Role Overview

We are looking for an experienced Application Security Tester with 3–6 years of hands-on experience in Web, Mobile, API Security Testing and Secure Code Review (SCR). Experience in BFSI, UPI/payment applications and security compliance will be preferred.
The candidate should have strong technical skills along with exposure to team coordination, client interaction and audit support.

Key Responsibilities

  • Perform Web Application Security Testing based on OWASP Top 10 and industry-standard methodologies.
  • Conduct Mobile Application Security Testing for Android/iOS.
  • Perform API Security Testing using Burp Suite, Postman, OWASP ZAP, etc.
  • Conduct Secure Code Review (SCR) and identify insecure coding practices.
  • Identify and validate vulnerabilities related to authentication, authorization, access control, injection, session management, sensitive data, business logic and API security.
  • Perform vulnerability retesting and remediation validation.
  • Prepare detailed VAPT/security assessment reports with evidence, impact and remediation recommendations.
  • Perform/support security testing of UPI/payment applications, including API security, transaction flows, authentication, authorization and business logic.
  • Support PCI-DSS and other security audits with VAPT reports, evidence, remediation and retest documentation.
  • Coordinate with development/application teams for vulnerability remediation and closure.
  • Handle client queries and participate in security review meetings.

Team Handling & Coordination

  • Coordinate day-to-day activities of junior security testers.
  • Allocate testing tasks and track assessment deliverables and timelines.
  • Review vulnerability findings and reports for quality and technical accuracy.
  • Mentor junior team members on application security testing and vulnerability validation.
  • Coordinate with project managers, developers, application owners and client stakeholders.
  • Support multiple security assessments and track remediation/closure.

Audit & Compliance Support

  • Support PCI-DSS audits/assessments and client security compliance requirements.
  • Prepare audit evidence including VAPT reports, scope, methodology, findings, remediation and retest results.
  • Coordinate with auditors and stakeholders for security testing-related queries.
  • Maintain assessment documentation and evidence for audit readiness.

Required Skills

  • 3–6 years of hands-on Application Security / VAPT experience.
  • Strong experience in Web, API and Mobile Security Testing.
  • Hands-on experience in Secure Code Review.
  • Strong knowledge of OWASP Top 10 and application security fundamentals.
  • Understanding of JWT, OAuth, API authentication/authorization and business logic vulnerabilities.
  • Hands-on experience with Burp Suite, Postman, MobSF and OWASP ZAP.
  • Exposure to Frida / Objection is an advantage.
  • BFSI, UPI/payment application and PCI-DSS exposure preferred.
  • Good technical report writing, communication and stakeholder management skills.
  • Team coordination/mentoring experience preferred.

Certifications – Preferred

  • eWPT / eMAPT
  • CEH
  • OSCP / OSWE
  • CREST or equivalent
Practical hands-on experience will be preferred over certification alone.

Qualification

  • Bachelor's degree in Computer Science / IT / Cybersecurity or equivalent.
  • Strong analytical, communication and documentation skills.
  • Ability to work in a structured, compliance-driven BFSI environment.