Job Description Job Title: Application Security Analyst
nLocation: DLF Cybercity, Porur, Chennai- India
nExperience: 4 - 8 Years
n
n About the Job:
nWe are looking for an Application Security Analyst who will ensure that mobile and web applications are developed, deployed, and maintained based on security standards and best practices to protect the organization from potential threats and vulnerabilities. This role will work closely with development, network security, and technology teams to embed security throughout the software development lifecycle.
n
n Job Responsibilities:
n
n Mobile and Web Application Penetration Testing
nPerform static and agile analysis of Android and iOS applications to uncover insecure data storage, weak cryptography, SSL pinning/root detection bypass, and other mobile application risks.
nTest anti-tampering and device binding controls such as RASP, root/jailbreak detection, device attestation, and biometric authentication implementation.
nConduct web application penetration testing against the OWASP Top 10, including injection,
broken authentication/session management, and access control vulnerabilities, across customer and internal-facing web portals.
nDocument findings with risk ratings, proof of concept, and remediation recommendations, and perform retesting through closure.
n
n API Security Testing
nConduct API penetration testing on internal and externally exposed APIs using the OWASP API Security Top 10 as the baseline methodology.
nTest authentication and session handling, mTLS enforcement, token replay/reuse scenarios, and authorization controls.
nEvaluate rate limiting, throttling, and anti-automation controls against brute force, credential stuffing, and enumeration attacks on customer-facing APIs.
nReview API Gateway and WAF rule effectiveness against attack payloads and coordinate with the Network Security team on ruleset fine-tuning.
n
n Secure SDLC and Application Security Governance
nEmbed security c
📌 Application Security Analyst (Chennai)
🏢 Tonik
📍 Chennai