Engineer II - Application Security Test

NewSpace Research and Technologies

Bengaluru

On-site

INR 900,000 - 1,300,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

NewSpace Research and Technologies, a Bengaluru/Delhi NCR startup, seeks an Application Security Test Engineer to strengthen our security posture across code, applications, and IoT devices. You will perform DAST/SAST, secure code reviews, and risk assessments while collaborating with developers to embed security throughout the SDLC.

The role requires 2–3 years of hands-on experience, strong knowledge of web and IoT security, and proficiency with Burp Suite and OWASP ZAP.

Qualifications

  • 2-3 years of experience in security application testing or related fields.
  • Strong understanding of web application security, IoT security, and communication protocols.
  • Experience with security testing tools like Burp Suite, OWASP ZAP, and others.
  • Proficiency in programming languages such as Python, Java, or C/C++.
  • Understanding of secure coding practices and software development lifecycles.
  • Knowledge of common security frameworks and standards (e.g., OWASP, NIST).

Responsibilities

  • DAST/SAST (Dynamic and Static Application Security Testing): Identify vulnerabilities in code, applications, and IoT devices.
  • Secure Code Review - Coding Best Practices: Review source code for secure coding principles.
  • Software Development Posture and Inventory Management/Monitoring: Track security state of software assets.
  • Perform security testing on code, applications, IoT devices, and communication protocols.
  • Identify vulnerabilities and report findings to the development team.
  • Collaborate with developers to integrate security testing into the SDLC.
  • Review and audit security-related documentation for compliance with best practices.
  • Develop and execute penetration testing scripts and automated testing tools.
  • Conduct risk assessments and provide actionable mitigation recommendations.
  • Stay updated with trends, technologies, and best practices in application security.

Skills

Web application security
IoT security
Security testing
Secure coding practices
SDLC security integration
Programming: Python
Programming: Java
Programming: C/C++

Tools

Burp Suite
OWASP ZAP

Job description

We are a start-up based out of Bengaluru & Delhi NCR. We are engaged in development of next generation missions and technologies (NGM&T) towards future warfare needs of the Indian defence forces. It is undertaking research towards enhancing persistence and autonomy for unmanned vehicles and robotic swarms. NRT’s product development portfolio includes a solar power stratospheric high altitude pseudo satellite (HAPS) unmanned platform and an air/ground launched stand-off autonomous system.

Application Security Test Engineer

Test Engineer Grade II/III (Code, Application, IoT Tech)" role involves performing dynamic and static application security testing (DAST/SAST), secure code reviews, and managing software development posture. Key responsibilities include identifying and reporting vulnerabilities in code, applications, and IoT devices, collaborating with developers to integrate security into the SDLC, auditing security documentation, and conducting risk assessments.

Key Responsibilities:

  • DAST/SAST (Dynamic Application Security Testing/Static Application Security Testing): Perform both dynamic and static analysis of applications to identify security vulnerabilities.
  • Secure Code Review - Coding Best Practices: Conduct systematic reviews of source code to ensure adherence to secure coding principles and identify potential weaknesses.
  • Software Development Posture and Inventory Management/Monitoring: Continuously manage and monitor the security state of all software assets and their underlying infrastructure.
  • Perform security testing on code, applications, IoT devices, and communication protocols developed by the organization: Execute various security tests on the organization's proprietary software, IoT devices, and communication methods to uncover vulnerabilities.
  • Identify vulnerabilities and weaknesses in the software and applications, reporting findings to the development team: Discover and clearly report security flaws in software and applications to development teams for remediation.
  • Collaborate with developers to integrate security testing throughout the software development lifecycle (SDLC): Work closely with development teams to embed security activities into every stage of the software development process.
  • Review and audit security-related documentation for compliance with security best practices: Examine and verify security documentation to ensure it meets established industry standards and best practices.
  • Develop and execute penetration testing scripts and automated testing tools to identify potential exploits: Create and run specialized programs to simulate attacks and discover exploitable vulnerabilities.
  • Conduct risk assessments and provide actionable recommendations for mitigating security risks and vulnerabilities: Evaluate potential security threats and offer practical solutions to reduce or eliminate risks.
  • Stay updated with the latest trends, technologies, and best practices in application security: Continuously research and learn about emerging threats, new security tools, and industry standards to maintain expertise.
Required Skills:
  • 2-3 years of experience in security application testing or related fields.
  • Strong understanding of web application security, IoT security, and communication protocols.
  • Experience with security testing tools like Burp Suite, OWASP ZAP, and others.
  • Proficiency in programming languages such as Python, Java, or C/C++.
  • Understanding of secure coding practices and software development lifecycles.
Desired Skills:
  • Experience in penetration testing, vulnerability assessments, and threat modeling.
  • Knowledge of common security frameworks and standards (e.g., OWASP, NIST).
  • Familiarity with automated testing and DevSecOps practices.
  • Certifications like CEH (Certified Ethical Hacker), OSCP (Offensive Security Certified Professional) are a plus.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Engineer I - Embedded Security
Sr. Engineer I - Embedded Security

NewSpace Research and Technologies • Bengaluru

On-site
INR 1,000,000 - 2,000,000
Application Security Engineer
Application Security Engineer

Byline Learning Solutions • Pune District

On-site
INR 1,200,000 - 1,800,000
Application Security Engineer
Application Security Engineer

Tata Consultancy Services • New Delhi, Dadri

On-site
INR 2,000,000 - 3,500,000
Application Security Engineer
Application Security Engineer

Cynosure Corporate Solutions • Chennai District

On-site
INR 1,500,000 - 2,500,000
Engineer II - Software Development
Engineer II - Software Development

NewSpace Research and Technologies • Bengaluru

On-site
INR 600,000 - 1,200,000
Application Testing Engineer
Application Testing Engineer

Quess • Chennai District, Bengaluru, Pune District

Hybrid
INR 700,000 - 1,500,000
Application Security Engineer
Application Security Engineer

Basebiz • Pune District

On-site
INR 1,800,000 - 3,000,000
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2coms • Bengaluru

On-site
INR 2,500,000 - 4,000,000
Application and Product Security I Analyst I
Application and Product Security I Analyst I

Vertiv Co • Pune District

On-site
INR 1,000,000 - 1,800,000
Penetration Testing Engineer / Application Security Testing Engineer
Penetration Testing Engineer / Application Security Testing Engineer

VMC Soft Technologies, Inc • Dadri

On-site
INR 2,500,000 - 4,200,000