02 Oct
|
Comviva
|
Bengaluru
Key Responsibilities
Penetration Testing &
- Vulnerability Assessment
- Perform manual and automated penetration testing of Web, API, Android, and iOS applications.
- Identify, validate, and report security vulnerabilities with actionable remediation recommendations.
- Conduct security testing covering OWASP Top 10, OWASP API Security Top 10, and OWASP Mobile Top 10 / MASVS.
- Perform advanced testing across authentication, authorization, IDOR/BOLA, business logic, injection, session management, data protection, and API security.
Mobile Security Testing
- Conduct Android and iOS security testing including static and dynamic analysis, reverse engineering, SSL pinning bypass, secure storage, WebView, and runtime security testing.
- Use tools such as MobSF, Frida, Objection, and JADX/apktool.
Tooling &
- DevSecOps
- Use Burp Suite, Nmap, and vulnerability scanners as part of routine assessment work.
- Integrate and support SAST, DAST, SCA, and vulnerability scanning within CI/CD pipelines.
- Develop scripts and automation using Python, JavaScript, Bash, or similar to improve testing efficiency.
AI-Augmented Security Testing
- Leverage AI/LLM-based tools for endpoint discovery, JavaScript analysis, test-case and payload generation, response analysis, and security reporting.
Secure SDLC &
- Collaboration
- Participate in threat modeling, architecture reviews, and secure SDLC activities using methodologies such as STRIDE and PASTA.
- Collaborate with developers, architects,
and DevOps teams to drive vulnerability remediation and improve overall application security posture.
Mentoring &
- Continuous Improvement
- Mentor junior team members.
- Contribute to improving security testing methodologies and automation frameworks.
Required Skills Technical —
- Mandatory
- 3–5 years of hands-on experience in application security / penetration testing.
- Strong hands-on experience across Web, API, Android, and iOS security testing.
- Solid knowledge of OWASP Top 10, OWASP API Security Top 10, MASVS/MSTG, and common vulnerability classes.
- Hands-on expertise with Burp Suite Professional.
- Working knowledge of MobSF, Frida, Objection, JADX/apktool, or equivalent mobile security tools.
- Solid understanding of REST APIs, OAuth, JWT, HTTP/HTTPS, TLS, and authentication/authorization mechanisms.
- Experience with CI/CD and DevSecOps security practices.
- Knowledge of SAST, DAST, SCA, and vulnerability management tools.
- Strong scripting and automation skills in Python, JavaScript, or Bash.
- Exposure to AI-powered / AI-assisted security testing tools and techniques.
Behavioural
- Strong analytical and problem-solving skills.
- Clear written and verbal communication, particularly for reporting findings to technical and non-technical audiences.
- Collaborative approach across development, architecture, and operations teams.
Preferred Qualifications
- Certifications such as OSCP, CEH, or equivalent.
- Experience with cloud, container, and microservices security.
- Knowledge of threat modeling, OWASP ASVS, NIST frameworks, and SANS Top 25.
📌 Senior Engineer (Security) (Bengaluru)
🏢 Comviva
📍 Bengaluru