Security Researcher (Web Application)

Security Brigade

Mumbai

On-site

INR 1,000,000 - 1,500,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive salary
Sponsorship for certifications
Internal lab environment for research

Job summary

Security Brigade is looking for a Security Researcher to join our application security practice in Mumbai, India. This role involves hands-on web application penetration testing, working directly with enterprise customers across various sectors including BFSI, fintech, healthcare, and SaaS.

You will manage the entire process, from scoping and testing to documenting findings and guiding remediation efforts. Applicants should have over 2 years of experience in application security and a strong grasp of security standards and testing methodologies.

Qualifications

  • 2+ years of hands-on web application penetration testing experience.
  • Strong knowledge of OWASP Top 10 and common business-logic flaw patterns.
  • Proficient with Burp Suite and capable of writing custom payloads/extensions.

Responsibilities

  • Run web application penetration tests end-to-end on customer applications.
  • Document findings with evidence and remediation guidance.
  • Walk customer engineering teams through findings and advise on fixes.

Skills

Web application penetration testing
Burp Suite
OWASP Top 10
JavaScript frameworks (React, Angular, Vue)
Backend technologies (Node, Django, Rails, Spring)
REST and GraphQL APIs
Excellent written English communication

Job description

Hands-on web application penetration testing with end-to-end ownership of scoping, testing, reporting, and remediation walkthroughs for enterprise customers.

Security Brigade is hiring a Security Researcher to join our application security practice. You will run hands‑on web application penetration tests for enterprise customers across BFSI, fintech, healthcare, and SaaS — backed by our Lemon audit‑management platform and reviewed through our L1/L2/L3 senior chain so you grow under structured supervision from day one. You will own the full lifecycle: scoping with the customer, executing the test, documenting findings with proof‑of‑concept evidence, walking remediation owners through fixes, and revalidating closures. The role is a strong fit for engineers two to four years into application security who want depth — and a direct path to senior research as we scale.

What You’ll Do
  • Run web application penetration tests end-to-end on customer applications
  • Apply manual testing techniques alongside Burp / OWASP ZAP / custom tooling — automated scanners are a start, not a finish
  • Document findings with clear proof‑of‑concept, business impact, and remediation guidance — written for engineering teams to act on
  • Walk customer engineering teams through findings; advise on fixes; revalidate closures
  • Contribute to internal research, methodology updates, and Lemon platform improvements
What We’re Looking For
  • 2+ years of hands‑on web application penetration testing experience
  • Strong working knowledge of OWASP Top 10 (web) and common business‑logic flaw patterns
  • Proficient with Burp Suite (Pro a plus), and comfortable writing custom payloads / extensions where needed
  • Comfortable reading and reasoning about modern application stacks (React / Angular / Vue front‑ends; Node / Django / Rails / Spring back‑ends; REST + GraphQL APIs)
  • Excellent written English for report‑quality output
  • Practical lab experience on Hack The Box, PortSwigger Web Security Academy, or TryHackMe a strong signal
What We Offer
  • Competitive salary aligned to experience
  • Hybrid + remote‑friendly
  • Sponsorship for OSCP, OSWE, BSCP, or equivalent certifications
  • Internal lab environment for research time
  • Direct mentorship from L2/L3 senior researchers on every engagement
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Associate Cybersecurity Consultant
Associate Cybersecurity Consultant

Security Brigade • Mumbai

Hybrid
INR 800,000 - 1,200,000
Competitive salary aligned to experience
Hybrid + remote-friendly
Sponsorship for offensive security certifications
+2
Senior Security Researcher — ShadowMap
Senior Security Researcher — ShadowMap

Security Brigade • Mumbai

Hybrid
INR 1,200,000 - 1,800,000
Competitive salary + performance-linked variable
Sponsorship for offensive-security certifications
Internal research time
Application Security Engineer
Application Security Engineer

DigiCert • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Generous time off policies
Top shelf benefits
Education, wellness, and lifestyle support
Application Security Consultant
Application Security Consultant

Securityboat • Mumbai

On-site
INR 1,200,000 - 2,000,000
Flexible engagements
Competitive compensation
Collaborative cybersecurity team
+1
Senior Penetration Tester
Senior Penetration Tester

AppSecure Security • Bengaluru Urban

Remote
INR 1,500,000 - 2,100,000
Competitive compensation package
Comprehensive health insurance
Company-sponsored off-sites
+2
Software Engineer
Software Engineer

Cloudxtreme • Bengaluru, Hyderabad

Hybrid
INR 900,000 - 1,500,000
Application Security
Application Security

Airtel • India

On-site
INR 1,200,000 - 2,400,000
Security-focused culture
Senior Security Research Engineer
Senior Security Research Engineer

Jobgether • India

On-site
INR 1,200,000 - 1,800,000
Competitive salary
Fully remote work
Open vacation policy
+3
Security Pen tester
Security Pen tester

Infios • Bengaluru

On-site
INR 3,000,000 - 5,500,000
Senior Vulnerability Management Engineer
Senior Vulnerability Management Engineer

LSEG • Bengaluru

On-site
INR 1,200,000 - 1,800,000