03 Sep
|
Lennox India Technology Centre
|
Chennai
03 Sep
Lennox India Technology Centre
Chennai
We are seeking a highly skilled Senior Security Specialist (IC3) with 6-9 years of experience in Application Security & Penetration Testing (VAPT), and security testing methodologies. The ideal candidate should possess strong expertise in DAST, API Security Testing, Mobile Application Security Testing (MAST) , and hands-on exposure to AI-driven security testing and AI security risks . This role will work closely with development, DevOps, architecture, and product teams to identify, assess, and remediate security vulnerabilities throughout the SDLC.
Key Responsibilities
Application Security
- Perform end-to-end application security assessments for web, mobile, and API applications.
- Conduct threat modeling, secure design reviews, and architecture assessments.
- Validate security controls and identify vulnerabilities using manual and automated techniques.
- Review remediation recommendations and support development teams during vulnerability closure.
DAST (Dynamic Application Security Testing)
- Conduct DAST assessments using tools such as:
- Burp Suite Enterprise/Qualified
- Invicti (Netsparker)
- Checkmarx
- Analyze and validate findings to eliminate false positives.
- Support tuning and optimization of DAST tools.
- Develop DAST scanning standards, processes, and reporting mechanisms.
API Security
- Perform API security testing against REST, SOAP, GraphQL, and Microservices architectures.
- Validate API security controls including:
- Authentication & Authorization
- OAuth 2.0 / OIDC
- JWT Security
- Rate Limiting
- Input Validation
- API Abuse Scenarios
- Conduct testing aligned with:
- OWASP API Security Top 10
- OWASP ASVS
- OWASP Testing Guide
- Utilize tools such as:
- Postman
- Burp Suite
- OWASP ZAP
- ReadyAPI
Mobile Application Security Testing (MAST)
- Perform Android and iOS application security assessments.
- Conduct dynamic mobile application testing.
- Assess data storage, encryption, certificate pinning, and API security implementations.
- Use security tools such as:
- MobSF
- NowSecure
- Burp Suite
VAPT Activities
- Conduct vulnerability assessments and penetration tests.
- Validate exploitability and business impact of identified vulnerabilities.
- Prepare detailed technical and executive reports.
- Track remediation and support closure verification activities.
- Collaborate with development teams to reduce recurring vulnerabilities.
AI Security & Emerging Technologies
- Assess security risks associated with AI/LLM-powered applications.
- Understand and evaluate:
- Prompt Injection
- Data Leakage Risks
- Model Poisoning
- Insecure Plugin Integrations
- Excessive Agency
- Sensitive Information Disclosure
- Familiarity with:
- OWASP Top 10 for LLM Applications
- GenAI Security Best Practices
- Secure AI Development Lifecycle
- Utilize AI-assisted security testing tools to improve assessment efficiency.
Secure SDLC Integration
- Collaborate with development and DevOps teams.
- Support security gates within CI/CD pipelines.
- Participate in security reviews and release approvals.
📌 Senior Security Specialist (Chennai)
🏢 Lennox India Technology Centre
📍 Chennai