Security Tester – Web / API / FinTech (Surat)

Security Tester – Web / API / FinTech (Surat)

24 Sep
|
Andromedatech
|
Surat

24 Sep

Andromedatech

Surat

Security Tester – Web / API / FinTech

Experience: 3+ Years Preferred

Job Type: Full-Time

Department: Information Security / Application Security

Industry: FinTech / Crypto Exchange / Trading Technology

Job Summary

We are looking for a skilled Security Tester – Web / API / FinTech to perform hands-on security assessments of authenticated web applications, APIs, administrative systems, and financial transaction workflows.

This is not a scanner-only security testing role.

The successful candidate must be able to manually investigate vulnerabilities involving authorization, authentication, MFA, sessions, administrative privilege boundaries, withdrawals, transaction controls, race conditions, replay/idempotency, and financial business logic.

You should be capable of safely demonstrating security issues, explaining their business impact, assigning appropriate severity, recommending remediation, and performing retesting after fixes.

Assessments should be structured using OWASP Web Security Testing Guide (WSTG) and OWASP Application Security Verification Standard (ASVS).

Key Responsibilities

- Conduct security assessments of authenticated web applications and APIs.
- Perform manual testing in addition to automated security scanning.
- Test authentication, authorization, access controls, and privilege boundaries.
- Assess MFA implementation, session management, token handling, session expiration, logout behavior, and account recovery flows.
- Test horizontal and vertical authorization boundaries between normal users, privileged users, support users, and administrators.
- Assess sensitive financial workflows including withdrawals, transfers, wallet operations, account changes, and approval mechanisms.
- Identify potential financial and transactional business-logic vulnerabilities.
- Test APIs for improper authorization, authentication weaknesses, input-handling issues, and security-control failures.
- Assess race-condition scenarios affecting sensitive or financial operations.
- Validate replay protection and idempotency controls for transaction-related requests.
- Safely assess systems for duplicate transaction or double-spend-type business-logic scenarios within authorized testing environments.
- Evaluate rate limits and other abuse-prevention controls where applicable.
- Review administrative functionality and privilege separation.
- Validate security controls protecting high-risk account and financial actions.
- Document vulnerabilities with clear and safe proof of concept.
- Assign severity based on technical and business impact.
- Provide practical remediation recommendations.
- Retest vulnerabilities after remediation and document their final status.
- Work closely with engineering, QA, DevOps,



and product teams throughout remediation.

Must-Have Skills
- Solid hands-on Web Application Security Testing experience.
- Strong API Security Testing experience.
- Experience testing authenticated applications, not only public-facing endpoints.
- Strong understanding of authentication and authorization vulnerabilities.
- Experience assessing MFA and session security.
- Understanding of role-based access control and administrative privilege boundaries.
- Ability to identify and test complex business-logic vulnerabilities.
- Understanding of race conditions, replay attacks, and idempotency controls.
- Ability to assess transaction and financial workflows safely.
- Experience with HTTP requests, API requests, cookies, tokens, headers, sessions, and authentication mechanisms.
- Ability to manually validate findings instead of relying entirely on automated scanners.
- Strong security reporting and technical communication skills.

Security Areas You Should Understand Candidates should be comfortable assessing areas including:

Authentication • Authorization • MFA • Session Management • API Security • Access Control • IDOR/BOLA • Privilege Escalation • Admin Boundaries • Business Logic • Withdrawal Controls • Transaction Security • Race Conditions • Replay Protection • Idempotency • Financial Abuse Scenarios

Knowledge of common web and API vulnerability classes, including the OWASP Top 10 and OWASP API security risks, is expected.

FinTech / Exchange Security

Experience with FinTech, cryptocurrency exchanges, wallets, trading platforms, banking, payment gateways, or other transaction-heavy applications is highly preferred.

You should understand that a financially sensitive application requires testing beyond conventional vulnerability scanning.

For example, assessments may require determining whether:

- A user can access another user's protected resources.
- Privileged/admin actions are properly restricted.
- MFA is consistently enforced on sensitive actions.
- Sessions and tokens are securely managed.
- Withdrawal controls cannot be improperly bypassed.
- Transaction requests are protected against unintended replay.
- Duplicate requests are safely handled.
- Concurrent requests cannot cause unintended financial state changes.
- Wallet, balance, and transaction controls remain consistent under edge cases.





All testing must be performed only within explicitly authorized scope and environments.

Assessment Frameworks

Candidates must be comfortable using:

OWASP Web Security Testing Guide (WSTG)

OWASP Application Security Verification Standard (ASVS)

The ability to map findings and testing coverage against established security requirements is important.

Security Reporting Requirements

Every confirmed security finding should include:

Finding Title → Affected Component → Preconditions → Reproduction Steps → Secure Proof of Concept → Evidence → Technical Impact → Business/Financial Impact → Severity → Remediation Recommendation → Retest Result

Reports must be clear enough for engineering teams to reproduce and remediate the issue without unnecessary ambiguity.

Preferred Tools & Knowledge

Experience with tools and technologies such as:

- Burp Suite
- Postman or equivalent API clients
- Browser Developer Tools
- API documentation/testing tools
- HTTP interception proxies
- CLI tools
- JWT and token analysis
- SQL fundamentals
- Security testing utilities

Tools are important, but manual reasoning and business-logic testing ability are essential for this position.

Preferred Background

Candidates with previous security assessment experience involving any of the following are particularly relevant:

Crypto Exchanges • Digital Asset Wallets • Trading Platforms • Banking Applications • Payment Gateways • FinTech Platforms • Financial APIs

What We Are Looking For

We want a security tester who goes beyond asking:

“Did the scanner find a vulnerability?”

You should also be able to investigate:

“Can this user perform an action they are not authorized to perform?”

“Can a sensitive transaction be submitted twice?”

“What happens when two authorized requests reach the system concurrently?”

“Are withdrawal and administrative controls enforced consistently across both the UI and API?”

“Does the server enforce the security rule, or is it enforced only by the client?”

If you have strong manual Web/API security testing skills and understand the additional risks involved in financial transaction systems, we would like to hear from you.

Application Requirement

Please include

- Total security testing experience
- Web application security testing experience
- API security testing experience
- FinTech/exchange/payment/wallet experience, if applicable
- Security testing tools you regularly use
- Experience with OWASP WSTG and/or ASVS
- An anonymized example of a complex business-logic vulnerability you have previously identified, if permitted

Pay: ₹20,000.00 - ₹30,000.00 per month

Work Location: In person

📌 Security Tester – Web / API / FinTech (Surat)
🏢 Andromedatech
📍 Surat

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: security tester – web / api / fintech (surat) / surat

Subscribe to this job alert:

Get the latest job offers by email for: security tester – web / api / fintech (surat) / surat