Application Security Tester (Web, Mobile & API) – BFSI Domain
Experience: 1–2 Years
Location: Thane Ghodbunder Road(Onsite)
Domain: BFSI (Banking / Financial Services / Insurance)
Role Overview
We are looking for a motivated Application Security Tester with 1–2 years of hands-on experience in Web, Mobile, and API Security Testing, preferably within the BFSI domain. The candidate should have strong fundamentals in application security testing methodologies and vulnerability assessment aligned with industry standards.
Key Responsibilities
- Perform Web Application Security Testing using industry-standard methodologies such as OWASP Top 10
- Conduct Mobile Application Security Testing (Android/iOS – basic to intermediate level)
- Perform API Security Testing using tools like Postman and Burp Suite
- Identify vulnerabilities such as:
- Authentication & authorization issues
- Injection flaws
- Sensitive data exposure
- Business logic issues
- Validate vulnerabilities and perform retesting after fixes
- Prepare detailed vulnerability assessment reports
- Support client queries and remediation validation
- Follow secure testing practices aligned with BFSI expectations
Required Skills
Mandatory:
- Hands-on experience in Web Application Security Testing
- Basic experience in Mobile App Security Testing
- Understanding of API Security Testing concepts
- Familiarity with:
- Burp Suite
- MobSF
- OWASP ZAP
- Knowledge of:
- OWASP Top 10
- Basic secure coding issues
- Authentication & session management vulnerabilities
Good to Have:
- Exposure to BFSI applications
- Understanding of API authentication (JWT / OAuth basics)
- Experience with runtime testing tools like Frida or Objection
- Certification (any one preferred):
- eWPT
- eMAPT
- CEH (Practical exposure preferred over theory)
Qualification
- Bachelor’s Degree in Computer Science / IT / Cybersecurity or equivalent
- Strong understanding of application security fundamentals
Soft Skills
- Good report writing skills
- Ability to communicate vulnerabilities clearly
- Willingness to learn BFSI security expectations
- Ability to work in a structured testing environment