Security Lead- Red Teaming and Application Security

Security Brigade

Navi Mumbai

On-site

INR 4,000,000 - 7,000,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Security Brigade is seeking an experienced Security Lead- Red Teaming & Application Security to join our cybersecurity team in Navi Mumbai. The role demands hands-on expertise in web and mobile application security, red teaming, and offensive security engagements.

You will independently lead complex assessments, simulate attacker scenarios, and deliver actionable remediation guidance to stakeholders. The ideal candidate has 7+ years in cybersecurity, strong knowledge of OWASP Top 10 and API

Qualifications

  • 7+ years of overall experience in Cybersecurity/Offensive Security.
  • Strong expertise in Web Application Security Testing.
  • Mobile Application Security Testing for Android and/or iOS.
  • 2-3 years of hands-on Red Teaming or advanced Offensive Security engagements.
  • Knowledge of OWASP Top 10, OWASP API Security, and Mobile Security principles.

Responsibilities

  • Lead and perform comprehensive Web Application and Mobile Application Security Assessments.
  • Conduct advanced penetration testing and vulnerability assessments across applications, APIs, networks, and supporting infrastructure.
  • Perform Red Team exercises and adversary simulations to identify gaps in security controls and detection capabilities.
  • Identify, validate, and demonstrate the impact of complex security vulnerabilities.
  • Perform manual security testing beyond automated vulnerability scanning.
  • Assess authentication, authorization, session management, API security, business logic flaws, and common vulnerabilities.
  • Prepare detailed technical reports and executive summaries of findings.
  • Validate remediation and re-testing of identified vulnerabilities.
  • Support development and enhancement of security testing methodologies and internal capabilities.
  • Stay updated with emerging threats and exploit techniques.

Skills

Web App Security
Mobile App Security
Red Teaming
Offensive Security
Burp Suite
Nmap
Metasploit
Wireshark
MobSF
Frida

Tools

Burp Suite
Nmap
Metasploit
Wireshark
MobSF
Frida

Job description

Job Description

Security Brigade is looking for an experienced and highly skilled Security Lead- Red Teaming & Application Security to join our cybersecurity team. The ideal candidate will have strong hands-on expertise in Web Application Security, Mobile Application Security, and Red Teaming, with the ability to independently lead and execute complex security assessments and offensive security engagements.


The role requires a technically strong L3-level security professional who can identify, exploit, and validate security vulnerabilities, simulate real-world attack scenarios, and provide actionable remediation recommendations.


Key Responsibilities


  • Lead and perform comprehensive Web Application and Mobile Application Security Assessments.

  • Conduct advanced penetration testing and vulnerability assessments across applications, APIs, networks, and supporting infrastructure.

  • Perform Red Team exercises and adversary simulation activities to identify gaps in security controls and detection capabilities.

  • Identify, validate, and demonstrate the impact of complex security vulnerabilities.

  • Perform manual security testing beyond automated vulnerability scanning.

  • Assess authentication, authorization, session management, API security, business logic flaws, and common application vulnerabilities.

  • Conduct attack-path analysis and simulate real-world attacker techniques.

  • Work closely with technical stakeholders to communicate vulnerabilities, attack scenarios, business impact, and remediation recommendations.

  • Prepare detailed technical reports and executive-level summaries of security assessment findings.

  • Validate remediation and perform re-testing of identified vulnerabilities.

  • Support the development and enhancement of security testing methodologies, processes, and internal capabilities.

  • Stay updated with emerging threats, vulnerabilities, exploitation techniques, and offensive security tools.


Required Skills & Experience


  • 7+ years of overall experience in Cybersecurity, Information Security, VAPT, or Offensive Security.

  • Strong expertise in Web Application Security Testing.

  • Strong hands-on experience in Mobile Application Security Testing for Android and/or iOS.

  • Minimum 2-3 years of hands-on experience in Red Teaming or advanced Offensive Security engagements.

  • Strong understanding of OWASP methodologies, including:

    • OWASP Top 10

    • OWASP API Security

    • Mobile Application Security principles



  • Experience identifying and exploiting vulnerabilities such as:

    • Authentication and authorization flaws

    • Business logic vulnerabilities

    • Injection vulnerabilities

    • Broken access control

    • API security issues

    • Session management flaws

    • Client-side vulnerabilities



  • Experience with manual penetration testing and exploitation techniques.

  • Hands-on experience with security testing and offensive security tools such as Burp Suite, Nmap, Metasploit, Wireshark, MobSF, Frida, or similar tools.

  • Understanding of attacker tactics, techniques, and procedures and the ability to simulate realistic attack scenarios.

  • Strong analytical, problem-solving, and technical documentation skills.


Preferred Skills


  • Experience in API Security Testing.

  • Experience with network and infrastructure penetration testing.

  • Knowledge of Active Directory security and enterprise attack techniques.

  • Familiarity with MITRE ATT&CK framework.

  • Experience with cloud security testing would be an advantage.

  • Relevant certifications such as OSCP, OSWE, CRTP, CREST, CEH, eWPT, or similar will be an added advantage.


Key Attributes


  • Strong hands-on technical expertise with the ability to independently execute complex security assessments.

  • Ability to lead technical discussions and provide guidance during security engagements.

  • Strong communication skills for presenting findings to technical and non-technical stakeholders.

  • Ability to work effectively in an on-site, client-facing environment.

  • Detail-oriented with strong ownership and problem-solving skills.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Specialist Lead
Application Security Specialist Lead

Adani Enterprises Ltd • Ahmedabad District

On-site
INR 1,400,000 - 2,200,000
Red Team Specialist – I
Red Team Specialist – I

ESP Engineered • Mumbai

On-site
INR 2,000,000 - 4,500,000
Cyber Security Specialist
Cyber Security Specialist

Muthoot FinCorp (MFL) • India

On-site
INR 1,200,000 - 2,400,000
Appsec Specialist - Lead
Appsec Specialist - Lead

Adani Group • Ahmedabad District

On-site
INR 2,800,000 - 4,200,000
Red Team Specialist
Red Team Specialist

ESP Engineered • Mumbai

On-site
INR 1,200,000 - 2,000,000
Cutting-edge Red Team engagements
Collaborative environment
Continuous learning opportunities
Application Security Specialist - Lead
Application Security Specialist - Lead

adani capital pvt ltd • Ahmedabad District

On-site
INR 1,500,000 - 2,200,000
Red Team Specialist – I
Red Team Specialist – I

TalaKunchi Networks Pvt Ltd • Mumbai

On-site
INR 800,000 - 1,200,000
Opportunity to work on cutting-edge projects
Collaborative environment with continuous learning
Exposure to advanced security engagements
Application Security
Application Security

Airtel • India

On-site
INR 1,200,000 - 2,400,000
Security-focused culture
Security Penetration Testing Consultant
Security Penetration Testing Consultant

Withum • Bengaluru

On-site
INR 900,000 - 1,300,000
Senior Consultant, Offensive Security
Senior Consultant, Offensive Security

Jobtailor • Bengaluru

On-site
INR 1,800,000 - 3,000,000