HamburgerMenu
hirist

Application Security Engineer

Thinkaloud Consulting Private Limited
5 - 10 Years
Shillong

Posted on: 24/07/2026

Job Description

We are looking for a highly skilled Application Security Engineer to strengthen our cybersecurity posture by identifying, validating, and mitigating security vulnerabilities across applications, infrastructure, APIs, and enterprise systems. The ideal candidate should possess strong hands-on experience in Vulnerability Assessment and Penetration Testing (VAPT), secure application testing, and security compliance.


You will work closely with development, DevSecOps, infrastructure, and security teams to ensure applications and systems remain resilient against evolving cyber threats.

This role offers an opportunity to work on enterprise-scale banking applications while contributing to secure software development practices and regulatory compliance initiatives.

Key Responsibilities :

- Perform end-to-end Vulnerability Assessment and Penetration Testing (VAPT) for web applications, mobile applications, APIs, cloud-hosted applications, and enterprise infrastructure.

- Conduct authenticated and unauthenticated vulnerability assessments using industry-standard security tools.

- Execute manual penetration testing to validate automated scan findings and identify complex business logic vulnerabilities.

- Assess web applications against the latest OWASP Top 10, API Security Top 10, and common security weaknesses.

- Perform network penetration testing across internal and external network environments.

- Conduct infrastructure security assessments covering Windows, Linux, Active Directory, databases, network devices, firewalls, VPNs, and cloud environments.

- Identify security vulnerabilities including SQL Injection, Cross-Site Scripting (XSS), CSRF, SSRF, Authentication Bypass, Privilege Escalation, Remote Code Execution (RCE), Command Injection, Directory Traversal, and Insecure Deserialization.

- Evaluate application authentication mechanisms, authorization controls, session management, encryption implementation, and secure communication protocols.

- Perform API security testing covering REST, SOAP, GraphQL, OAuth, JWT, and token-based authentication mechanisms.

- Conduct mobile application security assessments for Android and iOS applications.

- Execute source code security reviews to identify insecure coding practices and recommend secure coding improvements.

- Collaborate with software development teams during Secure SDLC implementation and DevSecOps initiatives.

- Prepare comprehensive VAPT reports containing executive summaries, technical findings, business impact, proof of concept, CVSS scoring, risk ratings, and remediation recommendations.

- Validate remediation efforts by conducting retesting activities and provide closure reports for resolved vulnerabilities.

- Support vulnerability management lifecycle including identification, prioritization, remediation tracking, and risk acceptance processes.

- Assist security teams in incident investigations related to application vulnerabilities.

- Maintain testing methodologies, penetration testing playbooks, security documentation, and standard operating procedures.

- Perform security configuration reviews for web servers, application servers, middleware, and databases.

- Support compliance assessments related to ISO 27001, PCI DSS, RBI Cyber Security Guidelines, NIST, CIS Controls, and regulatory security requirements.

- Work closely with DevOps, Infrastructure, Cloud, and Product Engineering teams to integrate security into development pipelines.

- Stay updated with emerging cyber threats, zero-day vulnerabilities, exploit techniques, and industry best practices.

- Participate in internal security awareness initiatives and contribute to improving organizational security maturity.

Required Qualifications :

- B.E. / B.Tech in Computer Science, Information Technology, Cyber Security, Electronics, or a related discipline.

- Relevant cybersecurity certifications are highly preferred :

1. CEH (Certified Ethical Hacker)

2. OSCP (Offensive Security Certified Professional)

3. eJPT / eCPPT

4. GWAPT

5. Security+

6. CREST Certifications (Preferred)

Experience :

- 5+ years of experience in Application Security, VAPT, or Penetration Testing.

- Hands-on experience conducting security assessments for enterprise web applications, APIs, mobile applications, and network infrastructure.

- Experience working in Banking, Financial Services, FinTech, or highly regulated industries will be an advantage.

- Strong understanding of secure software development practices and vulnerability remediation.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...