Application Security Engineer
Role Overview
We are looking for an Application Security Engineer with strong hands-on experience in application security testing, vulnerability assessment, and secure SDLC practices across web, mobile, APIs, and LLM applications.
Key Responsibilities
- Conduct security assessments, penetration testing, and vulnerability analysis for web, mobile, APIs, and LLM applications.
- Actively perform hands-on pentesting/exploitation for web, mobile, API, and LLM applications.
- Perform Android security testing, including reverse engineering and static/energetic analysis.
- Assess API/microservices security, authentication, authorization, and data protection.
- Identify, triage, and support remediation of application vulnerabilities.
- Integrate security controls into CI/CD and DevSecOps processes.
- Provide secure coding guidance and security training to developers.
- Develop security automation/tools and document technical findings and risks.
- Stay updated on emerging application security threats.
Required Skills
- 57 years of experience in Application Security, Penetration Testing, or Secure Software Development.
- Strong knowledge of OWASP Top 10 (Web, Mobile, API) and common vulnerabilities.
- Hands-on expertise with Burp Suite/ZAP, MobSF, Frida, Postman, etc.
- Strong experience in web, mobile, and API security testing.
- Experience with LLM/AI application security testing is preferred.
- Programming knowledge in Java, Python, JavaScript, or Go.
- Understanding of DevSecOps and CI/CD.
Preferred
- Certifications: OSWE, OSCP, CEH, GWAPT, CSSLP.
- Exposure to Cloud (AWS/Azure/GCP) and Container Security (Docker/Kubernetes).
- Strong communication and collaboration skills.
📌 Application Security (Delhi)
🏢 Airtel
📍 Delhi