Senior Security Specialist

Lennox

Chennai District

On-site

INR 3,000,000 - 4,200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Lennox, a global HVAC and refrigeration leader, is seeking a Senior Security Specialist (IC3) with 6-9 years of experience in Application Security, VAPT, and security testing to join our team in India.

You will perform DAST, API security testing, and MAST, work with DevOps and product teams to secure SDLC, and contribute to AI security initiatives.

Qualifications

  • Bachelor’s degree in computer science, Cyber Security, Information Technology, or a related field.
  • 6-9 years of experience in Application Security, VAPT, or Security Testing.
  • Strong understanding of web, mobile, and API security principles.

Responsibilities

  • Perform end-to-end application security assessments for web, mobile, and API applications.
  • Conduct threat modeling, secure design reviews, and architecture assessments.
  • Validate security controls and identify vulnerabilities using manual and automated techniques.
  • Review remediation recommendations and support development teams during vulnerability closure.
  • Prepare detailed technical and executive reports and track remediation.
  • Collaborate with development and DevOps teams to integrate security gates in CI/CD.
  • Assess security risks in AI/LLM-powered applications.

Skills

Application Security
Penetration Testing
Threat Modeling
VAPT
AI Security Testing
Security Auditing
Communication

Education

Bachelor’s degree in Computer Science or related field

Tools

Burp Suite
Invicti (Netsparker)
Checkmarx
Postman
OWASP ZAP
ReadyAPI
MobSF
NowSecure

Job description

Company Profile

Lennox (NYSE: LII) Driven by 130 years of legacy, HVAC and refrigeration success, Lennox provides our residential and commercial customers with industry-leading climate-control solutions. At Lennox, we win as a team, aiming for excellence and delivering innovative, sustainable products and services. Our culture guides us and creates a workplace where all employees feel heard and welcomed. Lennox is a global community that values each team member’s contributions and offers a supportive environment for career development. Come, stay, and grow with us.

Job Description

We are seeking a highly skilled Senior Security Specialist (IC3) with 6-9 years of experience in Application Security & Penetration Testing (VAPT), and security testing methodologies. The ideal candidate should possess strong expertise in DAST, API Security Testing, Mobile Application Security Testing (MAST), and hands-on exposure to AI-driven security testing and AI security risks. This role will work closely with development, DevOps, architecture, and product teams to identify, assess, and remediate security vulnerabilities throughout the SDLC.

Key Responsibilities
Application Security
  • Perform end-to-end application security assessments for web, mobile, and API applications.
  • Conduct threat modeling, secure design reviews, and architecture assessments.
  • Validate security controls and identify vulnerabilities using manual and automated techniques.
  • Review remediation recommendations and support development teams during vulnerability closure.
DAST (Dynamic Application Security Testing)
  • Conduct DAST assessments using tools such as:
    • Burp Suite Enterprise/Professional
    • Invicti (Netsparker)
    • Checkmarx
  • Analyze and validate findings to eliminate false positives.
  • Support tuning and optimization of DAST tools.
  • Develop DAST scanning standards, processes, and reporting mechanisms.
API Security
  • Perform API security testing against REST, SOAP, GraphQL, and Microservices architectures.
  • Validate API security controls including:
    • Authentication & Authorization
    • OAuth 2.0 / OIDC
    • JWT Security
    • Rate Limiting
    • Input Validation
    • API Abuse Scenarios
  • Conduct testing aligned with:
    • OWASP API Security Top 10
    • OWASP ASVS
    • OWASP Testing Guide
  • Utilize tools such as:
    • Postman
    • Burp Suite
    • OWASP ZAP
    • ReadyAPI
Mobile Application Security Testing (MAST)
  • Perform Android and iOS application security assessments.
  • Conduct dynamic mobile application testing.
  • Assess data storage, encryption, certificate pinning, and API security implementations.
  • Use security tools such as:
    • MobSF
    • NowSecure
    • Burp Suite
VAPT Activities
  • Conduct vulnerability assessments and penetration tests.
  • Validate exploitability and business impact of identified vulnerabilities.
  • Prepare detailed technical and executive reports.
  • Track remediation and support closure verification activities.
  • Collaborate with development teams to reduce recurring vulnerabilities.
AI Security & Emerging Technologies
  • Assess security risks associated with AI/LLM-powered applications.
  • Understand and evaluate:
    • Prompt Injection
    • Data Leakage Risks
    • Model Poisoning
    • Insecure Plugin Integrations
    • Excessive Agency
    • Sensitive Information Disclosure
  • Familiarity with:
    • OWASP Top 10 for LLM Applications
    • GenAI Security Best Practices
    • Secure AI Development Lifecycle
  • Utilize AI-assisted security testing tools to improve assessment efficiency.
Secure SDLC Integration
  • Collaborate with development and DevOps teams.
  • Support security gates within CI/CD pipelines.
  • Participate in security reviews and release approvals.
Qualifications
  • Bachelor’s degree in computer science, Cyber Security, Information Technology, or a related field.
  • 6-9 years of experience in Application Security, VAPT, or Security Testing.
  • Strong understanding of web, mobile, and API security principles.
  • Experience interacting with development and architecture teams.
  • Excellent analytical, problem-solving, and communication skills.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Specialist
Senior Security Specialist

Lennox India Technology Centre • Chennai District

On-site
INR 2,800,000 - 4,000,000
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
Appsec Specialist - Lead
Appsec Specialist - Lead

Adani Group • Ahmedabad District

On-site
INR 2,800,000 - 4,200,000
Application Security Testing Engineer
Application Security Testing Engineer

Infosys • Bengaluru

On-site
INR 900,000 - 1,200,000
Application Security
Application Security

Airtel • India

On-site
INR 1,200,000 - 2,400,000
Security-focused culture
VAPT consultant
VAPT consultant

Cyraac Services • Pune District

On-site
INR 700,000 - 1,100,000
Appsec Specialist - Lead
Appsec Specialist - Lead

Adani Enterprises Limited • Ahmedabad District

On-site
INR 2,600,000 - 3,800,000
Application Testing Engineer
Application Testing Engineer

Quess • Chennai District, Bengaluru, Pune District

Hybrid
INR 700,000 - 1,500,000
Senior Security Consultant
Senior Security Consultant

Payatu Technologies Pvt Ltd • Pune District

On-site
INR 1,800,000 - 3,200,000
Application Security Engineer
Application Security Engineer

Basebiz • Chennai District

On-site
INR 1,200,000 - 1,800,000