11 Aug
|
Tata Consultancy Services
|
Noida
11 Aug
Tata Consultancy Services
Noida
Role: Application Security Engineer
Location: Recent Delhi
Experience: 4 - 10 Years
We are looking for a skilled Application Security Engineer with hands-on experience in Web Application Security, API Security, Mobile Application Security, and Manual Penetration Testing.
The ideal candidate should have expertise in identifying security vulnerabilities, performing security assessments, validating remediation, and supporting secure application development practices.
Must-Have Skills
- 1. Perform vulnerability assessment and manual penetration testing for web applications, APIs, and application components.
- Create security test cases based on application functionality, threat scenarios, OWASP Top 10, API Security Top 10, and business logic risks.
- Use security tools such as Burp Suite, OWASP ZAP, Fortify, Nessus, Acunetix, Postman, and similar tools for scanning and validation.
- Analyze scan results, validate true positives, identify false positives, and prepare clear technical vulnerability reports.
- Work with development teams to explain vulnerabilities, recommend remediation steps, and perform retesting after fixes.
- Knowledge of SAST, DAST, API security testing, dependency scanning, and vulnerability management processes.
Key Responsibilities
1. Perform authorized vulnerability assessment and penetration testing for web applications, APIs, mobile applications,
and related infrastructure components.
2. Identify, validate, and document security vulnerabilities including OWASP Top 10, API Security Top 10, authentication, authorization, session management, business logic, and configuration weaknesses.
3. Use security testing tools such as Burp Suite, OWASP ZAP, Postman, Fortify, Nessus, Acunetix, and similar tools for scanning, validation, and exploitation verification.
4. Analyze scan results, remove false positives, prioritize true vulnerabilities based on risk, and prepare clear technical reports with impact and remediation recommendations.
5. Coordinate with development, DevOps, and infrastructure teams to explain findings, support remediation, and perform retesting after fixes
6. Create security test cases and checklists based on application functionality, threat scenarios, compliance requirements, and secure coding standards.
7. Maintain proper evidence, screenshots, testing notes, and audit-ready documentation for all identified and remediated vulnerabilities.
8. Support secure SDLC activities including SAST, DAST, dependency scanning, API security testing, and vulnerability management governance.
9. Stay updated on latest attack techniques, vulnerabilities, security tools, and industry best practices
📌 Application Security Engineer (Noida)
🏢 Tata Consultancy Services
📍 Noida