Get more replies from employers
Send a job-specific resume in minutes.
Tata Consultancy Services is seeking an Application Security Engineer in New Delhi to perform vulnerability assessments, manual penetration testing, and security testing across web, API, and mobile applications. The role requires hands‑on expertise with security tooling and SDLC security practices.
You will identify vulnerabilities, validate remediation, and collaborate with development teams to implement fixes, while staying current with industry best practices and threat intelligence.
We are looking for a skilled Application Security Engineer with hands‑on experience in Web Application Security, API Security, Mobile Application Security, and Manual Penetration Testing.
The ideal candidate should have expertise in identifying security vulnerabilities, performing security assessments, validating remediation, and supporting secure application development practices.
Perform authorized vulnerability assessment and penetration testing for web applications, APIs, mobile applications, and related infrastructure components.
Identify, validate, and document security vulnerabilities including OWASP Top 10, API Security Top 10, authentication, authorization, session management, business logic, and configuration weaknesses.
Use security testing tools such as Burp Suite, OWASP ZAP, Postman, Fortify, Nessus, Acunetix, and similar tools for scanning, validation, and exploitation verification.
Analyze scan results, remove false positives, prioritize true vulnerabilities based on risk, and prepare clear technical reports with impact and remediation recommendations.
Coordinate with development, DevOps, and infrastructure teams to explain findings, support remediation, and perform retesting after fixes.
Create security test cases and checklists based on application functionality, threat scenarios, compliance requirements, and secure coding standards.
Maintain proper evidence, screenshots, testing notes, and audit‑ready documentation for all identified and remediated vulnerabilities.
Support secure SDLC activities including SAST, DAST, dependency scanning, API security testing, and vulnerability management governance.
Stay updated on latest attack techniques, vulnerabilities, security tools, and industry best practices.