Hebe dich für diese Rolle von der Masse ab — erstelle in etwa einer Minute einen maßgeschneiderten Lebenslauf und ein Anschreiben.
Sonata Software is seeking a hands-on Security Engineer (VAPT & Remediation) in Pune with 5-8 years of experience. You will conduct penetration testing across applications, APIs, and infrastructure, identify vulnerabilities, and implement fixes in code and configurations.
The role covers cloud environments and requires strong tooling skills including Burp Suite, Nmap, Nessus, and more. Attention to secure design, risk-based remediation, and clear reporting are essential.
Job Title- Security Engineer (VAPT & Remediation)
Location- Pune | Hybrid
Experience- 5-8 Years
Primary Skills- VAPT / Penetration Testing, Web & API Security, Vulnerability Remediation, Cloud & Infrastructure Security
This is a hands-on security engineering role responsible for the complete vulnerability lifecycle- identifying vulnerabilities, validating their impact, implementing remediation, and confirming that fixes are effective. The role involves penetration testing and security reviews across applications, APIs, mobile applications, infrastructure, and cloud environments, along with direct remediation through application code and infrastructure configuration.
Plan and execute penetration tests across web applications, APIs, mobile applications, thick clients, and supporting infrastructure.
Review application and infrastructure security covering authentication, authorization, session management, data flows, secrets management, network exposure, and cloud configurations.
Identify vulnerabilities beyond automated scanners through manual testing, including business logic flaws, chained vulnerabilities, and privilege escalation.
Execute and tune vulnerability scans across applications, hosts, and cloud environments.
Triage, deduplicate, and prioritize findings based on exploitability, business impact, and CVSS.
Track vulnerabilities through remediation and maintain accurate risk status.
Retest fixes and close findings only after confirming successful remediation.
Remediate vulnerabilities directly in application code across different languages and frameworks.
Fix infrastructure and configuration vulnerabilities involving web servers, TLS, cloud IAM, network rules, containers, Kubernetes, IaC, and CI/CD pipelines.
Apply security patches and upgrades to operating systems, frameworks, libraries, and third-party components.
Raise pull requests or configuration changes for vulnerabilities owned by other teams and drive them through completion.
Prepare clear security findings with reproduction steps, evidence, risk ratings, and remediation guidance.
Communicate security risks and remediation requirements effectively to developers, DevOps teams, and business stakeholders.
Sonata Software is an AI-first modernization engineering company that helps enterprises transform legacy systems into intelligent, scalable business platforms. Powered by its Platformation framework and Harmoni.AI platform, Sonata delivers AI-led modernization across cloud, data, AI, Dynamics, test automation, and managed services. Headquartered in Bengaluru, India, Sonata has more than $1.2 billion in revenue and 6,400+ AI engineers supporting global delivery across regions including the US, UK, India, Malaysia, Mexico, Australia, DACH, and the Nordics. With deep partnerships across Microsoft, AWS, Salesforce, and Snowflake, Sonata helps Fortune 500 enterprises accelerate innovation, improve efficiency, and drive sustainable growth. For more information, please visit www.sonata-software.com .