13 Sep
|
Dhanode Technologies
|
Pune
13 Sep
Dhanode Technologies
Pune
SENIOR CODE AUDITOR — APPLICATION SECURITY & CODE REVIEW
Experience: 6+ years
Salary: ₹1,25,000+ per month (based on skill and experience)
Location: 515, Gera Imperium Rise, Opposite Wipro, Hinjewadi Phase 2, Pune
Type: Full time, on-site
ABOUT US
We build and run software that handles real money and real client data — a SaaS platform, client platforms we maintain, and a mobile app, across Laravel, MySQL/PostgreSQL and Ubuntu servers. Security here isn't a checkbox exercise — production systems have faced real attack attempts, and we take that seriously.
THE ROLE
This role owns security code review across our codebases — not a one-time audit, an ongoing practice. You go through the code the way an attacker would, not the way a linter would: authentication, authorisation, business logic around money and credits, API security, dependency risk, the works. If something is exploitable, we need to know before someone else finds it first.
WHAT YOU WILL DO
- Run deep security code reviews across our Laravel/PHP codebases — injection, auth, authorisation/IDOR, XSS, CSRF, file upload, SSRF, deserialisation, and everything in between
- Pay special attention to business-logic flaws — anything touching money, balances, credits or payments, since that's where real damage happens, not just in the obvious places
- Review API security, secrets management, dependency risk, and configuration/deployment across our Hostinger and DigitalOcean-hosted servers
- Review the Flutter mobile app's security posture, not just the backend
- Document every finding properly — file, location, plain explanation, exploit path, real impact, and a working fix, not a vague suggestion
- Set priorities by how easily an attacker could actually use the flaw, not textbook severity ratings
- Work across multiple live projects, keeping context straight on each one instead of treating every review the same
- Build repeatable review processes and checklists so security isn't only as good as whoever's paying attention that week
- Advise on hardening — auth/session handling, secrets, server and web-server config, database security, rate limiting, logging and monitoring
- Be honest in every report — never call something secure that hasn't actually been verified
WHAT WE ARE LOOKING FOR
- 6+ years in application security or security-focused senior development — real production experience, not a certification-only profile
- Deep, hands-on knowledge of the OWASP-class vulnerability set — injection, auth/authz, XSS, CSRF, SSRF, deserialisation, IDOR — and how each actually gets exploited, not just defined
- Real experience with PHP/Laravel security specifically; comfortable across MySQL and PostgreSQL
- Understands financial/transaction-system security — balances, credits, payment flows — where a logic bug is as dangerous as an injection flaw
- Has investigated a real breach or incident before, not only performed scheduled audits
- Comfortable working from a short brief and figuring out the rest — this is not a role where every step gets spelled out
- Can write a finding a non-technical founder can understand, and a fix a developer can paste in and ship
- Discreet — what you find in this code does not leave this room
BONUS POINTS
- Experience securing crypto, wallet or payment-gateway integrations specifically
- Experience with Flutter/mobile app security
- Familiarity with Cloudflare WAF and server-side hardening on Ubuntu/Linux
- Prior incident-response or digital-forensics experience
WHAT THIS ROLE IS NOT
- Not a QA or code-style review job — this is security, not linting
- Not a one-time audit and done — this is ongoing, across live projects
- Not a role for someone who needs constant direction — you're expected to know the job
HOW TO APPLY
Send us
1. Resume
2. Current salary, expected salary, notice period
3. A 3-4 line write-up of one real vulnerability you found and fixed — what it was, how it could've been exploited, and what you did (no client names or confidential details, just the technical story)
Pay: ₹70,000.00 - ₹100,000.00 per year
Work Location: In person
📌 Senior Code Auditor - Application Security & Code Review (Pune)
🏢 Dhanode Technologies
📍 Pune