Job Title: Application Security Analyst
Location: DLF Cybercity, Porur, Chennai- India
Experience: 4 - 8 Years
About the Job:
We are looking for an Application Security Analyst who will ensure that mobile and web applications are developed, deployed, and maintained based on security standards and best practices to protect the organization from potential threats and vulnerabilities. This role will work closely with development, network security, and technology teams to embed security throughout the software development lifecycle.
Job Responsibilities:
Mobile and Web Application Penetration Testing
Perform static and dynamic analysis of Android and iOS applications to uncover insecure data storage, weak cryptography, SSL pinning/root detection bypass, and other mobile application risks.
Test anti-tampering and device binding controls such as RASP, root/jailbreak detection, device attestation, and biometric authentication implementation.
Conduct web application penetration testing against the OWASP Top 10, including injection, broken authentication/session management, and access control vulnerabilities, across customer and internal-facing web portals.
Document findings with risk ratings, proof of concept, and remediation recommendations, and perform retesting through closure.
API Security Testing
Conduct API penetration testing on internal and externally exposed APIs using the OWASP API Security Top 10 as the baseline methodology.
Test authentication and session handling, mTLS enforcement, token replay/reuse scenarios, and authorization controls.
Evaluate rate limiting, throttling, and anti-automation controls against brute force, credential stuffing, and enumeration attacks on customer-facing APIs.
Review API Gateway and WAF rule effectiveness against attack payloads and coordinate with the Network Security team on ruleset fine-tuning.
Secure SDLC and Application Security Governance
Embed security checkpoints across the SDLC, including security requirements review at the design phase, secure code review, and pre-release security sign-off.
Support integration of SAST/DAST in CI/CD pipelines and triage automated scan findings for accuracy and risk relevance.
Track application security findings and remediation status through risk registers, KPIs, and reports.
Conduct periodic application security awareness sessions for developers on secure coding practices and common vulnerabilities.
Preferred Experience and Qualifications:
- Bachelor’s degree in Computer Science, IT, Information Security, or a related field; certifications such as OSCP, eMAPT, or CEH are preferred.
- 4–8 years of experience in Application Security, with hands-on mobile application penetration testing as core experience.
- Proficient with mobile, web, and API testing tools such as Burp Suite, Frida, MobSF, or equivalent tools, and SAST/DAST/SCA tools such as SonarQube, GitHub, or equivalent.
- Knowledge of authentication and authorization protocols and mobile platform security architecture.
- Ability to write clear, risk-rated technical and executive reports with proof of concept and remediation guidance.
- Working knowledge of OWASP Top 10, secure API design, authentication and authorization protocols, and secure coding standards.
Who are we looking for?
Willingness to go the extra mile for success.
A talented individual who embodies our company’s core values of teamwork, honesty, reliability, sense of humour and street smart.
Energetic and lively.
As our approach to banking is far from ordinary, we are looking for an creative and creative individual to join our team.
About Tonik:
We are a transformative digital bank with a mission to revolutionize the way money works. We create better financial products for the world by encouraging inclusivity through simplifying processes, reducing costs, improving transparency, and embracing flexibility to empower more people with unique financial needs. All these are on the most secure mobile banking platform.
To enable this, innovation is woven into the DNA of our company. We do not just search for the best talent, but for people who seek to challenge the status quo and are passionate about transforming the impossible into reality.
Tonik (www.tonikbank.com) is the first digital-only neo bank in the Philippines, providing loan, deposit, payment, and card products to consumers on a highly secure digital banking platform. The neo bank operates based on the first private digital bank license issued by the Bangko Sentral ng Pilipinas. Tonik is led by a team of retail finance veterans who have previously built and scaled multiple retail banks and fintechs across the global emerging markets.
It is backed by top international venture capital funds. Tonik operates out of hubs in Singapore (HQ), Manila, Chennai, and Kyiv.
📌 Application Security Analyst (Chennai)
🏢 Tonik
📍 Chennai