Senior Application Security Tester

Commvault

Bengaluru

On-site

INR 1,200,000 - 1,800,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Annual health check-ups
Tuition Reimbursement
Inclusive culture
Personal accident cover and Term life

Job summary

Commvault invites a Senior Application Security Tester to join our security team. You’ll conduct comprehensive testing on on‑premises and cloud applications, using automated and manual methods to identify vulnerabilities and guide remediation across AWS, Azure, and GCP environments.

You will lead threat modeling, stay current on threats, and mentor junior testers while collaborating with DevOps, Engineering, and Cloud teams to strengthen our secure SDLC.

Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, IT or related field.
  • 5+ years of experience in application security testing or offensive security.
  • Deep understanding of OWASP Top 10, CWE/SANS Top 25, and secure SDLC.

Responsibilities

  • Perform detailed application security testing (DAST, SAST, IAST) on internal and customer-facing apps.
  • Lead threat modeling and security assessments across the SDLC for on-prem and cloud environments.
  • Use automated tools (Burp Suite, OWASP ZAP, Fortify, Veracode, Checkmarx, Snyk, etc.) to identify vulnerabilities.
  • Manually validate and prioritize issues identified by automated scans.
  • Collaborate with DevOps, Engineering, and Cloud teams; provide remediation guidance and verify fixes.

Skills

OWASP Top 10
Threat modeling
Python
Shell scripting
RESTful APIs
Cloud security

Education

Bachelor's degree in Computer Science, Cybersecurity, IT

Tools

Burp Suite
OWASP ZAP
Fortify
Veracode
Checkmarx
Snyk
AppSpider
Docker
Kubernetes
AWS
Azure
GCP

Job description

Senior Application Security Tester

We are seeking a highly skilled and experienced Senior Application Security Tester to join our security team. In this role, you will be responsible for conducting comprehensive security testing on both on-premises and cloud-based applications. You will evaluate the security posture of web, mobile, and API-based applications using automated tools and manual techniques, ensuring they are protected against the latest threats and vulnerabilities.

About Commvault

Commvault (NASDAQ: CVLT) is the gold standard in cyber resilience. The company empowers customers to uncover, take action, and rapidly recover from cyberattacks - keeping data safe and businesses resilient. The company’s unique AI-powered platform combines best-in-class data protection, exceptional data security, advanced data intelligence, and lightning-fast recovery across any workload or cloud at the lowest TCO. For over 25 years, more than 100,000 organizations and a vast partner ecosystem have relied on Commvault to reduce risks, improve governance, and do more with data.

What you'll do...
  • Perform detailed application security testing (DAST, SAST, IAST) on internal and customer-facing applications.
  • Lead threat modeling and security assessments across the SDLC for both on-premises and cloud-hosted environments.
  • Utilize automated security testing tools (e.g., Burp Suite, OWASP ZAP, Fortify, Veracode, Checkmarx, Snyk, etc.) to identify security vulnerabilities.
  • Manually validate and prioritize security issues identified by automated scans.
  • Collaborate with DevOps, Engineering, and Cloud teams
  • Provide remediation guidance to development teams and validate fixes.
  • Conduct code reviews and perform secure code analysis, as necessary.
  • Stay current on emerging threats, vulnerabilities, and industry trends in application security.
  • Document findings clearly and concisely for both technical and non-technical audiences.
  • Mentor junior security testers and contribute to overall security program improvements.
Who you are?
  • Bachelor's degree in computer science, Cybersecurity, Information Technology, or related field.
  • 5+ years of experience in application security testing or offensive security.
  • Deep understanding of OWASP Top 10, CWE/SANS Top 25, and other security best practices.
  • Hands-on experience with testing applications hosted in AWS, Azure, or GCP environments.
  • Familiarity with RESTful APIs, microservices architecture, and container security (Docker, Kubernetes).
  • Experience in testing GenAI solutions.
  • Strong command of scripting languages (e.g., Python, Bash, PowerShell) for custom testing and automation.
  • Experience with security testing tools such as:
  • Static analysis tools: Fortify, Checkmarx, Veracode
  • Dynamic analysis tools: Burp Suite Pro, OWASP ZAP, AppSpider
  • Software composition analysis (SCA): Snyk, Black Duck, White Source
  • Solid understanding of secure SDLC and DevSecOps principles.
Preferred Qualifications:
  • Relevant security certifications (e.g., OSCP, GWAPT, GPEN, CISSP, CSSLP).
  • Experience with Infrastructure-as-Code (IaC) scanning (e.g., Terraform, CloudFormation).
  • Working knowledge of compliance frameworks (e.g., PCI-DSS, HIPAA, NIST, ISO 27001).
You'll love working here because...
  • Continuous professional development, product training, and career pathing
  • Annual health check-ups, Tuition Reimbursement
  • An inclusive company culture, an opportunity to join our Community Guilds
  • Personal accident cover and Term life cover

Commvault is an equal opportunity workplace and is an affirmative action employer. We are always committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status and we will not discriminate against on the basis of such characteristics or any other status protected by the laws or regulations in the locations where we work.

Commvault’s goal is to make interviewing inclusive and accessible to all candidates and employees. If you have a disability or special need that requires accommodation to participate in the interview process or apply for a position at Commvault, please email accommodations@commvault.com For any inquiries not related to an accommodation please reach out to wwrecruitingteam@commvault.com.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Operations Engineer
Senior Security Operations Engineer

Commvault • Bengaluru

On-site
INR 1,000,000 - 1,500,000
Senior Software Security Architect
Senior Software Security Architect

Commvault • Bengaluru

On-site
INR 1,800,000 - 2,500,000
Continuous professional development
Inclusive company culture
Personal accident cover
+1
Senior Engineer-C++/C#
Senior Engineer-C++/C#

Commvault • Maharashtra

On-site
INR 1,000,000 - 1,800,000
ESPP
Professional development
Car lease program
+4
Resilience Operations Lead
Resilience Operations Lead

Commvault • Bengaluru

On-site
INR 400,000 - 700,000
Senior Engineer-C++/C#
Senior Engineer-C++/C#

Commvault • Mumbai

On-site
INR 1,400,000 - 2,000,000
ESPP
Professional development
Health check-ups
+5
Senior Sales Engineer
Senior Sales Engineer

Commvault • Mumbai

Remote
INR 3,500,000 - 6,000,000
Business Systems Analyst
Business Systems Analyst

Commvault • Bengaluru

On-site
INR 1,200,000 - 1,500,000
Continuous professional development
Personal accident cover
Inclusive culture
Associate Manager
Associate Manager

Commvault • Bengaluru

On-site
INR 2,000,000 - 3,600,000
Personal accident cover
Term life cover
Senior Engineer-C++ and SQL
Senior Engineer-C++ and SQL

Commvault • Maharashtra

On-site
INR 1,800,000 - 3,000,000
Employee stock purchase plan
Professional development
Health check-ups
+3
Senior Engineer-C++/C#
Senior Engineer-C++/C#

Commvault • Hyderabad, Pune District, Bengaluru

On-site
INR 1,500,000 - 3,000,000
Employee stock purchase plan (ESPP)
Continuous professional development,培训
Annual health check-ups
+5