Role & responsibilities
- Primary mandate skill required
Dynamic Application Security Testing (DAST) triage and vulnerability assessment
— ability to review and validate DAST scan findings, distinguish true vs false positives (using tools like Burp Suite/Postman), prioritize risk using CVSS/risk scoring, and drive remediation with dev/DevOps teams (including CI/CD integration support).
- Secondary mandate skill required.
Web & API security fundamentals with hands‑on validation skills— strong understanding of HTTP methods/status codes, request/response flows, authN/authZ, and web traffic analysis (browser dev tools/network tab), with ability to validate findings using Burp Suite/Postman/OWASP ZAP.
- Open to look at CWR’s – Yes / No– Yes
- Flexible to hire in any location – If not, please mention job location – Yes – Pan India
- Detailed Job Description–
Job Summary
We are seeking a dedicated CyberSecurity Specialist with expertise in Threat and Vulnerability Management (TVM) to join our team. The ideal candidate will have 7 to 11 years of experience in cybersecurity, focusing on web services testing and security practices. This role involves working in a hybrid model with day shifts, ensuring the security of our digital assets and contributing to the safety of our users.
Responsibilities
- DAST Triage and Vulnerability Assessment Review and triage dynamic application security testing DAST scan results identify, prioritize, and validate vulnerabilities in running applications using CVSS scoring and risk frameworks to determine business impact and recommend remediation strategies False Positive Management Assess and validate false positives from DAST scans using tools such as Burp Suite and Postman working with development teams to understand their application document findings and maintain accuracy of vulnerability data Remediation Support Work with development teams to identify and implement fixes for DAST identified vulnerabilities track remediation efforts and verify resolutions Policy Compliance Support enforcement of application security policies ensure compliance with security requirements for web and API applications Documentation Create vulnerability assessments remediation guidance and knowledge base articles for development teams based on DAST findings processes and identified best practices Tool Management Assist in managing and optimizing enterprise DAST tool maintain tool hygiene and data quality DevOps Integration Support integration of DAST tools within CICD pipelines assist with security gate implementation for DAST testing Cross functional Collaboration Partner with developers DevOps and security teams to embed dynamic testing practices into the SDLC Reporting and Metrics Track and report on DAST vulnerability metrics remediation status and security trends 2 4 years of experience in application security software development or DevOps Strong knowledge of Dynamic Application Security Testing DAST tools and runtime vulnerability management Understanding of vulnerability assessment and prioritization CVSS risk scoring Proficiency in at least one programming language Python Go JavaScript Java or similar Familiarity with SQL and database concepts including querying data manipulation data dashboarding and visualization Familiarity with web application and API fundamentals including HTTP methods error codes request response structures authentication authorization web traffic analysis and the use of browser developer tools eg network tab Experience with vulnerability databases NVD CVE GitHub Advisory or similar Basic understanding of CI CD pipelines and DevOps practices Strong analytical and problem solving skills Excellent written and verbal communication skills Ability to work cross functionally with development and operations teams