Application Security Consultant

Securityboat

Mumbai

On-site

INR 1,200,000 - 2,000,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Flexible engagements
Competitive compensation
Collaborative cybersecurity team
Professional development opportunities

Job summary

Securityboat in Mumbai is seeking a highly skilled Application Security Consultant to join our Offensive Security team. The role focuses on hands-on penetration testing of Web, Mobile, API, and Thick Client applications, and requires thinking like an attacker to identify complex vulnerabilities.

You will perform end-to-end assessments, craft actionable reports, and help remediate findings. A minimum of 3 years’ experience and at least one CVE publication are expected.

Qualifications

  • Minimum 3 years of hands-on penetration testing experience.
  • At least one published CVE
  • Ability to execute complete penetration testing engagements independently.

Responsibilities

  • Identify complex security vulnerabilities, business logic flaws, authentication and authorization weaknesses, and real-world attack paths beyond automated scanning.
  • Perform end-to-end authenticated security assessments and report findings.
  • Analyze external attack surface and leverage misconfigurations or publicly exposed assets within scope.

Skills

Web App Security Testing
Android App Security Testing
iOS App Security Testing
API Security Testing
Thick Client Security Testing
OWASP Top 10
OWASP API Security Top 10
Authenticated testing
Auth/Session/Access control testing
External attack surface analysis
Troubleshooting & reporting

Job description

Introduction

We are looking for a highly skilled Application Security Consultant to join our Offensive Security team. The ideal candidate should have extensive hands‑on experience performing penetration testing across modern applications, including Web, Mobile (Android & iOS), APIs, and Thick Client applications.

Responsibilities

This role requires an offensive mindset with the ability to identify complex security vulnerabilities, business logic flaws, authentication and authorization weaknesses, and real-world attack paths beyond automated scanning. The candidate should be capable of performing end‑to‑end authenticated security assessments and should possess strong knowledge of external attack surface analysis. During authorized engagements, the engineer should be able to identify alternative access paths to target applications by leveraging exposed assets, internet‑facing services, misconfigurations, publicly available information, credential exposure, or other legitimate attack vectors, wherever applicable within the agreed scope. The ideal candidate is someone who enjoys solving complex security challenges, thinks like an attacker, and can independently execute complete penetration testing engagements from reconnaissance through reporting.

Requirements
Technical Skills
  • Web Application Security Testing
  • Android Application Security Testing
  • iOS Application Security Testing
  • API Security Testing (REST, GraphQL, SOAP)
  • Thick Client/Desktop Application Security Testing
  • OWASP Top 10
  • OWASP API Security Top 10
  • Authenticated penetration testing
  • Authentication, authorization, session management, access control, and business logic testing
  • External network penetration testing and attack surface assessment
  • Identifying alternate attack paths using publicly exposed infrastructure, internet-facing assets, credential exposure (where authorized), or security misconfigurations
  • Strong analytical and problem‑solving skills
  • Technical documentation and report‑writing
Mandatory Requirements

Minimum 3 years of hands‑on penetration testing experience. At least one published CVE where the candidate has been credited. Ability to execute complete penetration testing engagements independently.

Certifications
  • OSCP / OSCP+
  • eCPPT
  • eWPTX
  • eMAPT
  • BSCP
  • CRTO
  • CARTP
  • Relevant Cloud Security Certifications
Benefits
  • Flexible engagements tailored to professional and personal goals.
  • Competitive compensation structure.
  • Access to specialized expertise and a collaborative cybersecurity team.
  • Professional development opportunities and recognition within the cybersecurity community.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security
Application Security

Airtel • India

On-site
INR 1,200,000 - 2,400,000
Security-focused culture
Senior Security Consultant
Senior Security Consultant

Payatu Technologies Pvt Ltd • Pune District

On-site
INR 1,800,000 - 3,200,000
Senior Penetration Tester
Senior Penetration Tester

AppSecure Security • Bengaluru Urban

Remote
INR 1,500,000 - 2,100,000
Competitive compensation package
Comprehensive health insurance
Company-sponsored off-sites
+2
Software Engineer
Software Engineer

Cloudxtreme • Bengaluru, Hyderabad

Hybrid
INR 900,000 - 1,500,000
Penetration Tester | OSCP / OSWE Mandatory
Penetration Tester | OSCP / OSWE Mandatory

Cyberintelsys Consulting Services Private Limited • Chennai District

On-site
INR 1,200,000 - 2,000,000
Application Security Engineer
Application Security Engineer

Security Lit • Mumbai

On-site
INR 900,000 - 1,200,000
Hiring For Penetration Tester - Mumbai
Hiring For Penetration Tester - Mumbai

Saint Gobain • Mumbai, Navi Mumbai

On-site
INR 4,000,000 - 8,000,000
Application Penetration Tester
Application Penetration Tester

ControlCase, LLC • Mumbai

On-site
INR 800,000 - 2,000,000
Senior Security Engineer
Senior Security Engineer

Delta6Labs FinTech Pvt Ltd • Dadri

On-site
INR 1,500,000 - 2,500,000
Principal Penetration Tester/ Offensive Security Team Lead
Principal Penetration Tester/ Offensive Security Team Lead

BreachLock, Inc. • Dadri

On-site
INR 1,500,000 - 2,000,000