06 Aug
|
Lennox International
|
Tamil Nadu
06 Aug
Lennox International
Tamil Nadu
Company Profile
Lennox (NYSE: LII) Driven by 130 years of legacy, HVAC and refrigeration success, Lennox provides our residential and commercial customers with industry-leading climate-control solutions. At Lennox, we win as a team, aiming for excellence and delivering innovative, sustainable products and services. Our culture guides us and creates a workplace where all employees feel heard and welcomed.
Lennox is a global community that values each team member’s contributions and offers a supportive setting for career development. Come, stay, and grow with us.
We are seeking a highly skilled Senior Security Specialist (IC3) with 6-9 years of experience in Application Security & Penetration Testing (VAPT), and security testing methodologies. The ideal candidate should possess strong expertise in DAST, API Security Testing, Mobile Application Security Testing (MAST), and hands-on exposure to AI-driven security testing and AI security risks. This role will work closely with development, DevOps, architecture, and product teams to identify, assess, and remediate security vulnerabilities throughout the SDLC.
Key Responsibilities
Application Security
Perform end-to-end application security assessments for web, mobile, and API applications.
Conduct threat modeling, secure design reviews, and architecture assessments.
Validate security controls and identify vulnerabilities using manual and automated techniques.
Review remediation recommendations and support development teams during vulnerability closure.
DAST (Dynamic Application Security Testing)
Conduct DAST assessments using tools such as:
Burp Suite Enterprise/Professional
Invicti (Netsparker)
Checkmarx
Analyze and validate findings to eliminate false positives.
Support tuning and optimization of DAST tools.
Develop DAST scanning standards, processes, and reporting mechanisms.
API Security
Perform API security testing against REST, SOAP, GraphQL, and Microservices architectures.
Validate API security controls including:
Authentication & Authorization
OAuth 2.0 / OIDC
JWT Security
Rate Limiting
Input Validation
API Abuse Scenarios
Conduct testing aligned with
OWASP API Security Top 10
OWASP ASVS
OWASP Testing Guide
Utilize tools such as
Postman
Burp Suite
OWASP ZAP
ReadyAPI
Mobile Application Security Testing (MAST)
Perform Android and iOS application security assessments.
Conduct dynamic mobile application testing.
Assess data storage, encryption, certificate pinning, and API security implementations.
Use security tools such as:
MobSF
NowSecure
Burp Suite
VAPT Activities
Conduct vulnerability assessments and penetration tests.
Validate exploitability and business impact of identified vulnerabilities.
Prepare detailed technical and executive reports.
Track remediation and support closure verification activities.
Collaborate with development teams to reduce recurring vulnerabilities.
AI Security & Emerging Technologies
Assess security risks associated with AI/LLM-powered applications.
Understand and evaluate
Prompt Injection
Data Leakage Risks
Model Poisoning
Insecure Plugin Integrations
Excessive Agency
Sensitive Information Disclosure
Familiarity with
OWASP Top 10 for LLM Applications
GenAI Security Best Practices
Secure AI Development Lifecycle
Utilize AI-assisted security testing tools to improve assessment efficiency.
Secure SDLC Integration
Collaborate with development and DevOps teams.
Support security gates within CI/CD pipelines.
Participate in security reviews and release approvals.
Qualifications
Bachelor’s degree in computer science, Cyber Security, Information Technology, or a related field.
6-9 years of experience in Application Security, VAPT, or Security Testing.
Strong understanding of web, mobile, and API security principles.
Experience interacting with development and architecture teams.
Excellent analytical, problem-solving, and communication skills.
📌 Senior Security Specialist (Tamil Nadu)
🏢 Lennox International
📍 Tamil Nadu