Location: Vadodara, Gujarat
Work Mode: Full-Time | Work From Office
Experience: 2+ Years
About the Role
We are looking for an Application Security / VAPT Engineer to perform hands-on security testing of Web Applications and APIs and identify vulnerabilities, security gaps and business-logic loopholes.
Key Responsibilities
- Perform manual & automated VAPT of Web Applications and APIs.
- Identify vulnerabilities such as OWASP Top 10, IDOR/BOLA, XSS, SQL Injection, CSRF, Broken Access Control and API security issues.
- Test authentication, authorization, sessions, APIs and business logic.
- Perform security testing beyond automated scanners.
- Document vulnerabilities with impact, evidence, severity and remediation.
- Work with developers on root-cause analysis, fixes and security retesting.
Requirements
- 2+ years in Application Security, VAPT or Penetration Testing.
- Strong knowledge of Web & API Security / OWASP Top 10.
- Hands-on with Burp Suite, OWASP ZAP, Postman, Nmap or similar tools.
- Understanding of HTTP/HTTPS, REST APIs, JSON, tokens, cookies and SQL.
- Strong analytical and attacker mindset.
Preferred
- .NET / C# / ASP.NET / MVC / Web API experience.
- Software developers who have transitioned into Application Security / VAPT are encouraged to apply.
- Robust experience in manual Web/API and business-logic testing.