SENIOR ENGINEER - Penetration Testing

Happiest Minds Technologies

Bengaluru

On-site

INR 1,100,000 - 1,700,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Happiest Minds Technologies in Bengaluru is seeking a Security Engineer focused on Application Security with 3–5 years of relevant experience. You will perform web application penetration testing, DAST/SAST tooling, and vulnerability management for infrastructure.

The role requires collaboration with engineering, DevOps, and IT teams to enhance security posture. The candidate should be hands-on with identifying issues, validating vulnerabilities, and guiding remediation within CI/CD workflows,

Qualifications

  • 3-5 years of experience in Application Security.
  • Strong understanding of web application security and common vulnerabilities.
  • Hands-on experience with manual web penetration testing.
  • Practical experience with DAST and SAST tools.
  • Working knowledge of Vulnerability Management for infrastructure.
  • Familiarity with OWASP Top 10 and secure SDLC.
  • Ability to clearly communicate technical issues to developers.
  • Bachelor's degree in Computer Science or Information Security is required.

Responsibilities

  • Perform security reviews of web applications, APIs and related services.
  • Conduct manual and automated web application penetration testing.
  • Configure, run and tune DAST tools and workflows.
  • Support SAST integration into CI/CD and help developers interpret findings.
  • Collaborate with engineering to validate vulnerabilities and track remediation.
  • Review authentication, authorization, session management and input validation.
  • Help improve secure coding and application security practices.

Skills

Web application penetration testing
Vulnerability management
OWASP Top 10
DevSecOps

Education

Bachelor's degree in Computer Science/Information Security

Tools

Burp Suite
ZAP
Checkmarx
Veracode
SonarQube
Tenable
Qualys
Rapid7

Job description

Job Code

14845

Mandatory Skills

Web Application Penetration Testing,Vulnerability Management

Experience

3 to 5 Years

Location

Bengaluru

Job Description

We are looking to hire a Security Engineer with 3 - 5 years of relevant experience. The primary focus of this role will be Application Security, including Web Penetration Testing, DAST, and SAST. The secondary focus will be Vulnerability Management for infrastructure assets.

The ideal candidate should have strong hands‑on experience in identifying, validating, and helping remediate security issues in web applications and supporting infrastructure. The role requires close collaboration with engineering, DevOps, and infrastructure teams to improve the security posture of the product and environment.

Education Qualificaiton

Bachelor's degree

Open Positions

1

Job Title

Senior Security Engineer ? Application Security

Roles & Responsibilities
Application Security
  • Perform security reviews of web applications, APIs, and related services.
  • Conduct manual and automated web application penetration testing.
  • Configure, run, and tune DAST tools and workflows.
  • Support SAST integration into CI/CD pipelines and help developers interpret findings.
  • Work with engineering teams to validate vulnerabilities, reduce false positives, and track remediation.
  • Review application architecture, authentication, authorization, session management, input validation, and common OWASP issues.
  • Help define and improve secure coding and application security practices.
Vulnerability Management
  • Support vulnerability management for infrastructure assets, including servers, endpoints, containers, and cloud workloads.
  • Triage, prioritize, and track remediation of infrastructure vulnerabilities based on risk and business impact.
  • Work with platform, DevOps, and IT teams to close findings within agreed SLAs.
  • Analyze vulnerability trends and report metrics to stakeholders.
  • Assist in improving vulnerability scanning coverage, alert quality, and remediation workflows.
Cross-Functional Security Work
  • Partner closely with product engineering, DevOps, and operations teams to build security into delivery pipelines.
  • Support security exceptions/risk acceptance processes where necessary.
  • Contribute to security standards, playbooks, and internal documentation.
  • Help improve the overall security posture of the project/product area.
What We Are Looking For
  • 3 - 5 years of experience in Application Security, Product Security, or a closely related role.
  • Strong understanding of web application security and common vulnerabilities.
  • Hands‑on experience with manual web penetration testing.
  • Practical experience with DAST and SAST tools and workflows.
  • Working knowledge of Vulnerability Management for infrastructure.
  • Familiarity with OWASP Top 10, secure SDLC, and remediation guidance.
  • Ability to clearly communicate technical issues to developers and non-security stakeholders.
  • Comfortable working in a fast‑moving engineering environment.
Good to Have
  • Experience with APIs, cloud security, or container security.
  • Exposure to CI/CD pipelines and DevSecOps practices.
  • Familiarity with tools such as Burp Suite, ZAP, Checkmarx, Veracode, SonarQube, Tenable, Qualys, Rapid7, or similar.
  • Knowledge of scripting or automation using Python, Bash, or similar.
  • Experience with Jira, ServiceNow, or similar tracking systems.
Qualifications
  • Bachelor?s degree in Computer Science, Information Security, or equivalent practical experience.
  • Relevant security certifications are a plus, but not mandatory.
Success in This Role Looks Like
  • Security findings are identified early and remediated effectively.
  • Vulnerability backlog is well‑triaged and aging is reduced.
  • Development teams receive actionable, high‑quality security guidance.
  • Security checks are integrated into the delivery process without slowing teams down unnecessarily.
Type of Employment

Contract

Project Details

Vulnerability Management Operations Project holds responsibility of managing the complete vulnerability management program which aims in securing Applications and Infrastructures.

Project Duration

NA

Shift Timings

14:00 to 23:00 IST

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SENIOR SOFTWARE ENGINEER - Application Security
SENIOR SOFTWARE ENGINEER - Application Security

Happiest Minds Technologies • Bengaluru

On-site
INR 1,700,000 - 2,100,000
Application Security Engineer
Application Security Engineer

Byline Learning Solutions • Pune District

On-site
INR 1,200,000 - 1,800,000
Security Engineer
Security Engineer

Amantya Technologies • India

On-site
INR 1,200,000 - 1,800,000
Senior Security Consultant (Web Application Penetration Tester)
Senior Security Consultant (Web Application Penetration Tester)

NetSPI Inc. • Pune District

On-site
INR 1,400,000 - 2,000,000
Penetration Testing Engineer / Application Security Testing Engineer
Penetration Testing Engineer / Application Security Testing Engineer

VMC Soft Technologies, Inc • Bengaluru Urban

On-site
INR 1,800,000 - 3,600,000
Application Security Engineer
Application Security Engineer

Basebiz • Pune District

On-site
INR 1,800,000 - 3,000,000
Penetration Testing Engineer / Application Security Testing Engineer
Penetration Testing Engineer / Application Security Testing Engineer

VMC Soft Technologies, Inc • Dadri

On-site
INR 2,500,000 - 4,200,000
Application Security Engineer (6 Months Contract)
Application Security Engineer (6 Months Contract)

Weekday AI (YC W21) • Hyderabad

On-site
INR 1,500,000 - 2,000,000
Application Security Engineer
Application Security Engineer

Tata Consultancy Services • New Delhi, Dadri

On-site
INR 2,000,000 - 3,500,000
Penetration Tester
Penetration Tester

VikingCloud • India

On-site
INR 700,000 - 900,000