04 Sep
|
Lennox India Technology Centre
|
Chennai
04 Sep
Lennox India Technology Centre
Chennai
Job Description
We are seeking a highly skilled Senior Security Specialist (IC3) with 6-9 years of experience in Application Security & Penetration Testing (VAPT), and security testing methodologies. The ideal candidate should possess solid expertise in DAST, API Security Testing, Mobile Application Security Testing (MAST) , and hands-on exposure to AI-driven security testing and AI security risks . This role will work closely with development, DevOps, architecture, and product teams to identify, assess, and remediate security vulnerabilities throughout the SDLC.
n
Key Responsibilities
n
Application Security
n
n
- Perform end-to-end application security assessments for web, mobile, and API applications.
n
- Conduct threat modeling, secure design reviews, and architecture assessments.
n
- Validate security controls and identify vulnerabilities using manual and automated techniques.
n
- Review remediation recommendations and support development teams during vulnerability closure.
n
n
DAST (Dynamic Application Security Testing)
n
n
- Conduct DAST assessments using tools such as:
n
- Burp Suite Enterprise/Professional
n
- Invicti (Netsparker)
n
- Checkmarx
n
- Analyze and validate findings to eliminate false positives.
n
- Support tuning and optimization of DAST tools.
n
- Develop DAST scanning standards, processes, and reporting mechanisms.
n
n
API Security
n
n
- Perform API security testing against REST, SOAP, GraphQL, and Microservices architectures.
n
- Validate API security controls including:
n
- Authentication & Authorization
n
- OAuth 2.0 / OIDC
n
- JWT Security
n
- Rate Limiting
n
- Input Validation
n
- API Abuse Scenarios
n
- Conduct testing aligned with:
n
- OWASP API Security Top 10
n
- OWASP ASVS
n
- OWASP Testing Guide
n
- Utilize tools such as:
n
- Postman
n
- Burp Suite
n
- OWASP ZAP
n
- ReadyAPI
n
n
Mobile Application Security Testing (MAST)
n
n
- Perform Android and iOS application security assessments.
n
- Conduct dynamic mobile application testing.
n
- Assess data storage, encryption, certificate pinning, and API security implementations.
n
- Use security tools such as:
n
- MobSF
n
- NowSecure
n
- Burp Suite
n
n
VAPT Activities
n
n
- Conduct vulnerability assessments and penetration tests.
n
- Validate exploitability and business impact of identified vulnerabilities.
n
- Prepare detailed technical and executive reports.
n
- Track remediation and support closure verification activities.
n
- Collaborate with development teams to reduce recurring vulnerabilities.
n
n
AI Security & Emerging Technologies
n
n
- Assess security risks associated with AI/LLM-powered applications.
n
- Understand and evaluate:
n
- Prompt Injection
n
- Data Leakage Risks
n
- Model Poisoning
n
- Insecure Plugin Integrations
n
- Excessive Agency
n
- Sensitive Information Disclosure
n
- Familiarity with:
n
- OWASP Top 10 for LLM Applications
n
- GenAI Security Best Practices
n
- Secure AI Development Lifecycle
n
- Utilize AI-assisted security testing tools to improve assessment efficiency.
n
n
Secure SDLC Integration
n
n
- Collaborate with development and DevOps teams.
n
- Support security gates within CI/CD pipelines.
n
- Participate in security reviews and release approvals.
n
n
📌 Senior Security Specialist (Chennai)
🏢 Lennox India Technology Centre
📍 Chennai