16 Aug
|
Suzva Software Technologies
|
Mumbai
16 Aug
Suzva Software Technologies
Mumbai
Role summary
- We are looking for an experienced Application Penetration Tester to join our security team. You will perform hands-on security assessments of web, mobile, API, and cloud-hosted applications to identify vulnerabilities, exploitability, and business impact.
- You will work with engineering teams to validate issues, recommend mitigations, and help raise the overall security posture through secure-by-design advice, threat modeling, and security testing automation.
Key responsibilities
- Plan and execute manual and automated penetration tests for web applications, REST/GraphQL APIs, mobile apps (iOS/Android), and serverless/cloud functions.
- Perform authenticated and unauthenticated testing, business logic testing, and privilege escalation scenarios.
- Exploit vulnerabilities to demonstrate risk (safe, controlled exploitation) and produce transparent proof-of-concept (PoC).
- Produce high-quality,
actionable vulnerability reports with risk rating, reproduction steps, impact assessment, and remediation guidance.
- Work closely with development, DevOps, and product teams to triage, validate fixes, and re-test vulnerabilities.
- Integrate security testing into CI/CD pipelines and champion test automation (SAST/DAST/IAST) where appropriate.
- Conduct code reviews / secure code walkthroughs (as needed) focusing on language/frameworks used by engineering teams.
- Run threat modelling workshops, design reviews, and security architecture consultations for new features.
- Maintain knowledge of current attack techniques, CVEs, exploit frameworks and recommend defensive controls.
- Contribute to internal tooling, playbooks, and run periodic red-team / purple-team exercises.
📌 Application Penetration Tester (Mumbai)
🏢 Suzva Software Technologies
📍 Mumbai