Job Description
Job Title- Security Engineer (VAPT & Remediation)
Location- Pune | Hybrid
Experience- 5–8 Years
Primary Skills- VAPT / Penetration Testing, Web & API Security, Vulnerability Remediation, Cloud & Infrastructure Security
About The RoleThis is a hands-on security engineering role responsible for the complete vulnerability lifecycle—identifying vulnerabilities, validating their impact, implementing remediation, and confirming that fixes are effective. The role involves penetration testing and security reviews across applications, APIs, mobile applications, infrastructure, and cloud environments, along with direct remediation through application code and infrastructure configuration.
Roles And Responsibilities
Security Analysis & Testing
- Plan and execute penetration tests across web applications, APIs, mobile applications, thick clients, and supporting infrastructure.
- Review application and infrastructure security covering authentication, authorization, session management, data flows, secrets management, network exposure, and cloud configurations.
- Identify vulnerabilities beyond automated scanners through manual testing, including business logic flaws, chained vulnerabilities, and privilege escalation.
- Execute and tune vulnerability scans across applications, hosts, and cloud environments.
- Triage, deduplicate, and prioritize findings based on exploitability, business impact, and CVSS.
- Track vulnerabilities through remediation and maintain accurate risk status.
- Retest fixes and close findings only after confirming successful remediation.
Remediation & Patching
- Remediate vulnerabilities directly in application code across different languages and frameworks.
- Fix infrastructure and configuration vulnerabilities involving web servers, TLS, cloud IAM, network rules, containers, Kubernetes, IaC, and CI/CD pipelines.
- Apply security patches and upgrades to operating systems, frameworks, libraries, and third-party components.
- Raise pull requests or configuration changes for vulnerabilities owned by other teams and drive them through completion.
Reporting & Communication
- Prepare clear security findings with reproduction steps, evidence, risk ratings, and remediation guidance.
- Communicate security risks and remediation requirements effectively to developers, DevOps teams, and business stakeholders.
Qualifications & Required Skills
- 5+ years of experience in penetration testing, application security, or security engineering with hands-on vulnerability remediation experience.
- Strong understanding of VAPT methodologies, OWASP Top 10, OWASP ASVS, and secure application design.
- Experience with manual penetration testing using Burp Suite Professional.
- Strong knowledge of web and API security, including REST, GraphQL, SOAP, gRPC, OAuth 2.0, OpenID Connect, and JWT.
- Experience identifying injection, authentication/session flaws, IDOR/BOLA, SSRF, deserialization, XXE, race conditions, business logic vulnerabilities, mass assignment, rate limiting, and authorization issues.
- Hands-on mobile security testing across iOS and Android using tools such as Frida, Objection, MobSF, jadx, Ghidra, or Hopper.
- Experience with thick-client security testing, reverse engineering, memory/local storage analysis, DLL hijacking, and client-side trust issues.
- Infrastructure security testing experience using Nmap, Nessus, and Metasploit.
- Working knowledge of Active Directory, Linux, and Windows security hardening.
- Ability to read and modify code in multiple languages, with strong proficiency in at least two of Java, C#/.NET, JavaScript/TypeScript, Python, PHP, Go, Swift, or Kotlin.
- Scripting experience using Python, Bash, or PowerShell.
- Practical experience with Git workflows, pull requests, and code reviews.
- Working knowledge of Nginx, Apache, IIS, TLS, Docker, Kubernetes, Terraform, or CloudFormation.
Mandatory Skills
- VAPT / Penetration Testing
- Web Application Security & OWASP
- API Security
- Burp Suite Professional
- Vulnerability Assessment & Remediation
- Mobile / Thick Client Security Testing
- Infrastructure & Network Security
- Secure Coding & Vulnerability Remediation
- Python / Bash / PowerShell Scripting
- Git & Code Review
- Docker / Kubernetes
- Cloud Security Fundamentals across AWS, Azure, and GCP
Good To Have Skills
- Public security research, CVEs, bug bounty, or CTF experience.
- SAST, DAST, and SCA integration into CI/CD pipelines.
- Experience with security tooling such as Aikido.
- Threat modeling and secure design reviews.
- Knowledge of CIS benchmarks, CSPM, and tools such as Prowler.
- SIEM, log analysis, incident response, and MITRE ATT&CK fundamentals.
- Experience supporting SOC incident triage and detection engineering.
- Knowledge of ISO 27001, SOC 2, and PCI DSS compliance requirements related to vulnerability remediation.
SUCCESS MEASURES
- Security findings are remediated and successfully retested within agreed timelines.
- Development and DevOps teams are supported through hands-on remediation.
- Recurring vulnerability classes reduce through root-cause remediation.
- Cloud misconfigurations and patch exposure windows remain minimal.
About Sonata Software
Sonata Software is an AI-first modernization engineering company that helps enterprises transform legacy systems into intelligent, scalable business platforms. Powered by its Platformation framework and Harmoni.AI platform, Sonata delivers AI-led modernization across cloud, data, AI, Dynamics, test automation, and managed services. Headquartered in Bengaluru, India, Sonata has more than $1.2 billion in revenue and 6,400+ AI engineers supporting global delivery across regions including the US, UK, India, Malaysia, Mexico, Australia, DACH, and the Nordics. With deep partnerships across Microsoft, AWS, Salesforce, and Snowflake, Sonata helps Fortune 500 enterprises accelerate innovation, improve efficiency, and drive sustainable growth. For more information, please visit www.sonata-software.com .