Key Responsibilities
• Lead and manage a team of security testers across multiple projects.
• Define and implement security testing strategies for Web, Mobile, APIs, and MCP-based applications.
• Perform and oversee security assessments including: • MCP Security Testing
• Web Application Penetration Testing
• Mobile Application Security Testing (Android & iOS)
• API Security Testing
• Secure Code Review
• Threat Modeling
• Review MCP architecture, connector integrations, tool invocation mechanisms, and AI-agent interactions for security risks.
• Identify vulnerabilities related to: • Prompt Injection
• Tool Poisoning
• Unauthorized Tool Access
• Data Leakage
• Excessive Permissions
• Authentication & Authorization Flaws
• Insecure Context Sharing
• AI Agent Abuse Scenarios
• Conduct security reviews for AI/LLM-enabled applications and MCP ecosystems.
• Provide remediation recommendations and work closely with development and architecture teams.
• Prepare security assessment reports and executive-level risk summaries.
• Participate in customer discussions, audits,
and security governance meetings.
• Mentor and guide junior security testers and security engineers.
Required Skills
MCP & AI Security
• Strong hands-on experience in MCP (Model Context Protocol) Security Testing.
• Understanding of MCP architecture, MCP servers, clients, tools, prompts, and resources.
• Experience identifying AI and MCP-specific security risks.
• Experience testing AI Agents, Copilot solutions, Agentic workflows, RAG systems, and LLM integrations.
• Knowledge of OWASP Top 10 for LLM Applications and AI Security best practices.
Application Security
• Web Application Security Testing.
• Mobile Application Security Testing (Android/iOS).
• API Security Testing.
• Secure Code Review.
• Threat Modeling and Risk Assessment.
• Authentication, Authorization, SSO, OAuth2, OpenID Connect, SAML.
Security Tools
• Burp Suite Enterprise/Qualified.
• OWASP ZAP.
• MobSF. Appknox
• Snyk, Checkmarx,
📌 Senior Security Lead (Pune)
🏢 Zensar
📍 Pune