SENIOR ENGINEER - Penetration Testing (Bengaluru)

SENIOR ENGINEER - Penetration Testing (Bengaluru)

19 Aug
|
Happiest Minds Technologies
|
Bengaluru

19 Aug

Happiest Minds Technologies

Bengaluru

Job Code

14845

Mandatory Skills

Web Application Penetration Testing,Vulnerability Management

Experience

3 to 5 Years

Location

Bengaluru

We are looking to hire a Security Engineer with 3 - 5 years of relevant experience. The primary focus of this role will be Application Security, including Web Penetration Testing, DAST, and SAST. The secondary focus will be Vulnerability Management for infrastructure assets.

The ideal candidate should have strong hands-on experience in identifying, validating, and helping remediate security issues in web applications and supporting infrastructure. The role requires close collaboration with engineering, DevOps, and infrastructure teams to improve the security posture of the product and environment.

Education Qualificaiton

Bachelor's degree

Open Positions

1

Job Title

Senior Security Engineer ?

Application

Security

Roles & Responsibilities

Application Security

- Perform security reviews of web applications, APIs, and related services.
- Conduct manual and automated web application penetration testing.
- Configure, run, and tune DAST tools and workflows.
- Support SAST integration into CI/CD pipelines and help developers interpret findings.
- Work with engineering teams to validate vulnerabilities, reduce false positives, and track remediation.
- Review application architecture, authentication, authorization, session management, input validation, and common OWASP issues.
- Help define and improve secure coding and application security practices.

Vulnerability Management
- Support vulnerability management for infrastructure assets,



including servers, endpoints, containers, and cloud workloads.
- Triage, prioritize, and track remediation of infrastructure vulnerabilities based on risk and business impact.
- Work with platform, DevOps, and IT teams to close findings within agreed SLAs.
- Analyze vulnerability trends and report metrics to stakeholders.
- Assist in improving vulnerability scanning coverage, alert quality, and remediation workflows.

Cross-Functional Security Work
- Partner closely with product engineering, DevOps, and operations teams to build security into delivery pipelines.
- Support security exceptions/risk acceptance processes where necessary.
- Contribute to security standards, playbooks, and internal documentation.
- Help improve the overall security posture of the project/product area.

What We Are Looking For
- 3 - 5 years of experience in Application Security, Product Security, or a closely related role.
- Strong understanding of web application security and common vulnerabilities.
- Hands-on experience with manual web penetration testing.
- Practical experience with DAST and SAST tools and workflows.
- Working knowledge of Vulnerability Management for infrastructure.




- Familiarity with OWASP Top 10, secure SDLC, and remediation guidance.
- Ability to clearly communicate technical issues to developers and non-security stakeholders.
- Comfortable working in a quick-moving engineering environment.

Good to Have
- Experience with APIs, cloud security, or container security.
- Exposure to CI/CD pipelines and DevSecOps practices.
- Familiarity with tools such as Burp Suite, ZAP, Checkmarx, Veracode, SonarQube, Tenable, Qualys, Rapid7, or similar.
- Knowledge of scripting or automation using Python, Bash, or similar.
- Experience with Jira, ServiceNow, or similar tracking systems.

Qualifications

- Bachelor?s degree in Computer Science, Information Security, or equivalent practical experience.
- Relevant security certifications are a plus, but not mandatory.

Success in This Role Looks Like
- Security findings are identified early and remediated effectively.
- Vulnerability backlog is well-triaged and aging is reduced.
- Development teams receive actionable, high-quality security guidance.
- Security checks are integrated into the delivery process without slowing teams down unnecessarily.

Type of Employment

Contract

Project Details

Vulnerability Management Operations Project holds responsibility of managing the complete vulnerability management program which aims in securing Applications and Infrastructures.

Project Duration

NA

Shift Timings

14:00 to 23:00 IST

Vulnerability Assessment,Application Security,Penetration Testing

📌 SENIOR ENGINEER - Penetration Testing (Bengaluru)
🏢 Happiest Minds Technologies
📍 Bengaluru

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior engineer - penetration testing (bengaluru) / bengaluru

Subscribe to this job alert:

Get the latest job offers by email for: senior engineer - penetration testing (bengaluru) / bengaluru