Technical Lead (Application Security testing - DAST)

Wipro Technologies

Bengaluru

On-site

INR 2,500,000 - 4,000,000

Full time

1 hour ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Wipro Limited is seeking a Technical Lead for Application Security testing - DAST in India. You will lead DAST and manual penetration testing across web, API, mobile, and Gen-AI contexts, and drive secure coding practices within CI/CD pipelines.

We value strong leadership, hands-on security expertise with OWASP Top 10, and collaboration with developers and stakeholders to remediate findings and reduce risk across enterprise projects.

Qualifications

  • Bachelor's degree in a technical field.
  • 2-5 years of experience in application security testing / penetration testing.
  • Proven ability to lead teams, review deliverables, and manage stakeholders.
  • Strong hands-on expertise in DAST and manual penetration testing (web, API, mobile, thick client, SAP, and Gen‑AI applications).
  • Good understanding of SAP ecosystem including architecture, authorization concepts, RFC/ICF/OData exposure points, and testing prerequisites (including T‑codes).
  • Experience in security testing of Gen‑AI/LLM-based applications.
  • Strong knowledge of OWASP Top 10, LLM Top 10, API top 10.
  • Experience in scan configuration, tuning, and authenticated scanning.
  • Hands‑on experience with Burp Suite, WebInspect, Postman, Sysinternals, etc.
  • Experience working in DevSecOps environments and CI/CD pipelines.
  • Good to have: Experience in WAF management and rule tuning.

Responsibilities

  • Perform and lead DAST and manual penetration testing (web, API, mobile, thick client, SAP, and Gen-AI applications) using gray box approach.
  • Perform security testing of Gen-AI/LLM-based applications, covering prompt injection, data leakage, access control, and API/model integration risks
  • Oversee and optimise automated security scans, including configuration, tuning, and false positive reduction
  • Perform and review API security testing (authentication, authorization, input validation, header and parameter manipulation)
  • Identify, exploit, and review security test reports with clear risk rating, PoC, and remediation guidance
  • Lead and mentor a team of security testers; review test quality, ensure coverage, and drive consistency
  • Drive integration of security testing into CI/CD pipelines (DevSecOps) and ensure shift-left practices
  • Introduce new enhancements in the testing track improving accuracy, quality. Liaising with vendors for enabling/upgrade of new features in the security scanning tools.
  • Collaborate with developers, architects, and stakeholders to ensure timely remediation.
  • Provide oversight and guidance on WAF onboarding, rule tuning, and policy effectiveness

Skills

DAST testing
Penetration testing
Team leadership
OWASP Top 10
Gen‑AI security testing
CI/CD / DevSecOps
Security testing tools

Education

Bachelor's degree

Tools

Burp Suite
WebInspect
Postman
Sysinternals

Job description

Job Title: Technical Lead (Application Security testing - DAST)

Posting Start Date: 8/28/26

Wipro Limited (NYSE: WIT, BSE: 507685, NSE: WIPRO) is a leading technology services and consulting company focused on building innovative solutions that address clients’ most complex digital transformation needs. Leveraging our holistic portfolio of capabilities in consulting, design, engineering, and operations, we help clients realize their boldest ambitions and build future-ready, sustainable businesses. With over 230,000 employees and business partners across 65 countries, we deliver on the promise of helping our customers, colleagues, and communities thrive in an ever-changing world. For additional information, visit us at www.wipro.com.

Job Description

Role: Application Security testing - DAST)

Location: Pune / Mumbai preferred, anywhere in India.

About the role: Wipro is looking to onboard a Application Security test lead with experience in Application Security Testing - DAST supporting Corporate CISO.

Roles & Responsibilities
  • Perform and lead DAST and manual penetration testing (web, API, mobile, thick client, SAP, and Gen-AI applications) using gray box approach.
  • Perform security testing of Gen-AI/LLM-based applications, covering prompt injection, data leakage, access control, and API/model integration risks
  • Oversee and optimise automated security scans, including configuration, tuning, and false positive reduction
  • Perform and review API security testing (authentication, authorization, input validation, header and parameter manipulation)
  • Identify, exploit, and review security test reports with clear risk rating, PoC, and remediation guidance
  • Lead and mentor a team of security testers; review test quality, ensure coverage, and drive consistency
  • Drive integration of security testing into CI/CD pipelines (DevSecOps) and ensure shift-left practices
  • Introduce new enhancements in the testing track improving accuracy, quality. Liaising with vendors for enabling/upgrade of new features in the security scanning tools.
  • Collaborate with developers, architects, and stakeholders to ensure timely remediation.
  • Provide oversight and guidance on WAF onboarding, rule tuning, and policy effectiveness
Qualifications
  • Bachelor’s degree in a technical field
  • 2-5 years of experience in application security testing / penetration testing
  • Proven ability to lead teams, review deliverables, and manage stakeholders
  • Strong hands‑on expertise in DAST and manual penetration testing (web, API, mobile, thick client, SAP, and Gen‑AI applications)
  • Good understanding of SAP ecosystem including architecture, authorization concepts, RFC/ICF/OData exposure points, and testing prerequisites (including T‑codes)
  • Experience in security testing of Gen‑AI/LLM-based applications
  • Strong knowledge of OWASP Top 10, LLM Top 10, API top 10
  • Experience in scan configuration, tuning, and authenticated scanning
  • Hands‑on experience with tools such as Burp Suite, WebInspect, Postman, Sysinternals, etc.
  • Experience working in DevSecOps environments and CI/CD pipelines
  • Good to have: Experience in WAF management and rule tuning
Good to have Certifications
  • CEH, GWAPT, GPEN, CISSP, or similar

Reinvent your world.We are building a modern Wipro. We are an end-to-end digital transformation partner with the boldest ambitions. To realize them, we need people inspired by reinvention. Of yourself, your career, and your skills. We want to see the constant evolution of our business and our industry. It has always been in our DNA - as the world around us changes, so do we. Join a business powered by purpose and a place that empowers you to design your own reinvention. Come to Wipro. Realize your ambitions.

Applications from people with disabilities are explicitly welcome.

We are an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, caste, creed, religion, gender, marital status, age, ethnic and national origin, gender identity, gender expression, sexual orientation, political orientation, disability status, protected veteran status, or any other characteristic protected by law.

Wipro is committed to creating an accessible, supportive, and inclusive workplace. Reasonable accommodation will be provided to all applicants including persons with disabilities, throughout the recruitment and selection process. Accommodations must be communicated in advance of the application, where possible, and will be reviewed on an individual basis. Wipro provides equal opportunities to all and values diversity.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Consultant (Application Security testing - SAST and SCA)
Senior Consultant (Application Security testing - SAST and SCA)

Wipro Technologies • Chennai District

On-site
INR 1,800,000 - 2,400,000
Developer - L3
Developer - L3

Wipro Technologies • India

On-site
INR 600,000 - 1,200,000
Senior Test Engineer (SDET)
Senior Test Engineer (SDET)

Wipro Technologies • Pune District

On-site
INR 1,500,000 - 2,300,000
C# with API automation (.Net QA)
C# with API automation (.Net QA)

Wipro Technologies • Bengaluru

On-site
INR 900,000 - 1,300,000
API Automation Testing
API Automation Testing

Wipro Technologies • Bengaluru

On-site
INR 900,000 - 1,200,000
Developer
Developer

Wipro Technologies • Pune District

On-site
INR 1,200,000 - 1,600,000
CTO - Technical Support Engineer - Topcoder
CTO - Technical Support Engineer - Topcoder

Wipro Technologies • Jaipur

Hybrid
INR 600,000 - 1,000,000
Inclusive workplace
Supportive environment
TEST ENGINEER L3
TEST ENGINEER L3

Wipro Technologies • Chennai District

On-site
INR 600,000 - 900,000
TEST ENGINEER L3
TEST ENGINEER L3

Wipro Technologies • Bengaluru

On-site
INR 600,000 - 800,000
AI Security & Risk Assessor
AI Security & Risk Assessor

Wipro Technologies • Bengaluru

On-site
INR 3,000,000 - 5,000,000