reports, and help remediate findings. A minimum of 3 years’ experience and at least one CVE publication are expected.

Qualifications

  • Minimum 3 years of hands-on penetration testing experience.
  • At least one published CVE
  • Ability to execute complete penetration testing engagements independently.

Responsibilities

  • Identify complex security vulnerabilities, business logic flaws, authentication and authorization weaknesses, and real-world attack paths beyond automated scanning.
  • Perform end-to-end authenticated security assessments and report findings.
  • Analyze external attack surface and leverage misconfigurations or publicly exposed assets within scope.

Skills

Web App Security Testing
Android App Security Testing
iOS App Security Testing
API Security Testing
Thick Client Security Testing
OWASP Top 10
OWASP API Security Top 10
Authenticated testing
Auth/Session/Access control testing
External attack surface analysis
Troubleshooting & reporting

Job description

Introduction

We are looking for a highly skilled Application Security Consultant to join our Offensive Security team. The ideal candidate should have extensive hands‑on experience performing penetration testing across modern applications, including Web, Mobile (Android & iOS), APIs, and Thick Client applications.

Responsibilities

This role requires an offensive mindset with the ability to identify complex security vulnerabilities, business logic flaws, authentication and authorization weaknesses, and real-world attack paths beyond automated scanning. The candidate should be capable of performing end‑to‑end authenticated security assessments and should possess strong knowledge of external attack surface analysis. During authorized engagements, the engineer should be able to identify alternative access paths to target applications by leveraging exposed assets, internet‑facing services, misconfigurations, publicly available information, credential exposure, or other legitimate attack vectors, wherever applicable within the agreed scope. The ideal candidate is someone who enjoys solving complex security challenges, thinks like an attacker, and can independently execute complete penetration testing engagements from reconnaissance through reporting.

Requirements
Technical Skills
  • Web Application Security Testing
  • Android Application Security Testing
  • iOS Application Security Testing
  • API Security Testing (REST, GraphQL, SOAP)
  • Thick Client/Desktop Application Security Testing
  • OWASP Top 10
  • OWASP API Security Top 10
  • Authenticated penetration testing
  • Authentication, authorization, session management, access control, and business logic testing
  • External network penetration testing and attack surface assessment
  • Identifying alternate attack paths using publicly exposed infrastructure, internet-facing assets, credential exposure (where authorized), or security misconfigurations
  • Strong analytical and problem‑solving skills
  • Technical documentation and report‑writing
Mandatory Requirements

Minimum 3 years of hands‑on penetration testing experience. At least one published CVE where the candidate has been credited. Ability to execute complete penetration testing engagements independently.

Certifications
  • OSCP / OSCP+
  • eCPPT
  • eWPTX
  • eMAPT
  • BSCP
  • CRTO
  • CARTP
  • Relevant Cloud Security Certifications
Benefits
  • Flexible engagements tailored to professional and personal goals.
  • Competitive compensation structure.
  • Access to specialized expertise and a collaborative cybersecurity team.
  • Professional development opportunities and recognition within the cybersecurity community.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Consultant
Application Security Consultant

SecurityBoat Cybersecurity Solutions Private Limited • Mumbai

On-site
INR 1,200,000 - 2,200,000
Competitive compensation
Specialized cybersecurity team
Professional development
Application Security Analyst
Application Security Analyst

Zs Associates • Pune District

On-site
INR 600,000 - 1,000,000
Application Security Analyst
Application Security Analyst

ZS • Maharashtra

On-site
INR 600,000 - 1,200,000
Security Engineer - OSCP
Security Engineer - OSCP

TAC Security • Delhi

On-site
INR 1,200,000 - 1,800,000
Application Security Analyst
Application Security Analyst

Zs Associates • Mumbai

On-site
INR 900,000 - 1,500,000
Senior Penetration Tester
Senior Penetration Tester

AppSecure Security • Bengaluru Urban

On-site
INR 1,500,000 - 2,100,000
Competitive compensation package
Comprehensive health insurance
Company-sponsored off-sites
+2
Penetration Tester / Ethical Hacker (Offensive Security)
Penetration Tester / Ethical Hacker (Offensive Security)

Zoho • India

Remote
INR 1,200,000 - 2,000,000
Software Engineer
Software Engineer

Cloudxtreme • Bengaluru, Hyderabad

On-site
INR 900,000 - 1,500,000
Associate Cybersecurity Consultant
Associate Cybersecurity Consultant

Security Brigade • Mumbai

On-site
INR 800,000 - 1,200,000
Competitive salary aligned to experience
Hybrid + remote-friendly
Sponsorship for offensive security certifications
+2
Senior Security Engineer
Senior Security Engineer

Delta6Labs FinTech Pvt Ltd • Dadri

On-site
INR 1,500,000 - 2,500,000