Senior Application Security Specialist

[24]7.ai

Bengaluru

On-site

INR 1,500,000 - 2,500,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A leading technology company seeks a Senior Security Specialist to lead security assessments across various products and infrastructure. The role involves evaluating vulnerabilities, ensuring compliance with security standards, and mentoring teams while participating actively in enhancing the organization's security posture. Candidates should have significant experience in vulnerability assessment and penetration testing, along with relevant degrees and certifications.

Qualifications

  • Minimum experience: 08-10 years in Vulnerability Assessment and Penetration Testing.
  • Strong command of OWASP Top 10 with practical knowledge of attack vectors and mitigation strategies.
  • Hands-on experience with various security tools and familiarity with industry standards.

Responsibilities

  • Plan, conduct, and close end-to-end Vulnerability Assessments and Penetration Tests.
  • Perform both manual and automated security assessments to identify vulnerabilities.
  • Guide development teams on Secure Coding standards and OWASP-aligned practices.

Skills

Vulnerability Assessment
Penetration Testing
OWASP Top 10
Threat Modeling
Secure Coding
Static and Dynamic Application Security Testing
Cloud Security
Scripting (Shell, Python, Ruby)

Education

Bachelor’s/Master’s degree in Computer/Information Science, Software Engineering, Cybersecurity

Tools

Burp Suite
OWASP ZAP
Acunetix
Nessus
Metasploit
Fortify

Job description

Direct message the job poster from [24]7.ai

Role: Senior Security Specialist

Final Round Interview : F2F

Summary of essential job functions

The overall responsibility of the team is to provide assurance to the management on the Information Security, Compliance and Risk Management of the organization globally. The candidate would be expected to lead security assessments of Products and Infrastructure globally.

Education, Certification and Experience:

  • Qualification Required: Bachelor/Master’s degree in Computer/ Information science, Software

Engineering, Cybersecurity, or a related field

  • Certification preferred: OSCP, OSWE, OSEP, ECSA|LPT, CPT, CEH
  • Minimum experience: 08-10 years in Vulnerability Assessment and Penetration Testing- Thin & Thick Client, API , Infrastructure, Cloud, Mobile

Competency Requirements:

Performs a combination of duties in accordance with departmental guidelines:

  • Hands-on experience in Vulnerability Assessment (VA) and Penetration Testing (PT) for Web, APIs, AI/ML models, Mobile , Network, and Infrastructure.
  • Strong command of OWASP Top 10 with practical knowledge of attack vectors and mitigation

strategies.

  • Familiarity with industry standards and frameworks such as OSSTMM, OQASP, CESG, CREST,

NIST, ISSAF, and PTES.

  • Expertise in Secure Development Lifecycle (SDLC), including Threat Modeling, Secure Coding

Practices, and Security Assessments.

  • Proficient in both Static and Dynamic Application Security Testing (SAST, DAST, IAST), and

Software Composition Analysis (SCA).

  • Experience conducting secure code reviews and identifying logic flaws in code bases written in Java, .NET, C/C++, Python, etc.
  • Knowledge of cryptographic protocols, secure communication, data security and key management.
  • Hands-on with commercial and open-source tools: Burp Suite, OWASP ZAP, Acunetix, AppSpider,SQLMap, Nmap, Metasploit, Nessus, OpenVAS, Fortify, Checkmarx, Veracode, SonarQube, NexusIQ and Snyk.
  • Proficient in assessing mobile applications (thick/hybrid clients) using tools like Dex2jar, ADB, Frida.
  • Exposure to AuthN/AuthZ protocols such as OAuth, SAML, OIDC; ability to read, write, and interpret application logic.
  • Familiarity with vulnerability standards: CVSS, CVE, CWE, CAPEC; and patch management lifecycle.
  • Experience automating tasks via shell scripting and Python/Ruby/Php etc.
  • Proficiency in secure code development and reviewing DAST/SAST reports across languages.
  • Understanding security aspects in AWS, Azure, and GCP including IAM, VPC/VNet, S3/Blob storage, API gateway, Load Balancers, WAF, Containers (Docker), and Kubernetes.
  • Experience in infrastructure/network penetration testing and exploitation techniques on Windows/Linux environments.
  • Experience in mentoring, leading teams, and managing security assessments under tight deadlines.
  • Manage third-party security assessments, including vendor risk evaluations, engagement oversight, and ensuring compliance with organizational security standards.
  • Proven ability to provide technical oversight and drive engagement quality across security projects.
  • Exposure to agile/scrum development methodologies and ability to work with cross-functional teams.
  • Familiarity with security standards like PCI DSS, SOC, ISO 27001.
  • Participation in bug bounty program and CTFs is a strong plus.
  • Proactive learning approach, staying updated with evolving cybersecurity trends and technologies.

Job Responsibilities:

  • Plan, conduct, and close end-to-end Vulnerability Assessments and Penetration Tests for Web Applications, APIs, Mobile Apps, Thick Clients, Infrastructure, and Cloud environments.
  • Perform both manual and automated security assessments to identify, validate, and prioritize vulnerabilities.
  • Review application code in various programming languages and provide actionable remediation recommendations.
  • Reproduce reported vulnerabilities with proof-of-concept (PoC) and assess associated risks.
  • Evaluate new security tools and products for adoption and integration.
  • Guide development teams on Secure Coding standards and OWASP-aligned practices.
  • Lead and contribute to secure SDLC processes, threat modeling workshops, and risk reviews.
  • Manage and triage security bugs from Bug Bounty programs, working closely with engineering teams to ensure timely resolution.
  • Maintain and improve the security posture of applications across business units, aligning with best practices.
  • Act as a security advisor on project teams, influencing architecture and design decisions.
  • Drive security awareness initiatives and conduct training sessions for developers and QA teams.
  • Update and maintain InfoSec policies and procedures in line with emerging threats, technologies, and compliance requirements; provide support to both internal and external auditors during security assessments and audits.

Other Requirements:

  • Strong ethics and understanding of ethics in business and information security.
  • Proficiency in English (both written and oral communication skills).
  • Ability to complete tasks and deliver professionally written reports for clients.
  • Ability to present findings to technical staff and executives.
  • Ability to interact with 247 internal stakeholders to review their requirements.
  • Should be able to think “out of the box” and implement new attack vectors.
  • Self-motivated, curious, knowledgeable pertaining to news and current events
Seniority level
  • Seniority level
    Associate
Employment type
  • Employment type
    Full-time
Job function
  • Job function
    Information Technology
  • Industries
    Computer and Network Security

Referrals increase your chances of interviewing at [24]7.ai by 2x

Get notified about new Senior Application Security Specialist jobs in Bengaluru, Karnataka, India.

We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Specialist
Senior Security Specialist

techvantage.ai • Thiruvananthapuram

On-site
INR 1,500,000 - 2,500,000
High visibility in a growing function
Opportunity to work with innovative technology
Competitive compensation
Staff Security Engineer
Staff Security Engineer

Ethos • Bengaluru

On-site
INR 1,500,000 - 2,500,000
Senior Security Analyst (Offensive)
Senior Security Analyst (Offensive)

CloudSEK • Bengaluru

On-site
INR 600,000 - 1,000,000
Unlimited snacks and drinks
Cyber Security Architect
Cyber Security Architect

VARITE INC • Bengaluru

On-site
INR 1,500,000 - 2,500,000
Candidate Referral Bonus
SENIOR SOFTWARE ENGINEER - Application Security
SENIOR SOFTWARE ENGINEER - Application Security

Happiest Minds Technologies • Bengaluru

On-site
INR 1,700,000 - 2,100,000
Senior Network Security Engineer
Senior Network Security Engineer

Objectways • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Application Security Specialist Lead
Application Security Specialist Lead

Adani Enterprises Ltd • Ahmedabad District

On-site
INR 1,400,000 - 2,200,000
AWS Cloud Security Engineer
AWS Cloud Security Engineer

Globex Digital • India

On-site
INR 800,000 - 1,200,000
Application Security Engineer
Application Security Engineer

Humantech Solutions India • Bengaluru

On-site
INR 1,600,000 - 2,300,000
Security Consultant (Secure Code Review Practice)
Security Consultant (Secure Code Review Practice)

NetSPI • Pune City

On-site
INR 800,000 - 1,200,000