Senior Security Engineer

Delta6Labs FinTech Pvt Ltd

Dadri

On-site

INR 1,500,000 - 2,500,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Delta6Labs FinTech Pvt Ltd is seeking an experienced Security Engineer skilled in offensive security. You will conduct penetration tests on web, mobile, APIs, and networks, ensuring the integrity of fintech and crypto platforms.

The ideal candidate will have over 7 years of experience, especially with vulnerabilities in fintech applications. Important certifications like OSCP are required. Join us to enhance security measures while working on cutting-edge technologies.

Qualifications

  • More than 7 years of experience in Vulnerability Assessment, Penetration Testing, and Red Team operations.
  • More than 5 years of experience in Web, API, Mobile, and Network testing.
  • Experience testing Fintech, Crypto Exchange, Blockchain, or Trading applications.

Responsibilities

  • Conduct full-cycle Penetration Testing on fintech and crypto services.
  • Perform mobile application testing on Android and iOS.
  • Execute Network Penetration Testing across various environments.
  • Simulate real-world attack scenarios in Red Team exercises.

Skills

Web VAPT tools (OWASP Top 10, Burp Suite, ZAP)
Mobile VAPT techniques (Frida, Objection, MobSF)
API testing (Postman, Burp Suite)
Scripting (Python, Bash, PowerShell)
Secure coding techniques
Authentication mechanisms (OAuth, JWT, SAML)
Cryptography and MITRE ATT&CK framework

Education

OSCP (Offensive Security Certified Professional)

Job description

We are looking for an experienced & skilled Security Engineer with advanced offensive security skills to join our Information Security group. You will conduct complete penetration testing, vulnerability scans/assessments, and advanced Red Team assessments for web applications, mobile applications (iOS and Android), APIs, networks, and cloud infrastructure.

You will assist in identifying and mitigating high-impact vulnerabilities and simulate real-world adversarial attacks against our fintech and crypto platforms, where we store digital assets, provide trading systems, offer wallets, and create or support payment systems.

Key Responsibilities
  • Conduct full-cycle Web Application Penetration Testing (manual + automated) on highly complex fintech and crypto services.
  • Performing Mobile Application Penetration Testing on Android and iOS apps, including a thorough examination of rooted/jailbroken devices.
  • Perform API Penetration Testing (REST, GraphQL, WebSocket) — Authentication bypass, business logic bug, and rate-limiting vulnerabilities
  • You execute Network Penetration Testing (Internal & External), encompassing infrastructure, servers, and AWS cloud environments.
  • Conduct Red Team exercises, simulating APTs and real-world attack scenarios against the organization’s critical systems.
  • Conduct tracing, hunting, and incident response to Red Team operations and activities across the organization from Reconnaissance through Initial Access, Lateral Movement, persistence, and Exfiltration.
  • Target and use fintech & Crypto Exchange related vulnerabilities, including but not limited to: Wallet security issues, Trading engine bugs, Bypasses in the payment gateway, manipulating KYC/AML reports, Session hijacking & Blockchain integration weaknesses.
  • Shift your focus from checklist-based testing to finding complex business logic, zero-day, and architectural defects.
  • Conduct new features and release source code reviews, threat modeling, and secure design assessment.
  • Auditing security posture, Secret scanning, Branch protection, and Repository Security Controls
  • Custom Scripts (Python, Bash, PowerShell): Automate Repetitive VAPT & Red Team Tasks
  • Work with development, DevOps, and product teams to confirm fixes and re-testing.
  • Support secure SDLC activities like security requirements definition, code reviews, and cyber risk assessments.
  • Stay updated with the latest attack vectors, tools, and techniques across fintech, crypto & Red Teaming.
Experience
  • More than 7 years of experience performing Vulnerability Assessment, Penetration Testing, and Red Team operations.
  • More than 5 years of experience completing Web, API, Mobile, Network, Cloud, and Red Team activities.
  • Required experience testing Fintech, Crypto Exchange, Blockchain, or Trading applications.
  • Demonstrated experience in organizing and executing successful Red Team operations.
Mandatory Certification
  • OSCP (Offensive Security Certified Professional) – Must have.
Technical Skills
  • Experience of Web VAPT: Deep knowledge on OWASP Top 10, Burp Suite, ZAP, SQLMap & related Tools
  • Mobile VAPT: In-depth partnering for Android (Root) and iOS (Jailbreak) Test with Frida, Objection, MobSF, Drozer, Appium, etc.
  • API VAPT: Expertise at Postman, Burp Suite & custom API testing scripts.
  • Expert level of scripting knowledge: Python (preferred), bash, PowerShell
  • Strong understanding of secure coding techniques, authentication mechanisms (OAuth, JWT, SAML), cryptography, and MITRE ATT&CK framework.
Preferred Qualifications
  • The ideal candidate should also hold additional certifications, including OSWE, OSEP, CRTP, CRTE, CEH, or eJPT.
  • The candidate should have previous experience performing cloud penetration testing, red teaming (AWS, GCP), blockchains, reviewing blockchains, and auditing smart contracts.
  • The candidate should also have a familiarity with compliance frameworks such as NIST CSF, NIST SP 800-53, NIST SP 800-171, SOC 2, ISO 27001, etc.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Consultant
Application Security Consultant

Securityboat • Mumbai

On-site
INR 1,200,000 - 2,000,000
Flexible engagements
Competitive compensation
Collaborative cybersecurity team
+1
Security Engineer
Security Engineer

Recro • Bengaluru

On-site
INR 1,800,000 - 2,600,000
Red Team Specialist – I
Red Team Specialist – I

ESP Engineered • Mumbai

On-site
INR 2,000,000 - 4,500,000
Software Engineer
Software Engineer

Cloudxtreme • Bengaluru, Hyderabad

Hybrid
INR 900,000 - 1,500,000
Ethical Hacker / Application Security Expert - Red Team
Ethical Hacker / Application Security Expert - Red Team

Win Global PR • Bengaluru

On-site
INR 350,000 - 700,000
Application Security Engineer - Red Team
Application Security Engineer - Red Team

Air India • Gurugram District

On-site
INR 2,500,000 - 4,000,000
Hiring For Penetration Tester - Mumbai
Hiring For Penetration Tester - Mumbai

Saint Gobain • Mumbai, Navi Mumbai

On-site
INR 4,000,000 - 8,000,000
Appsec Specialist - Lead
Appsec Specialist - Lead

Adani Group • Ahmedabad District

On-site
INR 2,800,000 - 4,200,000
Red Team Specialist – I
Red Team Specialist – I

TalaKunchi Networks Pvt Ltd • Mumbai

On-site
INR 800,000 - 1,200,000
Opportunity to work on cutting-edge projects
Collaborative environment with continuous learning
Exposure to advanced security engagements
Senior Security Consultant
Senior Security Consultant

Payatu Technologies Pvt Ltd • Pune District

On-site
INR 1,800,000 - 3,200,000