We are looking for a skilled Application Security Engineer with hands-on experience in Web Application Security, API Security, Mobile Application Security, and Manual Penetration Testing.
The ideal candidate should have expertise in identifying security vulnerabilities, performing security assessments, validating remediation, and supporting secure application development practices.
Must-Have Skills
Strong hands-on experience in manual penetration testing of web applications.
Experience in API Security Testing using tools such as:
Postman
Burp Suite
Experience in Mobile Application Security Testing (Android/iOS).
Strong understanding of
OWASP Top 10
API Security Top 10
Authentication & Authorization mechanisms
Experience identifying and validating vulnerabilities such as:
SQL Injection
XSS
CSRF
SSRF
IDOR
Authentication bypass
Business logic vulnerabilities
Ability to create detailed vulnerability reports with remediation recommendations.
Key Responsibilities
Perform manual penetration testing of web, mobile, and API-based applications.
Conduct security assessments and identify vulnerabilities in applications.
Execute API testing using Postman and Burp Suite.
Review application security posture against OWASP standards.
Analyze application architecture and identify potential security weaknesses.
Work with development teams to validate fixes and provide remediation guidance.
Prepare assessment reports and present findings to stakeholders.
Participate in security reviews during SDLC and release cycles.
Support security compliance and audit requirements.