A global professional services network and part of the Big Four, along with Client, EY, and KPMG, operating across 149 countries worldwide.
Essential Job Functions:
Perform Static Application Security Testing (SAST), Agile Application Security Testing (DAST), and Software Composition Analysis (SCA) using approved security tools.
Validate vulnerabilities identified by automated scanners and eliminate false positives.
Understand and assess common web application vulnerabilities based on the OWASP Top 10.
Review security findings and provide remediation recommendations to development teams.
Support secure code review activities under guidance from senior AppSec engineers.
Assist in API security assessments.
Participate in vulnerability management by tracking findings until closure.
Perform basic threat moClienting and security design reviews.
Support security testing during SDLC and CI/CD pipelines.
Prepare security assessment reports and maintain documentation.
Coordinate with development teams to validate remediation.
Qualifications:
Positive understanding of:
OWASP Top 10
Secure SDLC
HTTP/HTTPS
REST APIs
Authentication & Authorization (OAuth, JWT, SAML - basic understanding)
SQL Injection, XSS, CSRF, SSRF, XXE, IDOR
Familiarity with at least one programming language:
Java
Python
JavaScript
C#
Basic understanding of Linux and networking.
Knowledge of Git and CI/CD concepts is desirable.
Security Tools
Exposure to one or more of:
Burp Suite
OWASP ZAP
SonarQube
Checkmarx
Fortify
Veracode
GitHub Advanced Security (preferred)
Soft Skills
Robust analytical and troubleshooting skills
Good communication and documentation skills
Ability to work with developers and security teams
Willingness to learn
📌 Appsec Mumbai
🏢 VARITE
📍 Mumbai
Reply to this offer
Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.