Application Security Engineer

Tata Consultancy Services

New Delhi, Dadri

On-site

INR 2,000,000 - 3,500,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Tata Consultancy Services is seeking an Application Security Engineer in New Delhi to perform vulnerability assessments, manual penetration testing, and security testing across web, API, and mobile applications. The role requires hands‑on expertise with security tooling and SDLC security practices.

You will identify vulnerabilities, validate remediation, and collaborate with development teams to implement fixes, while staying current with industry best practices and threat intelligence.

Qualifications

  • Identifies security vulnerabilities in web, API, and mobile applications.
  • Performs security assessments and validates remediation actions.
  • Creates security test cases based on threat scenarios and industry standards.
  • Maintains evidence and audit-ready documentation of findings and fixes.

Responsibilities

  • Perform authorized vulnerability assessments for web apps, APIs, mobile apps, and related infrastructure.
  • Identify and document vulnerabilities including OWASP Top 10 and API security top 10.
  • Use Burp Suite, OWASP ZAP, Fortify, Nessus, Acunetix, Postman for testing and verification.
  • Analyze results, remove false positives, and produce actionable remediation reports with impact.
  • Coordinate with development, DevOps, and infra teams to retest after fixes and validate mitigations.

Skills

Vulnerability assessment
Manual penetration testing
Threat modeling
OWASP Top 10
Security testing
Remediation guidance
Secure SDLC

Tools

Burp Suite
OWASP ZAP
Fortify
Nessus
Acunetix
Postman

Job description

Role: Application Security Engineer
Location: New Delhi
Experience: 4 - 10 Years

We are looking for a skilled Application Security Engineer with hands‑on experience in Web Application Security, API Security, Mobile Application Security, and Manual Penetration Testing.

The ideal candidate should have expertise in identifying security vulnerabilities, performing security assessments, validating remediation, and supporting secure application development practices.

Must‑Have Skills
  • Perform vulnerability assessment and manual penetration testing for web applications, APIs, and application components.
  • Create security test cases based on application functionality, threat scenarios, OWASP Top 10, API Security Top 10, and business logic risks.
  • Use security tools such as Burp Suite, OWASP ZAP, Fortify, Nessus, Acunetix, Postman, and similar tools for scanning and validation.
  • Analyze scan results, validate true positives, identify false positives, and prepare clear technical vulnerability reports.
  • Work with development teams to explain vulnerabilities, recommend remediation steps, and perform retesting after fixes.
  • Knowledge of SAST, DAST, API security testing, dependency scanning, and vulnerability management processes.
Key Responsibilities

Perform authorized vulnerability assessment and penetration testing for web applications, APIs, mobile applications, and related infrastructure components.

Identify, validate, and document security vulnerabilities including OWASP Top 10, API Security Top 10, authentication, authorization, session management, business logic, and configuration weaknesses.

Use security testing tools such as Burp Suite, OWASP ZAP, Postman, Fortify, Nessus, Acunetix, and similar tools for scanning, validation, and exploitation verification.

Analyze scan results, remove false positives, prioritize true vulnerabilities based on risk, and prepare clear technical reports with impact and remediation recommendations.

Coordinate with development, DevOps, and infrastructure teams to explain findings, support remediation, and perform retesting after fixes.

Create security test cases and checklists based on application functionality, threat scenarios, compliance requirements, and secure coding standards.

Maintain proper evidence, screenshots, testing notes, and audit‑ready documentation for all identified and remediated vulnerabilities.

Support secure SDLC activities including SAST, DAST, dependency scanning, API security testing, and vulnerability management governance.

Stay updated on latest attack techniques, vulnerabilities, security tools, and industry best practices.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

Byline Learning Solutions • Pune District

On-site
INR 1,200,000 - 1,800,000
Application Security Engineer
Application Security Engineer

Basebiz • Pune District

On-site
INR 1,800,000 - 3,000,000
Application Security Engineer
Application Security Engineer

Basebiz • Chennai District

On-site
INR 1,200,000 - 1,800,000
Application Security Engineer
Application Security Engineer

Basebiz • Bengaluru

On-site
INR 1,800,000 - 2,800,000
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2coms • Bengaluru

On-site
INR 2,500,000 - 4,000,000
Security Engineer
Security Engineer

Amantya Technologies • India

On-site
INR 1,200,000 - 1,800,000
Security Expert (Application / Web Security) (Min 5 Years)
Security Expert (Application / Web Security) (Min 5 Years)

AagatiServe Pvt Ltd • India

On-site
INR 1,000,000 - 1,500,000
Application Security Engineer (6 Months Contract)
Application Security Engineer (6 Months Contract)

Weekday AI (YC W21) • Hyderabad

On-site
INR 1,500,000 - 2,000,000
Application Security Engineer
Application Security Engineer

Whitefield Careers • Bengaluru

On-site
INR 800,000 - 1,200,000
Application Security
Application Security

Airtel • India

On-site
INR 1,200,000 - 2,400,000
Security-focused culture