Security Tester

Disprz

Chennai District

On-site

INR 1,800,000 - 3,600,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Disprz is seeking a security-focused professional to lead penetration testing, secure SDLC, and DevSecOps initiatives across cloud and on‑prem environments. You will assess exploitability, validate fixes, and drive risk‑based remediation with engineering teams.

Responsibility includes automating security tests in CI/CD, supporting ISO 27001, SOC 2 and GDPR audits, and mentoring developers on secure coding. Proficiency with Burp Suite, ZAP, Nmap, Nessus and related tools is essential.

Qualifications

  • Bachelor's degree in Computer Science, Information Security, or related field.
  • 4–8 years of experience in application security or security testing.
  • Hands-on with security tools and programming languages.

Responsibilities

  • Execute penetration tests across black-box, grey-box, and white-box approaches.
  • Validate security fixes and verify vulnerability remediation.
  • Integrate security testing into CI/CD pipelines (SAST, DAST, SCA, secret scanning, IaC).
  • Support audits and ensure compliance with ISO 27001, SOC 2, and GDPR.
  • Assess API and cloud security postures and enable secure coding practices.

Skills

OWASP Top 10
API Security Top 10
OAuth2
OpenID Connect
JWT
Cryptography fundamentals
Secure Session Management
XSS
CSRF
SSRF
XXE
Deserialization attacks
RCE
Privilege Escalation

Education

Bachelor's degree in Computer Science, Information Security, or related field

Tools

Burp Suite Professional
OWASP ZAP
Postman
Nmap
Nessus
Nikto
SQLMap
MobSF
SonarQube
Checkmarx
Veracode

Job description

Penetration Testing
  • Execute black-box, grey-box and white-box penetration tests.
  • Assess exploitability and business impact.

Validate security of cloud-hosted environments including:

  • Identity & Access Management
  • Secrets Management
  • Storage Security
  • Network Security Groups
  • Container security
  • Serverless functions
  • Cloud misconfiguration assessments
Secure SDLC

Partner with engineering teams to:

  • Review security requirements
  • Review threat models
  • Verify secure coding practices
  • Validate security fixes
DevSecOps

Integrate security testing into CI/CD pipelines by managing and optimizing:

  • SAST
  • DAST
  • SCA (Software Composition Analysis)
  • Secret scanning
  • IaC scanning
Vulnerability Management
  • Verify vulnerabilities reported by scanners.
  • Eliminate false positives.
  • Prioritize findings using CVSS.
  • Track remediation.
  • Conduct regression testing.
AI & LLM Security Testing (Preferred)

Assess AI-enabled features for:

  • Jailbreak attempts
  • Data leakage
Compliance Support

Support security initiatives related to:

  • ISO 27001
  • SOC 2
  • GDPR

Provide evidence during internal and external audits.

Automation

Develop security automation scripts for:

  • Vulnerability validation
  • Security regression
  • Security reporting
Required Skills
Security

Strong understanding of

  • OWASP Top 10
  • API Security Top 10
  • OAuth2
  • OpenID Connect
  • JWT
  • Cryptography fundamentals
  • Secure Session Management
  • XSS
  • CSRF
  • SSRF
  • XXE
  • Deserialization attacks
  • RCE
  • Privilege Escalation
Tools

Hands-on experience with tools such as

  • Burp Suite Professional
  • OWASP ZAP
  • Postman
  • Nmap
  • Nessus
  • Nikto
  • SQLMap
  • MobSF
  • SonarQube
  • Checkmarx
  • Veracode
Programming

Working knowledge of at least one language

  • Python
  • Java
  • C#

Ability to read application code to understand vulnerabilities.

Nice to Have

Experience with

  • Docker
  • Terraform
  • GitHub Advanced Security
  • CodeQL
  • AI-assisted security testing
  • LLM security
  • Bug bounty participation
  • Capture The Flag (CTF)
Qualifications
  • Bachelor\'s degree in Computer Science, Information Security, or related field.
  • 4–8 years of experience in application security or security testing.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Testing Engineer
Application Security Testing Engineer

Infosys • Bengaluru

On-site
INR 900,000 - 1,200,000
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
Application Testing Engineer
Application Testing Engineer

Quess • Chennai District, Bengaluru, Pune District

Hybrid
INR 700,000 - 1,500,000
Security Tester
Security Tester

Paramount Computer Systems LLC • Coimbatore District

On-site
INR 900,000 - 1,300,000
Appsec Specialist - Lead
Appsec Specialist - Lead

Adani Group • Ahmedabad District

On-site
INR 2,800,000 - 4,200,000
Penetration Tester
Penetration Tester

Soffit Infrastructure Services (P) Ltd • Ernakulam

On-site
INR 1,200,000 - 2,200,000
Security Engineer
Security Engineer

Recro • Bengaluru

On-site
INR 1,800,000 - 2,600,000
Cyber Security Specialist
Cyber Security Specialist

SuperOps • Chennai District

On-site
INR 800,000 - 1,200,000
Application Security Engineer
Application Security Engineer

Cyberpwn • Bengaluru

On-site
INR 900,000 - 1,300,000
DevSecOps (Security test lead) Engineer
DevSecOps (Security test lead) Engineer

D-techworks • Mumbai, Bengaluru

On-site
INR 2,500,000 - 4,000,000