17 Aug
|
Suzva Software Technologies
|
Mumbai
17 Aug
Suzva Software Technologies
Mumbai
Role summary
We are looking for an experienced Application Penetration Tester to join our security team. You will perform hands-on security assessments of web, mobile, API, and cloud-hosted applications to identify vulnerabilities, exploitability, and business impact.
You will work with engineering teams to validate issues, recommend mitigations, and help raise the overall security posture through secure-by-design advice, threat modeling, and security testing automation.
Key responsibilities
Plan and execute manual and automated penetration tests for web applications, REST/GraphQL APIs, mobile apps (iOS/Android), and serverless/cloud functions.
Perform authenticated and unauthenticated testing, business logic testing, and privilege escalation scenarios.
Exploit vulnerabilities to demonstrate risk (secure, controlled exploitation) and produce transparent proof-of-concept (PoC).
Produce high-quality,
actionable vulnerability reports with risk rating, reproduction steps, impact assessment, and remediation guidance.
Work closely with development, DevOps, and product teams to triage, validate fixes, and re-test vulnerabilities.
Integrate security testing into CI/CD pipelines and champion test automation (SAST/DAST/IAST) where appropriate.
Conduct code reviews / secure code walkthroughs (as needed) focusing on language/frameworks used by engineering teams.
Run threat modelling workshops, design reviews, and security architecture consultations for recent features.
Maintain knowledge of current attack techniques, CVEs, exploit frameworks and recommend defensive controls.
Contribute to internal tooling, playbooks, and run periodic red-team / purple-team exercises.
📌 Application Penetration Tester Mumbai
🏢 Suzva Software Technologies
📍 Mumbai