Application Security Engineer - Red Team

Air India

Gurugram District

On-site

INR 2,500,000 - 4,000,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Air India is seeking an experienced security engineer to lead Red Team operations across mobile, web, and API platforms. The role focuses on offensive security, threat emulation, and secure architecture reviews with emphasis on automation and real-world attack scenarios.

You will perform full-scope red team engagements, conduct VAPT, and collaborate with IT, DevOps, and security teams to drive remediation and secure design. Mentoring and KPI-driven improvements are part of the role.

Qualifications

  • Certifications demonstrate expertise in cybersecurity and are often required or preferred.
  • Detail oriented and methodical in testing and reporting.
  • Strong analytical and problem-solving abilities.

Responsibilities

  • Lead Red Team engagements across mobile, web, and API platforms.
  • Perform manual and automated VAPT for apps and APIs.
  • Reverse engineer mobile apps and analyze traffic, storage, and auth mechanisms.
  • Test REST, GraphQL, SOAP APIs for auth, data leakage issues.
  • Deliver high-quality reports and executive summaries; drive remediation.
  • Mentor junior red teamers and coordinate with IT/DevOps/security teams.

Skills

CERTIFICATIONS
Detail-oriented
Cybersecurity mindset
Analytical skills
Problem-solving
Passion for cybersecurity

Education

Bachelor's degree in Computer Science / Cybersecurity

Job description

1. Job Purpose
  • To lead and execute advanced Red Team operations and vulnerability assessments across mobile, web, and API platforms. The role demands deep technical expertise in offensive security, threat simulation, and secure architecture review, with a strong focus on automation, scalability, and real-world attack emulation.
2. Key Accountabilities
Strategic Activities
Red Team Operations
  • Design and execute full-scope Red Team engagements simulating real-world adversaries across enterprise, cloud, and AI/LLM environments.
  • Develop custom tooling and TTPs aligned with MITRE ATT&CK and MITRE ATLAS frameworks.
  • Conduct adversary emulation covering initial access, privilege escalation, lateral movement, and Active Directory/cloud exploitation.
  • Perform AI/LLM red teaming prompt injection, jailbreaking, agentic/tool-abuse, and RAG pipeline attacks per OWASP LLM Top 10.
  • Collaborate with Blue Team/SOC to validate detection coverage and drive purple team improvements.
  • Present attack narratives and risk-prioritized findings to technical and executive stakeholders.
  • Mentor junior red teamers and contribute to the team's engagement methodology and KPI framework.
Vulnerability Assessment & Penetration Testing
  • Perform manual and automated VAPT for mobile apps (Android/iOS), web applications, and APIs.
  • Identify and exploit vulnerabilities including OWASP Top 10, business logic flaws, and zero-days.
Mobile Security
  • Reverse engineer mobile apps and analyze traffic, storage, and authentication mechanisms.
  • Use tools like Frida, MobSF, Burp Suite, and custom scripts for dynamic/static analysis.
API & Web Security
  • Test REST, GraphQL, and SOAP APIs for authentication, authorization, and data leakage issues.
  • Perform advanced web app testing including SSRF, RCE, IDOR, and client-side vulnerabilities.
Reporting & Collaboration
  • Deliver high-quality technical reports and executive summaries.
  • Work closely with engineering, product, and security teams to drive remediation and secure design.
Team Management
  • Manage a team and coach them on tasks to ensure successful achievement of goals.
  • Monitor efforts, performance, and task demands and guide the team to achieve cohesiveness.

Any other additional responsibility could be assigned to the role holder from time to time as a standalone project or regular work. The same would be suitably represented in the Primary responsibilities and agreed between the incumbent, reporting officer and HR.

3. Skills Required for the role
  • Professional certifications play a significant role in the qualifications for a security engineer.
  • Certifications demonstrate expertise in specific areas of cybersecurity and are often required or strongly preferred by employers.
  • Detail oriented
  • Passion for cybersecurity
  • Analytical Skills
  • Problem Solving Mindset
4. Key Performance Indicators
  • Cybersecurity and Risk Management
  • Vulnerability Management
  • Compliance Adherence
  • Security Awareness Training Effectiveness
5. Key Interfaces
Internal Interfaces
Team Leads & Management
  • Provide updates and gain recommendations on security risks, compliance status, and strategic initiatives.
IT, DevOps & Application Teams
  • Collaborate closely with IT, DevOps teams to implement security issues/observation and get it validated.
  • Coordinate to ensure the security of applications, including web, API and mobile.
External Interfaces
Regulatory Authorities
  • Interface with regulatory authorities to ensure compliance with security regulations and standards, and to address any inquiries or audits related to security practices.
Third Party Vendor

Collaborate with vendors to evaluate security tool to address any security concerns or vulnerabilities.

6. Educational and Experience Requirements
Minimum Education Requirement
  • A bachelors degree in computer science, Information Technology, Cybersecurity, or a related field is commonly required. Some employers may accept equivalent work experience in lieu of a degree.
Minimum Requirement Desired
Experience
  • 5-7+ years of experience
  • Advanced degrees such as a masters degree or Ph.D. in Cybersecurity or a related field may be preferred for senior or specialized roles.
  • Certification required CRTP, OSCP, OSCE, GPEN, CEH
  • Understanding of network protocols, architecture, and security measures. Proficiency in configuring and managing firewalls, routers, switches, and other network security devices along with application security testing which includes web/ API and mobile.
  • Knowledge of various operating systems (Windows, Linux, Unix, etc.) and their security features.
  • Proficiency in vulnerability assessment tools and techniques to identify, prioritize, and remediate security vulnerabilities across systems and networks.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Ethical Hacker / Application Security Expert - Red Team
Ethical Hacker / Application Security Expert - Red Team

Win Global PR • Bengaluru

On-site
INR 350,000 - 700,000
Appsec Specialist - Lead
Appsec Specialist - Lead

Adani Group • Ahmedabad District

On-site
INR 2,800,000 - 4,200,000
Security Engineer - Red Team Operator / Engineer
Security Engineer - Red Team Operator / Engineer

PKF Algosmic Pvt Ltd • Maharashtra

On-site
INR 600,000 - 1,200,000
Cybersecurity Lead
Cybersecurity Lead

Trigyn Technologies Limited. • Gurugram District

On-site
INR 4,000,000 - 7,000,000
Security Engineer
Security Engineer

Recro • Bengaluru

On-site
INR 1,800,000 - 2,600,000
Red Team Specialist
Red Team Specialist

ESP Engineered • Mumbai

On-site
INR 1,200,000 - 2,000,000
Cutting-edge Red Team engagements
Collaborative environment
Continuous learning opportunities
Senior Security Engineer
Senior Security Engineer

Delta6Labs FinTech Pvt Ltd • Dadri

On-site
INR 1,500,000 - 2,500,000
Security Consultant - Red Team
Security Consultant - Red Team

Payatu • Bengaluru

On-site
INR 800,000 - 1,200,000
SOC Engineer
SOC Engineer

Mintskill HR Solutions LLP • Mumbai

On-site
INR 600,000 - 1,000,000
VAPT Lead
VAPT Lead

Adani Group • Ahmedabad District

On-site
INR 3,000,000 - 6,000,000