Penetration Testing Engineer / Application Security Testing Engineer
Experience: 8 Years (Mandatory)
Primary Location: Bangalore (Preferred) and other Apple locations across India
Job Summary
We are seeking an experienced Application Security Testing Engineer with 8 years of hands-on experience in penetration testing, application security assessments, and secure software development practices. The ideal candidate will have expertise in identifying security vulnerabilities across web applications, APIs, and cloud environments, while working closely with development teams to strengthen application security throughout the Software Development Life Cycle (SDLC).
Key Responsibilities
Perform comprehensive penetration testing of web applications, APIs, and enterprise applications to identify and validate security vulnerabilities.
Conduct manual security assessments using Burp Suite and other industry-standard security testing tools.
Review application source code from a security perspective to identify insecure coding practices and recommend remediation.
Execute and analyze SAST, DAST, and IAST scans, validate findings, and eliminate false positives.
Integrate automated security testing into CI/CD pipelines to enable continuous security validation.
Perform vulnerability assessments, risk analysis, and provide actionable remediation recommendations.
Assess cloud-native applications and containerized environments for security risks.
Support security audits, compliance assessments, and remediation initiatives.
Collaborate with development, DevOps, and infrastructure teams to implement secure coding and deployment practices.
Participate in security incident investigations, root cause analysis, and post-remediation validation.
Required Skills & Experience
8 years of hands-on experience in Application Security Testing and Penetration Testing.
Strong experience performing manual penetration testing on Web Applications and REST APIs using Burp Suite.
Strong understanding of the OWASP Top 10, common attack vectors, secure coding practices, and remediation techniques.
Proficiency in reviewing and understanding application code written in languages such as:
Java
JavaScript
Python
Other object-oriented or scripting languages
Hands-on experience with application security testing tools including:
SAST (Static Application Security Testing)
DAST (Dynamic Application Security Testing)
IAST (Interactive Application Security Testing)
Experience validating scan results and performing false-positive analysis.
Practical knowledge of integrating security testing into CI/CD pipelines.
Strong understanding of
Network Security
Encryption and Cryptographic Protocols
Identity and Access Management (IAM)
Authentication and Authorization mechanisms
Experience conducting vulnerability assessments and penetration testing across diverse technology stacks.
Knowledge of Cloud Security concepts, including Container Security.
Familiarity with Secure SDLC (SSDLC) practices and application security governance.
Experience supporting security audits, compliance assessments, and vulnerability remediation efforts.
Exposure to security incident response, investigation, and root cause analysis.
Preferred Qualifications
Experience securing cloud platforms and contemporary containerized applications.
Knowledge of DevSecOps practices and automated security validation.
Relevant security certifications such as OSCP, OSWE, CEH, GWAPT, GPEN, CSSLP, or CISSP are an added advantage.
Work Location
Primary Location: Bangalore
Other Locations: Candidate should be open to working from other Apple locations across India based on business requirements.
📌 Penetration Testing Engineer - Application Security (India)
🏢 SYSMIND
📍 India