19 Aug
|
Happiest Minds Technologies
|
Bengaluru
19 Aug
Happiest Minds Technologies
Bengaluru
Job Code
14845
Mandatory Skills
Web Application Penetration Testing,Vulnerability Management
Experience
3 to 5 Years
Location
Bengaluru
We are looking to hire a Security Engineer with 3 - 5 years of relevant experience. The primary focus of this role will be Application Security, including Web Penetration Testing, DAST, and SAST. The secondary focus will be Vulnerability Management for infrastructure assets.
The ideal candidate should have strong hands-on experience in identifying, validating, and helping remediate security issues in web applications and supporting infrastructure. The role requires close collaboration with engineering, DevOps, and infrastructure teams to improve the security posture of the product and environment.
Education Qualificaiton
Bachelor's degree
Open Positions
1
Job Title
Senior Security Engineer ?
Application
Security
Roles & Responsibilities
Application Security
- Perform security reviews of web applications, APIs, and related services.
- Conduct manual and automated web application penetration testing.
- Configure, run, and tune DAST tools and workflows.
- Support SAST integration into CI/CD pipelines and help developers interpret findings.
- Work with engineering teams to validate vulnerabilities, reduce false positives, and track remediation.
- Review application architecture, authentication, authorization, session management, input validation, and common OWASP issues.
- Help define and improve secure coding and application security practices.
Vulnerability Management
- Support vulnerability management for infrastructure assets,
including servers, endpoints, containers, and cloud workloads.
- Triage, prioritize, and track remediation of infrastructure vulnerabilities based on risk and business impact.
- Work with platform, DevOps, and IT teams to close findings within agreed SLAs.
- Analyze vulnerability trends and report metrics to stakeholders.
- Assist in improving vulnerability scanning coverage, alert quality, and remediation workflows.
Cross-Functional Security Work
- Partner closely with product engineering, DevOps, and operations teams to build security into delivery pipelines.
- Support security exceptions/risk acceptance processes where necessary.
- Contribute to security standards, playbooks, and internal documentation.
- Help improve the overall security posture of the project/product area.
What We Are Looking For
- 3 - 5 years of experience in Application Security, Product Security, or a closely related role.
- Strong understanding of web application security and common vulnerabilities.
- Hands-on experience with manual web penetration testing.
- Practical experience with DAST and SAST tools and workflows.
- Working knowledge of Vulnerability Management for infrastructure.
- Familiarity with OWASP Top 10, secure SDLC, and remediation guidance.
- Ability to clearly communicate technical issues to developers and non-security stakeholders.
- Comfortable working in a quick-moving engineering environment.
Good to Have
- Experience with APIs, cloud security, or container security.
- Exposure to CI/CD pipelines and DevSecOps practices.
- Familiarity with tools such as Burp Suite, ZAP, Checkmarx, Veracode, SonarQube, Tenable, Qualys, Rapid7, or similar.
- Knowledge of scripting or automation using Python, Bash, or similar.
- Experience with Jira, ServiceNow, or similar tracking systems.
Qualifications
- Bachelor?s degree in Computer Science, Information Security, or equivalent practical experience.
- Relevant security certifications are a plus, but not mandatory.
Success in This Role Looks Like
- Security findings are identified early and remediated effectively.
- Vulnerability backlog is well-triaged and aging is reduced.
- Development teams receive actionable, high-quality security guidance.
- Security checks are integrated into the delivery process without slowing teams down unnecessarily.
Type of Employment
Contract
Project Details
Vulnerability Management Operations Project holds responsibility of managing the complete vulnerability management program which aims in securing Applications and Infrastructures.
Project Duration
NA
Shift Timings
14:00 to 23:00 IST
Vulnerability Assessment,Application Security,Penetration Testing
📌 SENIOR ENGINEER - Penetration Testing (Bengaluru)
🏢 Happiest Minds Technologies
📍 Bengaluru