Apply Only if
- 7+ years of overall experience in Cybersecurity, Information Security, VAPT, or Offensive Security
- Specialized in Red Team, Web Application and Mobile Application Security Testing
- Willing to work On-site Full Time in Mumbai/Thane
- Joining/Available within 30 days
Send your resume to
[email protected]
Security Brigade is looking for an experienced and highly skilled Security Lead- Red Teaming & Application Security to join our cybersecurity team. The ideal candidate will have solid hands-on expertise in Web Application Security, Mobile Application Security, and Red Teaming , with the ability to independently lead and execute complex security assessments and offensive security engagements.
The role requires a technically strong L3-level security professional who can identify, exploit, and validate security vulnerabilities, simulate real-world attack scenarios, and provide actionable remediation recommendations.
Key Responsibilities
- Lead and perform comprehensive Web Application and Mobile Application Security Assessments .
- Conduct advanced penetration testing and vulnerability assessments across applications, APIs, networks, and supporting infrastructure.
- Perform Red Team exercises and adversary simulation activities to identify gaps in security controls and detection capabilities.
- Identify, validate, and demonstrate the impact of complex security vulnerabilities.
- Perform manual security testing beyond automated vulnerability scanning.
- Assess authentication, authorization, session management, API security, business logic flaws,
and common application vulnerabilities.
- Conduct attack-path analysis and simulate real-world attacker techniques.
- Work closely with technical stakeholders to communicate vulnerabilities, attack scenarios, business impact, and remediation recommendations.
- Prepare detailed technical reports and executive-level summaries of security assessment findings.
- Validate remediation and perform re-testing of identified vulnerabilities.
- Support the development and enhancement of security testing methodologies, processes, and internal capabilities.
- Stay updated with emerging threats, vulnerabilities, exploitation techniques, and offensive security tools.
Required Skills & Experience
- 7+ years of overall experience in Cybersecurity, Information Security, VAPT, or Offensive Security.
- Strong expertise in Web Application Security Testing .
- Strong hands-on experience in Mobile Application Security Testing for Android and/or iOS.
- Minimum 2-3 years of hands-on experience in Red Teaming or advanced Offensive Security engagements .
- Strong understanding of OWASP methodologies, including:
- OWASP Top 10
- OWASP API Security
- Mobile Application Security principles
- Experience identifying and exploiting vulnerabilities such as:
- Authentication and authorization flaws
- Business logic vulnerabilities
- Injection vulnerabilities
- Broken access control
- API security issues
- Session management flaws
- Client-side vulnerabilities
- Experience with manual penetration testing and exploitation techniques.
- Hands-on experience with security testing and offensive security tools such as Burp Suite, Nmap, Metasploit, Wireshark, MobSF, Frida , or similar tools.
- Understanding of attacker tactics, techniques, and procedures and the ability to simulate realistic attack scenarios.
- Strong analytical, problem-solving, and technical documentation skills.
Preferred Skills
- Experience in API Security Testing.
- Experience with network and infrastructure penetration testing.
- Knowledge of Active Directory security and enterprise attack techniques.
- Familiarity with MITRE ATT&CK; framework.
- Experience with cloud security testing would be an advantage.
- Relevant certifications such as OSCP, OSWE, CRTP, CREST, CEH, eWPT , or similar will be an added advantage.
Key Attributes
- Strong hands-on technical expertise with the ability to independently execute complex security assessments.
- Ability to lead technical discussions and provide guidance during security engagements.
- Strong communication skills for presenting findings to technical and non-technical stakeholders.
- Ability to work effectively in an on-site, client-facing environment.
- Detail-oriented with strong ownership and problem-solving skills.
📌 Security Lead - Red Team and Application Security (Thane)
🏢 Security Brigade
📍 Thane