30 Sep
|
Krazy Bee Services
|
Bengaluru
30 Sep
Krazy Bee Services
Bengaluru
About the Role
We are looking for a Security Engineer focused on Application Security to join our Cyber Security team. You will be responsible for identifying and preventing security vulnerabilities across our web and mobile applications, working closely with development teams to embed security into the software development lifecycle.
Key Responsibilities
- Internal VAPT: Conduct vulnerability assessments and penetration testing on web applications, APIs, and internal tools. Identify, categorise, and report vulnerabilities with transparent remediation guidance.
- Threat Modelling: Perform threat modelling for new features and architectural changes before development begins. Identify attack surfaces, data flows, and trust boundaries.
- Secure SDLC (S-SDLC): Embed security checkpoints into the SDLC participate in design reviews, define security requirements, and ensure security sign-offs before production release.
- Security Requirements: Define and document security requirements for new features. Work with product and engineering teams to ensure these are addressed before go-live.
- Pre-release Threat Assessment: Evaluate upcoming features for potential security threats. Proactively identify risks and provide risk-based recommendations to development teams.
- Web Application Security: Deep understanding of OWASP Top 10, common web vulnerabilities (XSS, SQLi, SSRF, IDOR, authentication flaws), and hands-on penetration testing of web applications.
- Mobile Security (Android & iOS): Perform security assessments on Android and iOS applications static and dynamic analysis, reverse engineering, insecure storage, and API communication security.
- SAST Triage & Validation: Triage and validate findings from static analysis tools (Semgrep, GitHub Advanced Security). Work with developers to remediate confirmed issues.
- API Security Testing: Assess REST and HTTP APIs for authentication, authorisation, injection, and business logic vulnerabilities.
- Secure Code Review: Conduct manual code reviews for security-critical modules authentication flows, payment processing, data handling, and access control logic.
- Developer Collaboration: Act as a security point-of-contact for feature teams. Provide clear, actionable feedback and support developers in understanding and fixing security issues.
- Security Documentation: Maintain internal VAPT reports, vulnerability trackers, and security requirement documents.
Required Skills & Qualifications 2 - 4 years of experience in application security, penetration testing, or a related cybersecurity role.
Strong knowledge of OWASP Top 10 and common web application vulnerabilities.
Hands-on experience with web application penetration testing tools Burp Suite, OWASP ZAP, or equivalent.
Solid understanding of mobile application security (Android and/or iOS).
Familiarity with at least one SAST tool Semgrep, GHAS, SonarQube, or equivalent.
Understanding of secure coding principles and common vulnerability patterns.
Knowledge of authentication and authorisation mechanisms (OAuth, JWT, session management).
Good communication skills ability to document findings clearly and explain security risks to developers.
Proficiency in at least one programming language (Python, Java, JavaScript, or Go).
📌 Security Engineer - AppSec (Bengaluru)
🏢 Krazy Bee Services
📍 Bengaluru