Security Compliance

Darwinbox Digital Solutions Pvt. Ltd.

Pune District

Hybrid

INR 2.400.000 - 3.600.000

Vollzeit

Vor 3 Tagen
Sei unter den ersten Bewerbenden
Bewerbungsgenerator

Hebe dich für diese Rolle von der Masse ab — erstelle in etwa einer Minute einen maßgeschneiderten Lebenslauf und ein Anschreiben.

Schaffe es an den ATS-Filtern vorbei

Zusammenfassung

Sonata Software is seeking a hands-on Security Engineer (VAPT & Remediation) in Pune with 5-8 years of experience. You will conduct penetration testing across applications, APIs, and infrastructure, identify vulnerabilities, and implement fixes in code and configurations.

The role covers cloud environments and requires strong tooling skills including Burp Suite, Nmap, Nessus, and more. Attention to secure design, risk-based remediation, and clear reporting are essential.

Qualifikationen

  • 5+ years of experience in penetration testing, application security, or security engineering with hands-on vulnerability remediation experience.
  • Strong understanding of VAPT methodologies, OWASP Top 10, OWASP ASVS, and secure application design.
  • Experience with manual penetration testing using Burp Suite Professional.
  • Strong knowledge of web and API security, including REST, GraphQL, SOAP, gRPC, OAuth 2.0, OpenID Connect, and JWT.
  • Experience identifying injection, authentication/session flaws, IDOR/BOLA, SSRF, deserialization, XXE, race conditions, business logic vulnerabilities, mass assignment, rate limiting, and authorization issues.
  • Hands-on mobile security testing across iOS and Android using tools such as Frida, Objection, MobSF, jadx, Ghidra, or Hopper.
  • Experience with thick-client security testing, reverse engineering, memory/local storage analysis, DLL hijacking, and client-side trust issues.
  • Infrastructure security testing experience using Nmap, Nessus, and Metasploit.
  • Working knowledge of Active Directory, Linux, and Windows security hardening.
  • Scripting experience using Python, Bash, or PowerShell.
  • Practical experience with Git workflows, pull requests, and code reviews.
  • Working knowledge of Nginx, Apache, IIS, TLS, Docker, Kubernetes, Terraform, or CloudFormation.

Aufgaben

  • Plan and execute penetration tests across web applications, APIs, mobile applications, thick clients, and supporting infrastructure.
  • Review application and infrastructure security covering authentication, authorization, session management, data flows, secrets management, network exposure, and cloud configurations.
  • Identify vulnerabilities beyond automated scanners through manual testing, including business logic flaws, chained vulnerabilities, and privilege escalation.
  • Execute and tune vulnerability scans across applications, hosts, and cloud environments.
  • Triage, deduplicate, and prioritize findings based on exploitability, business impact, and CVSS.
  • Track vulnerabilities through remediation and maintain accurate risk status.
  • Retest fixes and close findings only after confirming successful remediation.
  • Remediate vulnerabilities directly in application code across different languages and frameworks.
  • Fix infrastructure and configuration vulnerabilities involving web servers, TLS, cloud IAM, network rules, containers, Kubernetes, IaC, and CI/CD pipelines.
  • Apply security patches and upgrades to operating systems, frameworks, libraries, and third-party components.
  • Raise pull requests or configuration changes for vulnerabilities owned by other teams and drive them through completion.
  • Prepare clear security findings with reproduction steps, evidence, risk ratings, and remediation guidance.
  • Communicate security risks and remediation requirements effectively to developers, DevOps teams, and business stakeholders.

Kenntnisse

VAPT
Penetration Testing
Web Security
API Security
Vulnerability Remediation
Cloud Security
Infrastructure Security
Python Scripting
Bash Scripting
PowerShell

Tools

Burp Suite Professional
Nmap
Nessus
Metasploit
Frida
Objection
MobSF
Ghidra
Jadx
Hopper
Docker
Kubernetes
Terraform
CloudFormation
Git

Jobbeschreibung

Job Title- Security Engineer (VAPT & Remediation)
Location- Pune | Hybrid
Experience- 5-8 Years
Primary Skills- VAPT / Penetration Testing, Web & API Security, Vulnerability Remediation, Cloud & Infrastructure Security

ABOUT THE ROLE

This is a hands-on security engineering role responsible for the complete vulnerability lifecycle- identifying vulnerabilities, validating their impact, implementing remediation, and confirming that fixes are effective. The role involves penetration testing and security reviews across applications, APIs, mobile applications, infrastructure, and cloud environments, along with direct remediation through application code and infrastructure configuration.

ROLES AND RESPONSIBILITIES
Security Analysis & Testing

Plan and execute penetration tests across web applications, APIs, mobile applications, thick clients, and supporting infrastructure.

Review application and infrastructure security covering authentication, authorization, session management, data flows, secrets management, network exposure, and cloud configurations.

Identify vulnerabilities beyond automated scanners through manual testing, including business logic flaws, chained vulnerabilities, and privilege escalation.

Execute and tune vulnerability scans across applications, hosts, and cloud environments.

Triage, deduplicate, and prioritize findings based on exploitability, business impact, and CVSS.

Track vulnerabilities through remediation and maintain accurate risk status.

Retest fixes and close findings only after confirming successful remediation.

Remediation & Patching

Remediate vulnerabilities directly in application code across different languages and frameworks.

Fix infrastructure and configuration vulnerabilities involving web servers, TLS, cloud IAM, network rules, containers, Kubernetes, IaC, and CI/CD pipelines.

Apply security patches and upgrades to operating systems, frameworks, libraries, and third-party components.

Raise pull requests or configuration changes for vulnerabilities owned by other teams and drive them through completion.

Reporting & Communication

Prepare clear security findings with reproduction steps, evidence, risk ratings, and remediation guidance.

Communicate security risks and remediation requirements effectively to developers, DevOps teams, and business stakeholders.

QUALIFICATIONS & REQUIRED SKILLS
  • 5+ years of experience in penetration testing, application security, or security engineering with hands-on vulnerability remediation experience.
  • Strong understanding of VAPT methodologies, OWASP Top 10, OWASP ASVS, and secure application design.
  • Experience with manual penetration testing using Burp Suite Professional.
  • Strong knowledge of web and API security, including REST, GraphQL, SOAP, gRPC, OAuth 2.0, OpenID Connect, and JWT.
  • Experience identifying injection, authentication/session flaws, IDOR/BOLA, SSRF, deserialization, XXE, race conditions, business logic vulnerabilities, mass assignment, rate limiting, and authorization issues.
  • Hands-on mobile security testing across iOS and Android using tools such as Frida, Objection, MobSF, jadx, Ghidra, or Hopper.
  • Experience with thick-client security testing, reverse engineering, memory/local storage analysis, DLL hijacking, and client-side trust issues.
  • Infrastructure security testing experience using Nmap, Nessus, and Metasploit.
  • Working knowledge of Active Directory, Linux, and Windows security hardening.
  • Scripting experience using Python, Bash, or PowerShell.
  • Practical experience with Git workflows, pull requests, and code reviews.
  • Working knowledge of Nginx, Apache, IIS, TLS, Docker, Kubernetes, Terraform, or CloudFormation.
MANDATORY SKILLS
  • Web Application Security & OWASP
  • API Security
  • Burp Suite Professional
  • Vulnerability Assessment & Remediation
  • Mobile / Thick Client Security Testing
  • Infrastructure & Network Security
  • Secure Coding & Vulnerability Remediation
  • Python / Bash / PowerShell Scripting
  • Cloud Security Fundamentals across AWS, Azure, and GCP
GOOD TO HAVE SKILLS
  • Public security research, CVEs, bug bounty, or CTF experience.
  • SAST, DAST, and SCA integration into CI/CD pipelines.
  • Experience with security tooling such as Aikido.
  • Threat modeling and secure design reviews.
  • Knowledge of CIS benchmarks, CSPM, and tools such as Prowler.
  • SIEM, log analysis, incident response, and MITRE ATT&CK fundamentals.
  • Experience supporting SOC incident triage and detection engineering.
  • Knowledge of ISO 27001, SOC 2, and PCI DSS compliance requirements related to vulnerability remediation.
SUCCESS MEASURES
  • Security findings are remediated and successfully retested within agreed timelines.
  • Development and DevOps teams are supported through hands-on remediation.
  • Recurring vulnerability classes reduce through root-cause remediation.
  • Cloud misconfigurations and patch exposure windows remain minimal.
ABOUT SONATA SOFTWARE

Sonata Software is an AI-first modernization engineering company that helps enterprises transform legacy systems into intelligent, scalable business platforms. Powered by its Platformation framework and Harmoni.AI platform, Sonata delivers AI-led modernization across cloud, data, AI, Dynamics, test automation, and managed services. Headquartered in Bengaluru, India, Sonata has more than $1.2 billion in revenue and 6,400+ AI engineers supporting global delivery across regions including the US, UK, India, Malaysia, Mexico, Australia, DACH, and the Nordics. With deep partnerships across Microsoft, AWS, Salesforce, and Snowflake, Sonata helps Fortune 500 enterprises accelerate innovation, improve efficiency, and drive sustainable growth. For more information, please visit www.sonata-software.com .

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.

oder ziehe deine Datei hierhin.

Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Senior Devops Engineer
Senior Devops Engineer

Darwinbox Digital Solutions Pvt. Ltd. • Pune District

Hybrid
INR 1.500.000 - 2.100.000
Senior Test Automation Engineer
Senior Test Automation Engineer

Darwinbox Digital Solutions Pvt. Ltd. • Pune District

Hybrid
INR 1.800.000 - 2.600.000
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Clarivate Analytics • Bengaluru

Vor Ort
INR 1.500.000 - 2.100.000
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Clarivate • Bagaluru

Hybrid
INR 2.000.000 - 3.400.000
Assistant Manager - Global Information Security
Assistant Manager - Global Information Security

Tata Communications • Chennai District

Vor Ort
INR 2.500.000 - 4.200.000
Staff Product Security Engineer
Staff Product Security Engineer

Teladoc Health • Hyderabad

Vor Ort
INR 4.000.000 - 6.000.000
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

Vor Ort
INR 1.800.000 - 2.500.000
Sr. VAPT Engineer
Sr. VAPT Engineer

Neurealm Company • Chennai District

Hybrid
INR 1.800.000 - 3.200.000
Linux/Unix support & DevOps enginee
Linux/Unix support & DevOps enginee

Darwinbox Digital Solutions Pvt. Ltd. • Hyderabad

Vor Ort
INR 1.800.000 - 3.600.000
Senior Engineer, Product Security Testing
Senior Engineer, Product Security Testing

News Corp • Bengaluru

Vor Ort
INR 2.500.000 - 4.500.000