Job Summary
The opportunity: Consultant-National-Forensics-ASU - Forensics - Investigations & Compliance - Gurgaon.
Responsibilities
- Job Role Description: Offensive Security and Application Security Analyst A professional in this role will assist in identifying, exploiting, validating and helping remediate security weaknesses in applications, infrastructure, and cloud environments. The job blends ethical hacking, secure development practices, threat modelling, and vulnerability and penetration testing. The candidate should be able to:
- Identify vulnerabilities in application, network, mobile app and databases.
- Accurately assess real world exploitability and business impact.
- Deliver clear, concise, actionable remediation guidance.
- Build strong relationships with clients.
- Automate repetitive tasks (integrate scanners, scripts, tooling).
- Contribute to overall reduction of critical/high vulnerabilities for client.
- Execute application security and DevSecOps engagements, supporting clients in identifying, assessing, and mitigating application security risks.
- Perform application security assessments across web, mobile, APIs, cloud-native applications, and supporting infrastructure.
- Conduct AppSec and DevSecOps maturity assessments using frameworks such as OWASP SAMM, NIST SSDF, and BSIMM, and document improvement opportunities.
- Identify security gaps within the SDLC and provide practical recommendations to enhance application security posture.
- Support the implementation and integration of security controls within CI/CD pipelines, including SAST, SCA, DAST, secrets scanning, IaC scanning, and container security.
- Perform secure code reviews, vulnerability validation,
and remediation verification across multiple technology stacks.
- Assist clients in adopting secure development practices and embedding security requirements throughout the software development lifecycle.
- Communicate technical findings, risks, and remediation guidance to client stakeholders in clear and actionable terms.
- Support threat modeling activities, attack surface reviews, and security architecture assessments.
- Contribute to security automation initiatives, including tool integrations, reporting workflows, dashboards, and process improvements.
- Collaborate with development, DevOps, cloud, and security teams to address identified vulnerabilities and security gaps.
- Assist in the development of security standards, secure coding guidelines, and AppSec best practices.
- Prepare technical reports, presentations, and client deliverables while ensuring quality and consistency.
- Support proposal development, solution demonstrations, and other business development activities when required.
- Contribute to the development of reusable security tools, scripts, accelerators, and assessment methodologies.
- Support AI/GenAI security assessments, including LLM threat modeling, prompt security reviews, secure integration assessments, and AI risk evaluations.
Required Skills & Competencies
- Strong understanding of:
Web technologies (HTTP, sessions, authentication); API security (OAuth2, JWT, rate limiting); OWASP Top 10 & OWASP API Top 10; Authentication/Authorization patterns; Secure cloud architecture (AWS/Azure/GCP)
- Ability to exploit: XSS, SQLi, IDOR, SSRF, RCE, CSRF; Deserialization, logic flaws; Permission & role escalation weaknesses
Experience & Qualifications
- 25 years of experience in security testing, penetration testing, or application security.
- Bachelor's degree in CS/IT/Cybersecurity (or equivalent experience).
- Preferred certifications (not mandatory, but highly valued): OSCP (Offensive Security Certified Professional) o Burp Suite Certified Practitioner (BSCP) o GWAPT (GIAC Web Application Penetration Tester) o CPTS (Certified Penetration Testing Specialist)
- Hands-on penetration testing and Red Teaming experience is more key than certifications.
- Clear communication of vulnerabilities and business impact along with strong analytical and problem solving skills.
Skills and attributes To qualify for the role you must have
- Bachelor of Technology in Computer Science
Experience
- Frontend Development (2+ years)
What we look for
People with the ability to work in a collaborative manner to provide services across multiple client departments while following the commercial and legal requirements. You will need a practical approach to solving issues and complex problems with the ability to deliver insightful and practical solutions. We look for people who are agile, curious, mindful, and able to sustain positive energy, while being adaptable and creative in their approach.
📌 Forensics Consultant (Gurugram)
🏢 EY
📍 Gurugram