Senior Code Auditor - Application Security & Code Review (Pune)

Senior Code Auditor - Application Security & Code Review (Pune)

13 Sep
|
Dhanode Technologies
|
Pune

13 Sep

Dhanode Technologies

Pune

SENIOR CODE AUDITOR — APPLICATION SECURITY & CODE REVIEW

Experience: 6+ years

Salary: ₹1,25,000+ per month (based on skill and experience)

Location: 515, Gera Imperium Rise, Opposite Wipro, Hinjewadi Phase 2, Pune

Type: Full time, on-site

ABOUT US

We build and run software that handles real money and real client data — a SaaS platform, client platforms we maintain, and a mobile app, across Laravel, MySQL/PostgreSQL and Ubuntu servers. Security here isn't a checkbox exercise — production systems have faced real attack attempts, and we take that seriously.

THE ROLE

This role owns security code review across our codebases — not a one-time audit, an ongoing practice. You go through the code the way an attacker would, not the way a linter would: authentication, authorisation, business logic around money and credits, API security, dependency risk, the works. If something is exploitable, we need to know before someone else finds it first.

WHAT YOU WILL DO

- Run deep security code reviews across our Laravel/PHP codebases — injection, auth, authorisation/IDOR, XSS, CSRF, file upload, SSRF, deserialisation, and everything in between
- Pay special attention to business-logic flaws — anything touching money, balances, credits or payments, since that's where real damage happens, not just in the obvious places
- Review API security, secrets management, dependency risk, and configuration/deployment across our Hostinger and DigitalOcean-hosted servers
- Review the Flutter mobile app's security posture, not just the backend
- Document every finding properly — file, location, plain explanation, exploit path, real impact, and a working fix, not a vague suggestion
- Set priorities by how easily an attacker could actually use the flaw, not textbook severity ratings
- Work across multiple live projects, keeping context straight on each one instead of treating every review the same
- Build repeatable review processes and checklists so security isn't only as good as whoever's paying attention that week




- Advise on hardening — auth/session handling, secrets, server and web-server config, database security, rate limiting, logging and monitoring
- Be honest in every report — never call something secure that hasn't actually been verified

WHAT WE ARE LOOKING FOR
- 6+ years in application security or security-focused senior development — real production experience, not a certification-only profile
- Deep, hands-on knowledge of the OWASP-class vulnerability set — injection, auth/authz, XSS, CSRF, SSRF, deserialisation, IDOR — and how each actually gets exploited, not just defined
- Real experience with PHP/Laravel security specifically; comfortable across MySQL and PostgreSQL
- Understands financial/transaction-system security — balances, credits, payment flows — where a logic bug is as dangerous as an injection flaw
- Has investigated a real breach or incident before, not only performed scheduled audits
- Comfortable working from a short brief and figuring out the rest — this is not a role where every step gets spelled out
- Can write a finding a non-technical founder can understand, and a fix a developer can paste in and ship
- Discreet — what you find in this code does not leave this room

BONUS POINTS
- Experience securing crypto, wallet or payment-gateway integrations specifically
- Experience with Flutter/mobile app security
- Familiarity with Cloudflare WAF and server-side hardening on Ubuntu/Linux
- Prior incident-response or digital-forensics experience

WHAT THIS ROLE IS NOT
- Not a QA or code-style review job — this is security, not linting
- Not a one-time audit and done — this is ongoing, across live projects
- Not a role for someone who needs constant direction — you're expected to know the job

HOW TO APPLY

Send us

1. Resume
2. Current salary, expected salary, notice period
3. A 3-4 line write-up of one real vulnerability you found and fixed — what it was, how it could've been exploited, and what you did (no client names or confidential details, just the technical story)

Pay: ₹70,000.00 - ₹100,000.00 per year

Work Location: In person

📌 Senior Code Auditor - Application Security & Code Review (Pune)
🏢 Dhanode Technologies
📍 Pune

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior code auditor - application security & code review (pune) / pune