12 Sep
|
Comviva
|
Bengaluru
Job Title: Senior Security Engineer – Application Security
Job Summary We are looking for a passionate and hands-on Senior Security Engineer to join our Application Security team. The ideal candidate should have strong experience in penetration testing of Web, API, Android and iOS applications, along with good knowledge of DevSecOps, CI/CD security and AI-augmented security testing.
Key Responsibilities Perform manual and automated penetration testing of Web, API, Android and iOS applications.
Identify, validate and report security vulnerabilities and provide actionable remediation recommendations.
Perform security testing covering OWASP Top 10, OWASP API Security Top 10 and OWASP Mobile Top 10/MASVS.
Conduct advanced testing for authentication, authorization, IDOR/BOLA, business logic, injection, session management, data protection and API security.
Perform Android/iOS security testing including static/dynamic analysis, reverse engineering, SSL pinning, secure storage, WebView and runtime security testing.
Use tools such as Burp Suite, MobSF, Frida, Objection, JADX, Nmap and vulnerability scanners.
Integrate and support security tools such as SAST, DAST, SCA and vulnerability scanning within CI/CD pipelines.
Develop scripts and automation using Python, JavaScript, Bash or similar languages to improve security testing efficiency.
Leverage AI/LLM-based tools for AI-augmented security testing, including endpoint discovery, JavaScript analysis, test-case/payload generation,
response analysis and security reporting.
Participate in threat modeling, architecture reviews and secure SDLC activities using methodologies such as STRIDE/PASTA.
Collaborate with developers, architects and DevOps teams to drive vulnerability remediation and improve application security.
Mentor junior team members and contribute to improving security testing methodologies and automation.
Required Skills 3–5 years of hands-on experience in Application Security/Penetration Testing.
Strong hands-on experience in Web, API, Android and iOS security testing.
Robust knowledge of OWASP Top 10, API Security Top 10, MASVS/MSTG and common security vulnerabilities.
Hands-on expertise with Burp Suite Professional.
Good knowledge of MobSF, Frida, Objection, JADX/apktool or equivalent mobile security tools.
Good understanding of REST APIs, OAuth, JWT, HTTP/HTTPS, TLS and authentication/authorization mechanisms.
Experience with CI/CD and DevSecOps security practices.
Knowledge of SAST, DAST, SCA and vulnerability management tools.
Strong scripting/automation skills in Python, JavaScript or Bash.
Exposure to AI-powered/AI-assisted security testing tools and techniques.
Strong analytical, problem-solving and communication skills.
Preferred Qualifications Certifications such as OSCP, CEH, or equivalent.
Experience with cloud, containers and microservices security.
Knowledge of Threat Modeling, OWASP ASVS, NIST and SANS Top 25
📌 Senior Engineer (Security) (Bengaluru)
🏢 Comviva
📍 Bengaluru