Web application security Professional (Chennai)

Web application security Professional (Chennai)

01 Oct
|
Novalnet e-Solutions
|
Chennai

01 Oct

Novalnet e-Solutions

Chennai

Job Summary

We are looking for a motivated and enthusiastic Security Analyst (Penetration Testing/VAPT) with 0 2 years of experience to join our Information Security team. The ideal candidate will perform web application, API, network, and mobile application security assessments for payment applications and infrastructure. The role involves identifying and validating security vulnerabilities, providing remediation recommendations, supporting PCI DSS compliance activities, and contributing to the continuous improvement of the organization s security posture.

Domain: Payment Gateway / Payment Institution / Payment Service Provider (PSP)

Preferred Certifications

- eJPT

- CEH (Certified Ethical Hacker)

- CompTIA Security+

- Any other relevant cerificates

Preferred Experience

- Internship or academic project in penetration testing or vulnerability assessment.

- Participation in Capture the Flag (CTF) competitions, Hack The Box, TryHackMe or PortSwigger Web Security Academy is an added advantage.

Roles and Responsibilities

- Perform security assessments of payment applications, APIs, and supporting infrastructure.

- Perform Web Application Penetration Testing (WAPT) and API Security Testing.

- Conduct Network Vulnerability Assessments and basic Penetration Testing (VAPT).

- Identify, validate, and document security vulnerabilities with transparent proof of concept and remediation recommendations.

- Validate security controls implemented for payment processing systems.

- Develop, maintain, and execute Python scripts for security testing, vulnerability validation, API testing, automation, and other penetration testing activities.

- Test payment workflows, transaction processing, and payment-related APIs for security weaknesses.





- Perform security testing of payment integrations, including third-party APIs, payment interfaces, and transaction flows.

- Assess and validate security controls protecting cardholder data in alignment with PCI DSS requirements.

- Support PCI DSS compliance activities and security validation exercises, where applicable.

- Perform manual security testing based on the OWASP Top 10 and other industry best practices.

- Prepare detailed technical and executive security assessment reports, documenting identified vulnerabilities, risk ratings, proof of concept, and remediation recommendations.

- Verify remediation fixes and perform retesting.

- Research emerging threats, vulnerabilities, and attack techniques to continuously improve security testing methodologies.

Skills and Experience

- Understanding of common security risks affecting payment applications and APIs.

- Good understanding of payment security concepts, including PCI DSS requirements and secure payment processing.

- Good understanding of Web Application Security concepts.

- Strong ability to write and use Python scripts for security testing, vulnerability validation, automation, API testing, and security assessment activities.

- Strong knowledge of the OWASP Top 10.

- Understanding of the OWASP API Security Top 10.

- Basic understanding of API security concepts and common API vulnerabilities.





- Knowledge of authentication and authorization mechanisms used in payment systems, including OAuth, JWT, and MFA.

- Familiarity with networking concepts, including TCP/IP, DNS, HTTP, HTTPS, and SSL/TLS.

- Good understanding of common web application vulnerabilities, including SQL Injection, XSS, CSRF, SSRF, IDOR, authentication and authorization flaws, file upload vulnerabilities, security misconfigurations, and business logic vulnerabilities.

- Good understanding of Linux and Windows operating systems.

- Strong report-writing and communication skills.

- Exposure to Mobile Application Security Testing.

- Knowledge of secure HTTP headers, cookies, sessions, and JWT security.

- Basic understanding of cryptographic concepts, including encryption, hashing, digital certificates, and TLS/SSL.

- Familiarity with RESTful APIs and JSON.

- Basic knowledge of Active Directory security.

- Basic understanding of cloud security concepts, including (AWS, Azure, and GCP).

Hands-On Experience

- Burp Suite

- Tenable Nessus

- Owasp ZAP

- Nmap

- Nikto

- Postman

- Nuclei

- Wireshark

- Metasploit

- SQLMap

- Python

- Bash (preferred)

Soft Skills

- Strong analytical and problem-solving skills.

- Good written and verbal communication.

- Ability to work independently and collaboratively.

- Willingness to learn new technologies and security methodologies.

- Good time management and documentation skills.

Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.

📌 Web application security Professional (Chennai)
🏢 Novalnet e-Solutions
📍 Chennai

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: web application security professional (chennai) / chennai

Subscribe to this job alert:

Get the latest job offers by email for: web application security professional (chennai) / chennai