Company: Cysigil
Location: Bengaluru, India — On-site
Employment type: Full time
Experience: 2 years +
Function: Offensive Security / Vulnerability Assessment & Penetration Testing
Reports to: Lead Security Consultant — VAPT
About the role
Cysigil delivers vulnerability assessment and penetration testing engagements across web applications, APIs, networks, mobile apps and cloud environments for clients in BFSI, healthcare, SaaS and manufacturing.
We are hiring an Associate Security Analyst (L2) to join the VAPT practice. This is a hands-on, delivery-facing role.
Role Summary
Perform static application security testing and manual secure code reviews across web, API, and mobile codebases. Triage SAST tool output, determine exploitability, and deliver developer-ready remediation guidance.
Key Responsibilities
• Conduct manual secure code reviews focused on authentication, authorization, input validation, cryptography, session management, and data exposure
• Run and triage SAST scans using Checkmarx One, SonarQube, Semgrep, Snyk Code, or Fortify
• Analyze data flow from source to sink to confirm exploitability and eliminate false positives
• Perform SCA reviews of third-party dependencies and assess reachability of known CVEs
• Map findings to CWE and OWASP Top 10 / OWASP API Security Top 10 with justified severity
• Detect hardcoded secrets, credentials, and insecure configuration in source and IaC files
• Write findings with vulnerable code snippet, exploit scenario, and secure code fix example
• Support SAST integration into CI/CD pipelines (Jenkins, GitLab CI, GitHub Actions, Azure DevOps) and help define quality gates
• Work with development teams on remediation, verification, and closure rationale
• Contribute to custom rule/query tuning to reduce noise
Required Skills
• Ability to read and reason about code in at least two of: Java, C#, Python, JavaScript/TypeScript, PHP, Go, Kotlin/Swift
• Understanding of common vulnerability classes at the code level: SQLi, XSS, SSRF, IDOR, insecure deserialization, path traversal, XXE, command injection, race conditions
• Familiarity with framework-specific security controls (Spring Security, Django, Express, .NET, Laravel)
• Working knowledge of at least one SAST platform and its triage workflow
• Understanding of CWE taxonomy, CVSS scoring, and secure SDLC principles
• Comfortable with Git and code review platforms
Good to have
Cryptography fundamentals. CTF placements. CEH, eJPT, Security+. A HackTheBox or TryHackMe profile. Bug bounty acknowledgements. CVEs.
Apply
CV to
[email protected],
subject "Associate Security Analyst (L2) — VAPT". Attach a write-up, a profile, a disclosure — anything you've done. We read that before the CV.
📌 Assosiate Security Analyst (Bengaluru)
🏢 Cysigil
📍 Bengaluru