Security Tester

Disprz

Chennai District

On-site

INR 1,800,000 - 3,600,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Disprz is seeking a security-focused professional to lead penetration testing, secure SDLC, and DevSecOps initiatives across cloud and on‑prem environments. You will assess exploitability, validate fixes, and drive risk‑based remediation with engineering teams.

Responsibility includes automating security tests in CI/CD, supporting ISO 27001, SOC 2 and GDPR audits, and mentoring developers on secure coding. Proficiency with Burp Suite, ZAP, Nmap, Nessus and related tools is essential.

Qualifications

  • Bachelor's degree in Computer Science, Information Security, or related field.
  • 4–8 years of experience in application security or security testing.
  • Hands-on with security tools and programming languages.

Responsibilities

  • Execute penetration tests across black-box, grey-box, and white-box approaches.
  • Validate security fixes and verify vulnerability remediation.
  • Integrate security testing into CI/CD pipelines (SAST, DAST, SCA, secret scanning, IaC).
  • Support audits and ensure compliance with ISO 27001, SOC 2, and GDPR.
  • Assess API and cloud security postures and enable secure coding practices.

Skills

OWASP Top 10
API Security Top 10
OAuth2
OpenID Connect
JWT
Cryptography fundamentals
Secure Session Management
XSS
CSRF
SSRF
XXE
Deserialization attacks
RCE
Privilege Escalation

Education

Bachelor's degree in Computer Science, Information Security, or related field

Tools

Burp Suite Professional
OWASP ZAP
Postman
Nmap
Nessus
Nikto
SQLMap
MobSF
SonarQube
Checkmarx
Veracode

Job description

Penetration Testing
  • Execute black-box, grey-box and white-box penetration tests.
  • Assess exploitability and business impact.

Validate security of cloud-hosted environments including:

  • Identity & Access Management
  • Secrets Management
  • Storage Security
  • Network Security Groups
  • Container security
  • Serverless functions
  • Cloud misconfiguration assessments
Secure SDLC

Partner with engineering teams to:

  • Review security requirements
  • Review threat models
  • Verify secure coding practices
  • Validate security fixes
DevSecOps

Integrate security testing into CI/CD pipelines by managing and optimizing:

  • SAST
  • DAST
  • SCA (Software Composition Analysis)
  • Secret scanning
  • IaC scanning
Vulnerability Management
  • Verify vulnerabilities reported by scanners.
  • Eliminate false positives.
  • Prioritize findings using CVSS.
  • Track remediation.
  • Conduct regression testing.
AI & LLM Security Testing (Preferred)

Assess AI-enabled features for:

  • Jailbreak attempts
  • Data leakage
Compliance Support

Support security initiatives related to:

  • ISO 27001
  • SOC 2
  • GDPR

Provide evidence during internal and external audits.

Automation

Develop security automation scripts for:

  • Vulnerability validation
  • Security regression
  • Security reporting
Required Skills
Security

Strong understanding of

  • OWASP Top 10
  • API Security Top 10
  • OAuth2
  • OpenID Connect
  • JWT
  • Cryptography fundamentals
  • Secure Session Management
  • XSS
  • CSRF
  • SSRF
  • XXE
  • Deserialization attacks
  • RCE
  • Privilege Escalation
Tools

Hands-on experience with tools such as

  • Burp Suite Professional
  • OWASP ZAP
  • Postman
  • Nmap
  • Nessus
  • Nikto
  • SQLMap
  • MobSF
  • SonarQube
  • Checkmarx
  • Veracode
Programming

Working knowledge of at least one language

  • Python
  • Java
  • C#

Ability to read application code to understand vulnerabilities.

Nice to Have

Experience with

  • Docker
  • Terraform
  • GitHub Advanced Security
  • CodeQL
  • AI-assisted security testing
  • LLM security
  • Bug bounty participation
  • Capture The Flag (CTF)
Qualifications
  • Bachelor\'s degree in Computer Science, Information Security, or related field.
  • 4–8 years of experience in application security or security testing.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

CyberSecurity
CyberSecurity

Cloudxtreme • Hyderabad, Bengaluru

On-site
INR 170,000 - 210,000
Cybersecruity-Pentesting
Cybersecruity-Pentesting

CloudXtreme • Bengaluru

On-site
INR 1,400,000 - 2,100,000
Cyber Penetration Tester
Cyber Penetration Tester

Alignity Solutions • Hyderabad

On-site
INR 1,000,000 - 1,500,000
Staff Engineer - Application Security
Staff Engineer - Application Security

UST • Bengaluru

On-site
INR 2,400,000 - 4,200,000
Senior/Lead Security Engineer - AI
Senior/Lead Security Engineer - AI

EPAM Systems Inc • India

On-site
INR 3,000,000 - 4,500,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Nextwebi • Bengaluru

On-site
INR 1,500,000 - 3,000,000
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
Penetration Tester
Penetration Tester

Michael Page • Hyderabad

On-site
INR 2,500,000 - 5,500,000
Security Tester
Security Tester

Paramount Computer Systems LLC • Coimbatore District

On-site
INR 900,000 - 1,300,000
Senior Penetration Tester
Senior Penetration Tester

Target Corporation India Pvt Ltd • Bengaluru

On-site
INR 2,500,000 - 4,000,000