Senior Application Security Tester

Hdfc Bank

Navi Mumbai, Mumbai

On-site

INR 3,500,000 - 7,000,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

HDFC Bank in Navi Mumbai seeks a Senior Application Security Tester with 10+ years of deep, hands-on security testing experience across web, mobile, API, and microservices in fintech or banking environments. The candidate will mentor the team and lead complex assessments on mission-critical platforms.

Responsibilities include manual and automated testing, deep-dive analysis, PoC development, test automation framework creation, and reporting to stakeholders.

Qualifications

  • Over 10 years of deep, hands-on security testing experience in fintech or banking environments.
  • Expertise across web, mobile, API and microservices testing with PoC development.
  • Familiarity with OWASP Top 10, CWE Top 25, OWASP API Top 10, NIST, MASVS.

Responsibilities

  • Execute complex security assessments for web, API, mobile, and microservices.
  • Mentor juniors and lead the security testing team on critical projects.
  • Design and implement test strategies and automation frameworks.
  • Prepare detailed technical and executive reports for stakeholders.

Skills

Security testing
Manual & automated testing
Team leadership
Mentoring juniors
Cross-functional communication
Problem solving
Stakeholder management
Scripting (Python/JavaScript)
Vulnerability assessment

Education

Certifications: OSCP, OSWE, eWPTX, GWAPT, CISSP, CISM, CEH, CREST-CRT

Tools

Burp Suite Pro
OWASP ZAP
Mobile testing toolkit
API testing toolkit
SAST/DAST tools

Job description

Role & responsibilities

We are seeking a highly experienced Senior Application Security Tester with 10+ years of deep, handson experience in web application and mobile security testing within fintech or banking environments. The candidate mentor the team and will be responsible for executing complex security assessments, Web, API, mobile, microservices testing across mission critical financial platforms.

Perform manual and automated security testing (black box, grey box, and fuzz testing) across critical web, mobile (iOS/Android), API, and microservices architectures. Conduct deep-dive reviews static/dynamic/runtime analysis, and workflow checks to uncover logic flaws, cryptography weaknesses, RASP/SSL bypass issues, and authorization failures. Perform indepth testing of financial transaction workflows, payment gateways, and critical API endpoints. Identify, validate, and exploit vulnerabilities (including multi-stage exploit chains and privilege escalation) to build impactful Proof-of-Concepts (PoCs). The testing approach should include identifying and validating multi stage exploit chains, where multiple weaknesses can be combined to demonstrate realistic attack paths. Design and implement comprehensive test strategies for web, APIs, mobile and microservices. Review applications and create customised attack models and plans. Mentor juniors on testing scenarios, best testing practices and technical skills. Build, scale, and maintain robust test automation frameworks from scratch. Hands-on expertise in application security testing tools like Burp Suite Pro, OWASP ZAP, mobile testing toolkit, API testing toolkit, SAST/DAST tools. Knowledge of OWASP Top 10, CWE Top 25, OWASP API Top 10, NIST, MASVS, MASTG. Experience with scripting (Python/JavaScript) for automation or testing enhancement. Ability to map vulnerabilities to risk severity and remediation guidelines. Prepare detailed technical and executive reports for stakeholders. Strong leadership, cross-functional communication, and complex problem-solving abilities.

Mandatory Certifications any one from list OSCP, OSWE, eWPTX, GWAPT, CISSP, CISM, CEH, CREST-CRT.

Soft Skills Excellent written and verbal communication and documentation skills. Strong analytical and complex problemsolving abilities. Ability to multitask and manage multiple critical assessments in parallel.

Stakeholder management across engineering, product, and risk functions.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Tester (Web, Mobile & API) – BFSI Domain
Application Security Tester (Web, Mobile & API) – BFSI Domain

ESP Engineered • Mumbai

On-site
INR 700,000 - 900,000
Application Security
Application Security

Airtel • India

On-site
INR 1,200,000 - 2,400,000
Security-focused culture
Senior Security Engineer
Senior Security Engineer

Delta6Labs FinTech Pvt Ltd • Dadri

On-site
INR 1,500,000 - 2,500,000
Application Security Consultant
Application Security Consultant

Securityboat • Mumbai

On-site
INR 1,200,000 - 2,000,000
Flexible engagements
Competitive compensation
Collaborative cybersecurity team
+1
Software Engineer
Software Engineer

Cloudxtreme • Bengaluru, Hyderabad

Hybrid
INR 900,000 - 1,500,000
Senior Security Testing Engineer
Senior Security Testing Engineer

Allied Boston Consultants India • Dadri

On-site
INR 900,000 - 1,300,000
Application Security Engineer
Application Security Engineer

Cyberpwn • Bengaluru

On-site
INR 900,000 - 1,300,000
Application Security Professional
Application Security Professional

Sisa Information Security • Bengaluru

On-site
INR 900,000 - 1,500,000
Application Penetration Tester
Application Penetration Tester

ControlCase, LLC • Mumbai

On-site
INR 800,000 - 2,000,000
Senior Security Specialist
Senior Security Specialist

Lennox • Chennai District

On-site
INR 3,000,000 - 4,200,000