Senior Application Security Engineer / Cybersecurity Consultant

Stellar Innovations

Bengaluru

On-site

INR 2,500,000 - 4,200,000

Full time

5 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Stellar Innovations in Bengaluru seeks a senior security consultant to perform end-to-end security assessments of web applications and conduct penetration testing.

You will review architecture, authentication and authorization, session management and data protection, delivering remediation guidance with evidence for production readiness.

Ideal candidates have 5+ years in cybersecurity and 3+ years in web app security, with fintech experience preferred.

Qualifications

  • 5+ years of cybersecurity experience
  • Minimum 3+ years specifically in web application security and penetration testing
  • Experience working with financial services, mortgage, lending, fintech, or similar applications is preferred

Responsibilities

  • Perform end-to-end security assessment of web applications before production launch
  • Review application architecture from a cybersecurity perspective
  • Conduct web application penetration testing
  • Review authentication, authorization, user roles, session management, and password-security controls
  • Identify vulnerabilities based on OWASP Top 10, OWASP WSTG, and related application-security standards
  • Perform secure code reviews and identify coding-related security vulnerabilities
  • Review database security, access controls, credentials, encryption, and SQL-related vulnerabilities
  • Review web server, cloud/server configuration, TLS/SSL, firewall, security headers, and production configuration
  • Review third-party integrations and APIs from a security perspective, where applicable
  • Perform vulnerability scanning and automated security testing
  • Review third-party libraries and application dependencies for known vulnerabilities
  • Evaluate file uploads, input validation, error handling, logging, audit trails, and sensitive-data handling
  • Identify business-logic vulnerabilities and privilege-escalation risks
  • Provide detailed remediation recommendations to the development team
  • Retest the application after fixes are implemented
  • Provide a final security assessment / residual-risk report before production launch

Skills

Web application security
OWASP Top 10
OWASP WSTG
OWASP ASVS
Penetration testing
Secure code review
Authentication testing
Authorization testing
SQL injection
XSS testing
CSRF/SSRF/Session management
SAST/DAST/SCA
Vulnerability assessment
Burp Suite
OWASP ZAP
Cloud security
TLS/SSL security
Secrets management
Security logging and monitoring
Secure SDLC

Tools

Burp Suite
OWASP ZAP

Job description

Role & responsibilities
  • Perform end-to-end security assessment of web applications before production launch
  • Review application architecture from a cybersecurity perspective
  • Conduct web application penetration testing
  • Review authentication, authorization, user roles, session management, and password-security controls
  • Identify vulnerabilities based on OWASP Top 10, OWASP WSTG, and related application-security standards
  • Perform secure code reviews and identify coding-related security vulnerabilities
  • Review database security, access controls, credentials, encryption, and SQL-related vulnerabilities
  • Review web server, cloud/server configuration, TLS/SSL, firewall, security headers, and production configuration
  • Review third-party integrations and APIs from a security perspective, where applicable
  • Perform vulnerability scanning and automated security testing
  • Review third-party libraries and application dependencies for known vulnerabilities
  • Evaluate file uploads, input validation, error handling, logging, audit trails, and sensitive-data handling
  • Identify business-logic vulnerabilities and privilege-escalation risks
  • Provide detailed remediation recommendations to the development team
  • Retest the application after fixes are implemented
  • Provide a final security assessment / residual-risk report before production launch
Preferred candidate profile
  • 5+ years of overall cybersecurity experience
  • Minimum 3+ years specifically in web application security and penetration testing
  • Experience working with financial services, mortgage, lending, fintech, or similar applications is preferred
Required Technical Skills:
  • Strong Web Application Security knowledge
  • OWASP Top 10
  • OWASP Web Security Testing Guide (WSTG)
  • OWASP Application Security Verification Standard (ASVS)
  • Web Application Penetration Testing
  • Secure Code Review
  • Authentication and Authorization Testing
  • SQL Injection and Database Security
  • Cross-Site Scripting (XSS)
  • CSRF, SSRF, Session Management, and Access Control Testing
  • SAST, DAST, and Software Composition Analysis (SCA)
  • Vulnerability Assessment
  • Burp Suite / OWASP ZAP or equivalent security-testing tools
  • Server and Infrastructure Security
  • Cloud Security knowledge
  • TLS/SSL and security-header configuration
  • Secrets and credential management
  • Security Logging and Monitoring
  • Secure Software Development Lifecycle (Secure SDLC)
Preferred Certifications:

Certifications are preferred but hands-on application-security experience is more important.

Relevant certifications may include:

  • OSCP
  • OSWE
  • GIAC GWAPT / GWEB
  • CISSP
  • CEH or equivalent security certifications
Expected Deliverables:
  1. Application Security Assessment Report
  2. Penetration Testing Report
  3. List of vulnerabilities categorized as Critical / High / Medium / Low
  4. Evidence and affected areas for each vulnerability
  5. Recommended remediation for each issue
  6. Security configuration recommendations
  7. Retesting of identified vulnerabilities after remediation
  8. Final pre-production security assessment / residual-risk report
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Analyst
Application Security Analyst

ZS • Maharashtra

On-site
INR 600,000 - 1,200,000
Application Security Engineer
Application Security Engineer

Whitefield Careers • Bengaluru

On-site
INR 800,000 - 1,200,000
Application Security Engineer
Application Security Engineer

Ola • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Principle Engineer - Application Security
Principle Engineer - Application Security

UST • Bengaluru

On-site
INR 2,500,000 - 4,800,000
Application Security Consultant
Application Security Consultant

Securityboat • Mumbai

On-site
INR 1,200,000 - 2,000,000
Flexible engagements
Competitive compensation
Collaborative cybersecurity team
+1
Software Engineer
Software Engineer

Cloudxtreme • Bengaluru, Hyderabad

On-site
INR 900,000 - 1,500,000
System Security
System Security

BigShip Technologies Pvt. Ltd • Dadri

On-site
INR 1,000,000 - 1,500,000
Application Security Analyst
Application Security Analyst

Zs Associates • Mumbai

On-site
INR 900,000 - 1,500,000
Cyber Security Specialist
Cyber Security Specialist

SuperOps • Chennai District

On-site
INR 800,000 - 1,200,000
Application Security Testing Consultant with SAST and DAST
Application Security Testing Consultant with SAST and DAST

Cloudxtreme • Hyderabad, Pune District, Bengaluru

On-site
INR 1,200,000 - 1,800,000