TECHNICAL LEAD - Penetration Testing (Karnataka)

TECHNICAL LEAD - Penetration Testing (Karnataka)

30 Jul
|
Happiest Minds Technologies
|
Karnataka

30 Jul

Happiest Minds Technologies

Karnataka

Technical Lead - Application Security API Security

Role Overview:

- The Technical Lead - Application API Security will be responsible for leading end-to-end security assessments, including web application penetration testing and API security testing

The role involves technical leadership, client coordination, quality assurance of deliverables, and driving remediation guidance to improve overall security posture

- This role requires strong expertise in risk-based security assessment methodologies, OWASP standards, and hands-on penetration testing across modern applications and APIs

Key Responsibilities

1

Technical Leadership Delivery Oversight

- Lead and oversee execution of application penetration testing and API security assessments using risk-based methodologies

- Ensure quality and accuracy of vulnerability findings, reports, and remediation recommendations

- Act as the technical owner for assessment activities including planning, execution, validation, and reporting

2

Security Assessment Execution

- Drive comprehensive web application security testing , including:
- Authentication, authorization, and session management testing
- Input validation (SQL Injection, XSS, command injection, etc)
- Business logic flaw analysis
- Encryption and access control validation

- Lead API security testing , including:

- Parameter tampering, fuzz testing, authentication flaws
- Injection attacks (SQL/XPath/XML)
- Session attacks, replay attacks, and API abuse scenarios

3

Methodology Testing Approach

- Implement dynamic application security testing (DAST) combining manual and automated techniques

- Lead assessment lifecycle:





- Profiling attack surface identification
- Automated scanning
- Manual validation exploitation
- Risk scoring and reporting (CVSS-based)

4

Stakeholder Client Coordination

- Coordinate with client development and application teams for:

- Kick-off discussions and requirement elicitation
- Daily/periodic status updates and interim findings
- Risk validation and closure discussions

- Lead stakeholder presentations to explain findings, risks, and mitigation strategies

5

Reporting Deliverables Management

- Ensure delivery of:

- Detailed vulnerability assessment reports
- Executive summaries
- Risk register and tracking dashboards
- Weekly/monthly progress reports

- Maintain application security risk register and ensure effective tracking of remediation

6

Remediation Advisory

- Provide hands-on guidance to development teams to remediate vulnerabilities

- Support re-testing and validation of fixes within defined SLA timelines

- Drive secure coding awareness and best practices

7

Quality Compliance

- Ensure adherence to industry standards:

- OWASP, SANS, CREST, NIST, OSSTIMM

- Validate severity classification and risk prioritization using CVSS scoring frameworks

Required Skills Competencies:

Technical Skills

- Strong expertise in:




- Web Application Penetration Testing
- API Security Testing (REST/SOAP)
- Vulnerability Assessment tools and techniques

- Deep understanding of:

- OWASP Top 10 API Security Top 10 including AI testing
- Authentication, authorization, encryption mechanisms
- Secure coding practices

- Hands-on experience with tools such as:

- Burp Suite, OWASP ZAP, Nessus, Nmap, postman etc

- Leadership Delivery Skills
- Ability to lead security engagements end-to-end
- Strong stakeholder management and communication skills
- Experience in managing cross-functional teams (Dev, Infra, Security)
- Ability to mentor junior security consultants
- Experience Qualifications
- 6 to 9 years of experience in application security / penetration testing
- Prior experience in Technical Lead / Security Lead role
- Certifications (preferred):

- CEH, OSCP, GWAPT, CISSP or equivalent

- Key Deliverables Owned
- Security assessment reports (AI, Application API)
- Executive dashboards and summaries with enterprise level presentations
- Risk register and remediation tracking
- Client presentations and advisory artefacts
- Additional Expectations
- Ensure timely retesting and closure of vulnerabilities
- Maintain solid focus on risk reduction and security posture improvement
- Drive continuous improvement in testing methodologies and engagement quality

Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.

📌 TECHNICAL LEAD - Penetration Testing (Karnataka)
🏢 Happiest Minds Technologies
📍 Karnataka

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: technical lead - penetration testing (karnataka) / karnataka

Subscribe to this job alert:

Get the latest job offers by email for: technical lead - penetration testing (karnataka) / karnataka