Application Security Engineer

Cyberpwn

Bengaluru

On-site

INR 900,000 - 1,300,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Cyberpwn in Bengaluru is seeking a security testing professional to perform penetration testing on web applications and APIs, both automated and manual. You will configure security testing tools, validate scan outputs, and report remediation guidance to developers and stakeholders.

The role requires hands-on experience with Burp Suite, OWASP ZAP, and familiarity with CVSS scoring, OAuth/JWT/SAML authentication, and scripting in Python/PowerShell/Bash.

Qualifications

  • Hands-on application penetration testing across web apps and APIs.
  • Familiar with OWASP Top 10 and OWASP API Security Top 10.
  • Proficiency with Burp Suite and OWASP ZAP.
  • Knowledge of CVSS v3.x scoring.
  • Understanding OAuth, JWT, SAML authentication.
  • Basic scripting in Python/PowerShell/Bash.

Responsibilities

  • Execute hybrid and automated penetration testing across web apps and APIs.
  • Configure dynamic application security testing tools.
  • Validate scans and triage findings, report remediation guidance.
  • Prepare and deliver penetration test reports with OWASP mapping.
  • Support manual testing on critical applications and assist transitions.

Job description

Role & responsibilities:-
KEY RESPONSIBILITY AREAS (KRA)
  • Execute hybrid and fully automated penetration testing across web applications and APIs in line with the agreed testing schedule.
  • Configure and operate authenticated and unauthenticated dynamic application security testing using Fortify on Demand, OWASP ZAP, Burp Suite, and Qualys WAS.
  • Validate and triage automated scan output, eliminate false positives, and confirm exploitability before findings are reported.
  • Assign severity to findings using CVSS and application context, and prepare findings for peer review.
  • Produce penetration test reports with OWASP-mapped findings, reproduction steps, and remediation guidance.
  • Perform retest validation following remediation closure and document whether fixes are effective.
  • Support Senior Engineers on manual testing of critical applications, taking ownership of defined test areas.
  • Maintain scan configurations, authentication profiles, and application inventory records to ensure accurate testing scope.
  • Track application security findings through to closure in the client workflow system and elevate at risk items ahead of SLA breach.
  • Support walkthrough sessions with development teams and capture remediation actions and owners.
  • Contribute to the application testing schedule, coverage tracking, and monthly application security reporting inputs.
  • Participate in shadowing, reverse-shadowing, and assisted-operation phases of knowledge transfer during mobilisation and transition.
KEY PERFORMANCE INDICATORS (KPIs)
  • Assessment execution rate against the planned testing schedule.
  • Report delivery timeliness following completion of testing.
  • False-positive rate in reported findings.
  • Severity rating precision, measured by severity upheld on peer review.
  • Retest completion timeliness following receipt of remediation evidence.
  • Application testing coverage contribution against the annual portfolio plan.
  • Timeliness of escalation for at risk findings ahead of SLA breach.
  • Accuracy and timeliness of reporting inputs and coverage tracking.
REQUIRED TECHNICAL SKILLS & EXPERIENCE
  • Hands-on application penetration testing experience across web applications and APIs.
  • Working knowledge of OWASP Top 10 and OWASP API Security Top 10, with practical testing experience against each category.
  • Proficiency with Burp Suite and OWASP ZAP for manual request manipulation and guided testing, with exposure to Fortify on Demand or Qualys WAS an advantage.
  • Understanding of CVSS v3.x scoring and the application context factors that influence severity.
  • Working understanding of authentication and session management technologies including OAuth, JWT, and SAML.
  • Basic scripting (Python, PowerShell, or Bash) for test support, data handling, and report automation.
  • Familiarity with IT service management and ticketing tools, with ServiceNow and Azure Boards preferred, for finding lifecycle tracking.
  • Clear written and verbal communication for reporting findings and coordinating with development teams.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Testing Engineer
Application Security Testing Engineer

Infosys • Bengaluru

On-site
INR 900,000 - 1,200,000
Application Testing Engineer
Application Testing Engineer

Quess • Chennai District, Bengaluru, Pune District

Hybrid
INR 700,000 - 1,500,000
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
Application Security Engineer
Application Security Engineer

Basebiz • Bengaluru

On-site
INR 1,800,000 - 2,800,000
Application Security Engineer
Application Security Engineer

Basebiz • Chennai District

On-site
INR 1,200,000 - 1,800,000
Application Security Engineer
Application Security Engineer

Security Lit • Mumbai

On-site
INR 900,000 - 1,200,000
Application Security Engineer
Application Security Engineer

Cynosure Corporate Solutions • Chennai District

On-site
INR 1,500,000 - 2,500,000
Vulnerability Assessment & Penetration Testing (VAPT) Engineer
Vulnerability Assessment & Penetration Testing (VAPT) Engineer

Zensar • Pune District

On-site
INR 1,200,000 - 2,800,000
Application Security Engineer
Application Security Engineer

Tata Consultancy Services • New Delhi, Dadri

On-site
INR 2,000,000 - 3,500,000
Penetration Testing Engineer / Application Security Testing Engineer
Penetration Testing Engineer / Application Security Testing Engineer

VMC Soft Technologies, Inc • Dadri

On-site
INR 2,500,000 - 4,200,000