Senior Security Specialist

Lennox India Technology Centre

Chennai District

On-site

INR 900,000 - 1,350,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Lennox India Technology Centre seeks a Senior Security Specialist (IC3) with 6-9 years of experience in Application Security & Penetration Testing to safeguard applications across the SDLC. You will lead DAST, API security testing, and MAST efforts while exploring AI-driven security testing.

You will collaborate with development, DevOps, architecture, and product teams to identify, assess, and remediate vulnerabilities, and you will produce both technical and executive reports to drive

Qualifications

  • 6-9 years of experience in Application Security & Penetration Testing (VAPT).
  • Expertise in DAST, API Security Testing, and Mobile Application Security Testing (MAST).
  • Hands-on exposure to AI-driven security testing and AI security risks.
  • Collaborate with development, DevOps, architecture, and product teams to remediate vulnerabilities across the SDLC.

Responsibilities

  • Perform end-to-end application security assessments for web, mobile, and API apps.
  • Conduct threat modeling, secure design reviews, and architecture assessments.
  • Validate security controls and identify vulnerabilities using manual and automated techniques.
  • Review remediation recommendations and support developers during vulnerability closure.
  • Prepare detailed technical and executive reports; track remediation and closure verification.

Skills

Application security
Penetration testing
DAST
API security testing
MAST
AI security testing

Tools

Burp Suite
Invicti
Checkmarx
Postman
OWASP ZAP
ReadyAPI
MobSF
NowSecure

Job description

We are seeking a highly skilled Senior Security Specialist (IC3) with 6-9 years of experience in Application Security & Penetration Testing (VAPT), and security testing methodologies. The ideal candidate should possess strong expertise in DAST, API Security Testing, Mobile Application Security Testing (MAST), and hands‑on exposure to AI-driven security testing and AI security risks. This role will work closely with development, DevOps, architecture, and product teams to identify, assess, and remediate security vulnerabilities throughout the SDLC.

Key Responsibilities
Application Security
  • Perform end-to-end application security assessments for web, mobile, and API applications.
  • Conduct threat modeling, secure design reviews, and architecture assessments.
  • Validate security controls and identify vulnerabilities using manual and automated techniques.
  • Review remediation recommendations and support development teams during vulnerability closure.
DAST (Dynamic Application Security Testing)
  • Conduct DAST assessments using tools such as:
  • Burp Suite Enterprise/Professional
  • Invicti (Netsparker)
  • Checkmarx
  • Analyze and validate findings to eliminate false positives.
  • Support tuning and optimization of DAST tools.
  • Develop DAST scanning standards, processes, and reporting mechanisms.
API Security
  • Perform API security testing against REST, SOAP, GraphQL, and Microservices architectures.
  • Validate API security controls including:
  • OAuth 2.0 / OIDC
  • JWT Security
  • Input Validation
  • Conduct testing aligned with:
  • OWASP API Security Top 10
  • OWASP ASVS
  • OWASP Testing Guide
  • Utilize tools such as:
  • Postman
  • Burp Suite
  • OWASP ZAP
  • ReadyAPI
Mobile Application Security Testing (MAST)
  • Perform Android and iOS application security assessments.
  • Conduct dynamic mobile application testing.
  • Assess data storage, encryption, certificate pinning, and API security implementations.
  • Use security tools such as:
  • MobSF
  • NowSecure
  • Burp Suite
VAPT Activities
  • Conduct vulnerability assessments and penetration tests.
  • Validate exploitability and business impact of identified vulnerabilities.
  • Prepare detailed technical and executive reports.
  • Track remediation and support closure verification activities.
  • Collaborate with development teams to reduce recurring vulnerabilities.
AI Security & Emerging Technologies
  • Assess security risks associated with AI/LLM-powered applications.
  • Understand and evaluate:
  • Insecure Plugin Integrations
  • Excessive Agency
  • Sensitive Information Disclosure
  • Familiarity with:
  • OWASP Top 10 for LLM Applications
  • GenAI Security Best Practices
  • Secure AI Development Lifecycle
  • Utilize AI-assisted security testing tools to improve assessment efficiency.
Secure SDLC Integration
  • Collaborate with development and DevOps teams.
  • Support security gates within CI/CD pipelines.
  • Participate in security reviews and release approvals.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Specialist
Senior Security Specialist

Lennox • Chennai District

On-site
INR 3,000,000 - 4,200,000
Senior Security Testing Consultant
Senior Security Testing Consultant

Lennox International • Chennai District

On-site
INR 2,500,000 - 4,000,000
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
Application Security Specialist (AppSec + AI Security)
Application Security Specialist (AppSec + AI Security)

Qualizeal India • Hyderabad

On-site
INR 3,000,000 - 6,000,000
Senior Security Engineer
Senior Security Engineer

Nextwebi • Bengaluru

On-site
INR 1,500,000 - 2,100,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Nextwebi • Bengaluru

On-site
INR 1,500,000 - 3,000,000
Application Security Engineer
Application Security Engineer

Kyndryl • Dadri, Greater Noida

On-site
INR 2,500,000 - 4,500,000
Staff Engineer - Application Security
Staff Engineer - Application Security

UST • Bengaluru

On-site
INR 2,400,000 - 4,200,000
AI Security Engineer
AI Security Engineer

QualiZeal • Hyderabad

On-site
INR 2,500,000 - 4,500,000
CyberSecurity
CyberSecurity

Cloudxtreme • Hyderabad, Bengaluru

On-site
INR 170,000 - 210,000