27 Aug
|
Tinycrows Private
|
Mumbai
27 Aug
Tinycrows Private
Mumbai
Position: Information Security Consultant Location : Navi Mumbai, India
Shift Timings: Tinycrows Private Limited is a budding cybersecurity firm working with BFSI, fintech, and technology-driven enterprises dedicated to helping these businesses protect their digital assets and mitigate risks. At Tinycrows, we follow a 'shift left' cybersecurity approach to fortify the security of products. Our team of trusted professionals, with experience from top consulting firms like Microsoft and Deloitte, design robust security solutions for various industries. We have a proven track record of implementing cybersecurity best practices for startups and large organizations, ensuring digital assets remain secure in today's threat landscape.
Tinycrows has designed this role for a highly motivated and technically adept individual with strong expertise in Threat Intelligence, Web and Mobile (iOS/Android) Application Penetration Testing . This role requires analysing, designing and implementing robust security to help the stakeholders maintain and strengthen their security posture. Exposure to Red Team operations , Active Directory attack paths , and cloud environments is a strong plus. The Consultant will work closely with clients to ensure the security of their digital assets.
Execute in-depth security assessments and Manual penetration testing of web and mobile applications.
JavaScript, Java/Kotlin, Swift, Python).
Contribute to the automation and enhancement of internal testing frameworks , reporting tools, and reusable AppSec methodologies.
Leverage tools such as Burp Suite Pro, nmap, slmap, MobSF, Frida, Objection, Jadx, APKTool, and others as part of testing workflows.
Collaborate cross-functionally with developers, DevOps, and product teams to embed security across the SDLC.
Transfer of residual risks to the business/customer as required by the Client’s risk management framework.
Collaboration with stakeholder and IT teams to support incident response and investigations using their knowledge of the technology systems sharing security insights.
Deliver detailed technical findings and clear, actionable remediation guidance to both technical and non-technical stakeholders.
Practical experience in web and mobile application security testing, including real-world vulnerability exploitation and security implementation.
Understanding of threat intelligence concepts, threat actor landscape, TTPs, IOCs, and their application in identifying and assessing cybersecurity risks.
Basic experience with cloud security reviews, particularly for AWS, Azure, or GCP-hosted environments.
Excellent written and verbal communication skills along with the ability to work independently and remotely
Formal Cyber Security qualification e.g. Experience developing custom scripts or payloads using Python , Bash , or PowerShell .
Familiarity with SAST/DAST tools and API security testing methodologies.
You learn by doing, not just following manuals and your work directly shapes the company’s success and culture. You get exposure to latest technologies, regulatory frameworks, and client-facing challenges. You get more autonomy, creativity, and ownership of projects, apart from this you also get:
Chance to be part of the core founding team and contribute to building security from the ground up.
Fast-paced, agile environment where innovation and curiosity are encouraged.
Collaborative team culture with support for skill-building and certifications.
Therefore, working days, hours and holidays will be defined by the client.
It enables us to leverage different ways of thinking, ideas and perspectives, and bring more creativity and innovation to help solve our clients’ most complex challenges.
📌 Information Security Risk Consultant (Mumbai)
🏢 Tinycrows Private
📍 Mumbai