HamburgerMenu
hirist

Application Security Engineer/Penetration Tester

Talentxo
5 - 7 Years
Delhi

Posted on: 01/05/2026

Job Description

Job Summary :


We are looking for a skilled Application Security Engineer / Penetration Tester with strong expertise in business logic testing, fraud simulation, and vulnerability assessment across web, mobile, and API-based platforms. The ideal candidate will have experience securing transaction-heavy systems such as e procurement or financial platforms and identifying high-impact vulnerabilities.

Key Responsibilities :


- Perform penetration testing and vulnerability assessments across web applications, mobile apps, and APIs, focusing on high-volume transaction systems.

- Conduct business logic testing and fraud simulation, including scenarios like bid manipulation, price tampering, replay attacks, fake approvals, and maker-checker bypass.

- Execute controlled attack simulations to validate business rules, access controls, data validations, and system behavior under failure scenarios (errors, concurrency, integration issues).

- Identify and help remediate critical vulnerabilities, especially in Government/PSU or large-scale procurement/financial systems.

- Test and secure authentication mechanisms, session/token management, API endpoints, and input validation.

- Analyze and simulate e-procurement fraud patterns such as bid rigging, multi-account collusion, forged bids, transaction replay, and audit trail manipulation.

- Use advanced security tools like Burp Suite, OWASP ZAP, Kali Linux, Metasploit, along with custom scripts for attack simulation.

- Clearly document vulnerabilities and articulate business impact (financial loss, unfair deal awards, reputational risks).

- Collaborate with development and product teams to ensure secure design, remediation, and compliance.

Mandatory Skills & Experience :


- 5+ years of total experience, with minimum 3 years in Penetration Testing / Application Security.

- Strong hands-on expertise in business logic testing and fraud simulation.

- Proficiency in security testing tools : Burp Suite, OWASP ZAP, Kali Linux, Metasploit.

- Strong knowledge of authentication, session/token security, API security, and input manipulation techniques.

- Experience in identifying vulnerabilities with clear business impact assessment.

- Bachelors degree in Engineering/IT (B.Tech/BE) or MCA.

- At least one certification: OSCP / OSWE / CEH Practical / CREST.

Preferred Qualifications :


- Experience working on Government/PSU or high-scale procurement/financial systems.

- Deep understanding of e-procurement or marketplace fraud patterns.

- Strong analytical and problem-solving skills.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...