24 Sep
|
Sonata Software
|
Maharashtra
24 Sep
Sonata Software
Maharashtra
Security Engineer (VAPT and Remediation)
Location: Pune (Hybrid)
Experience: 5+ years
Availability: 0-15 days
About the role
This is a hands-on security engineering role that owns the full cycle: find the vulnerability, prove it, fix it, and confirm it stays fixed. You will run penetration tests and security reviews across our applications and infrastructure, then remediate what you find, in application code or in configuration, whatever the fix requires.
What you will do
Security Analysis and Testing
- Plan and execute penetration tests on web applications, APIs, mobile apps (iOS and Android), thick clients, and supporting infrastructure.
- Review application and infrastructure security design: authentication and authorization, session handling, data flows, secrets management, network exposure, and cloud configuration.
- Find what scanners miss through manual testing: business logic flaws, chained vulnerabilities, and privilege escalation paths.
- Run and tune vulnerability scans across applications, hosts, and cloud accounts.
- Triage, deduplicate, and prioritize findings by exploitability and business impact alongside CVSS.
- Track remediation to closure and maintain an accurate view of open risk.
- Retest fixes and close findings only when the vulnerability is confirmed resolved.
Remediation and patching
- Fix vulnerabilities directly in application code, in whatever language or framework the application uses.
- Fix infrastructure and configuration issues: web server and TLS settings, cloud IAM and network rules, container and Kubernetes configuration, infrastructure-as-code, and CI/CD pipeline hardening.
- Apply patches and upgrades to operating systems, frameworks, libraries, and third-party components, and verify the exposure is closed.
- Where code or infrastructure is owned by another team, raise the change yourself as a pull request or configuration change and drive it to merge.
Reporting and communication
- Write transparent findings with reproduction steps, evidence, risk rating, and specific remediation guidance.
- Explain risk to developers, DevOps engineers, and non-technical stakeholders, and agree on realistic remediation timelines.
What you bring
Experience
- 5+ years in penetration testing, application security, or security engineering, with a track record of fixing the vulnerabilities you report.
Deep VAPT expertise
- Web: manual testing with Burp Suite Professional; OWASP Top 10 and ASVS; injection, authentication and session flaws, access control (IDOR/BOLA), SSRF, deserialization, XXE, race conditions, and business logic abuse.
- API: REST, GraphQL, SOAP, and gRPC; OAuth 2.0, OpenID Connect, and JWT weaknesses; mass assignment, rate limiting, and object-level authorization failures.
- Mobile (iOS and Android): static and dynamic analysis against OWASP MASVS/MASTG; Frida, Objection, MobSF, jadx, and Ghidra or Hopper; SSL pinning and root/jailbreak detection bypass; insecure storage, IPC, and deep link issues.
- Thick client: interception of non-HTTP protocols, reverse engineering of .NET, Java, and native binaries, memory and local storage analysis, DLL hijacking, and client-side trust issues.
- Infrastructure: network and host testing with Nmap, Nessus, and Metasploit; Active Directory fundamentals; Linux and Windows hardening.
Remediation skills
- Able to read and modify code in multiple languages. Expect a mix that may include Java,
C#/.NET, JavaScript/TypeScript, Python, PHP, Go, Swift, and Kotlin. Depth in at least two of these, and the ability to land a correct, tested fix in an unfamiliar codebase.
- Scripting in Python, Bash, or PowerShell to automate testing and remediation.
- Practical experience with Git-based workflows, pull requests, and code review.
- Working knowledge of Nginx, Apache, IIS, TLS configuration, Docker, Kubernetes, and infrastructure-as-code such as Terraform or CloudFormation.
Working knowledge (fundamentals level)
- Cloud security: IAM, networking, storage, logging, and encryption across AWS, Azure, and GCP; CIS benchmarks; CSPM and cloud audit tooling such as Prowler.
- Vulnerability assessment: enterprise scanners, CVSS, and patch management processes.
- SOC operations: SIEM concepts, log analysis, incident response fundamentals, and MITRE ATT&CK; able to support incident triage with attacker-perspective input and feed detection ideas back from test findings.
Communication
- Clear written reports and the ability to explain risk and trade-offs to engineers and business stakeholders.
Nice to have
- Public security research, CVEs, bug bounty findings, or CTF experience.
- Experience integrating SAST, DAST, and SCA tooling such as Aikido into CI/CD pipelines.
- Threat modeling and secure design review experience.
- Familiarity with compliance evidence requirements (ISO 27001, SOC 2, PCI DSS) as they relate to vulnerability remediation.
What success looks like
- Findings from your tests reach confirmed, retested fixes within agreed timelines.
- Development and DevOps teams see you as someone who fixes problems alongside them.
- Recurring vulnerability classes decline over time because fixes address root causes.
- Cloud misconfiguration and patch exposure windows stay short.
📌 Security Engineer (Maharashtra)
🏢 Sonata Software
📍 Maharashtra