Get more replies from employers
Send a job-specific resume in minutes.
Writer Corporation in Mumbai is seeking a Security Analyst with expertise in Application Security and VAPT. The ideal candidate will conduct comprehensive security assessments, perform security testing, and ensure secure coding practices within development teams.
The role requires 5+ years of experience and a Bachelor's degree in a relevant field, along with CEH certification. Strong skills in VAPT and familiarity with tools like SonarQube and Fortify are essential.
Job Title: Security Analyst Application Security (VAPT)
Experience: 5+ Years
Location: Client Location
Certification: CEH (Certified Ethical Hacker) – Mandatory
We are seeking an experienced Security Analyst with strong expertise in Application Security and VAPT to join our security team. The ideal candidate will be responsible for conducting comprehensive security assessments of web and mobile applications, performing secure code reviews, and supporting the organization in strengthening its overall application security posture.
Perform Vulnerability Assessment and Penetration Testing (VAPT) for web applications, mobile applications, network and APIs.
Conduct Static Application Security Testing (SAST) to identify security vulnerabilities in source code.
Perform Dynamic Application Security Testing (DAST) to detect runtime vulnerabilities in applications.
Carry out Secure Code Reviews to identify security flaws and recommend remediation.
Perform Software Composition Analysis (SCA) to identify vulnerabilities in third-party libraries and open-source components.
Identify, analyze, and validate security vulnerabilities and provide detailed risk-based reports with remediation recommendations.
Work closely with development and DevOps teams to ensure secure coding practices and assist in vulnerability remediation.
Conduct re-testing and validation of vulnerabilities after remediation.
Prepare and present detailed security assessment reports to internal stakeholders and clients.
Strong hands-on experience in Web Application VAPT, APIs and Mobile Application VAPT.
Solid understanding of OWASP Top 10, API Security Top 10, and common application security vulnerabilities.
Experience in SAST, DAST, and SCA tools and methodologies.
Knowledge of secure coding principles and common programming vulnerabilities.
Experience in manual penetration testing techniques and vulnerability validation.
Understanding of authentication, authorization, session management, and cryptographic security issues.
Hands-on experience with the following tools is required:
SonarQube, Fortify, Burp Suite and other application security and penetration testing tools.
Bachelor’s degree in Computer Science, Cyber Security, Information Technology, or any other degree.
CEH (Certified Ethical Hacker) – Mandatory
Knowledge of CI/CD security integration.
Experience in cloud security testing (AWS / Azure / GCP) is an added advantage.
Strong communication skills for client interaction and technical reporting.
Strong analytical and problem-solving skills
Ability to work independently and manage multiple assessments
Good documentation and reporting capabilities