A global professional services network and part of the Big Four, along with Client, EY, and KPMG, operating across 149 countries worldwide.
Essential Job Functions:
- Perform Static Application Security Testing (SAST), Agile Application Security Testing (DAST), and Software Composition Analysis (SCA) using approved security tools.
- Validate vulnerabilities identified by automated scanners and eliminate false positives.
- Understand and assess common web application vulnerabilities based on the OWASP Top 10.
- Review security findings and provide remediation recommendations to development teams.
- Support secure code review activities under guidance from senior AppSec engineers.
- Assist in API security assessments.
- Participate in vulnerability management by tracking findings until closure.
- Perform basic threat moClienting and security design reviews.
- Support security testing during SDLC and CI/CD pipelines.
- Prepare security assessment reports and maintain documentation.
- Coordinate with development teams to validate remediation.
Qualifications:
Good understanding of:
- OWASP Top 10
- Secure SDLC
- HTTP/HTTPS
- REST APIs
- Authentication & Authorization (OAuth, JWT, SAML - basic understanding)
- SQL Injection, XSS, CSRF, SSRF, XXE, IDOR
- Familiarity with at least one programming language:
- Java
- Python
- JavaScript
- C#
- Basic understanding of Linux and networking.
- Knowledge of Git and CI/CD concepts is desirable.
- Security Tools
- Exposure to one or more of:
- Burp Suite
- OWASP ZAP
- SonarQube
- Checkmarx
- Fortify
- Veracode
- GitHub Advanced Security (preferred)
Soft Skills
- Strong analytical and troubleshooting skills
- Good communication and documentation skills
- Ability to work with developers and security teams
- Willingness to learn
📌 Appsec (Mumbai)
🏢 VARITE
📍 Mumbai
Reply to this offer
Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.