Posted on: 07/04/2026
Description :
- Perform end-to-end penetration testing and application security assessments across web portals, mobile apps, and APIs, especially for transaction-heavy procurement or financial platforms.
Conduct business logic testing and fraud simulation to identify vulnerabilities in critical workflows such as :
a. Bid manipulation
b. Price tampering
c. Replay attacks
d. Fake approvals
e. Maker-checker bypass
f. Multi-account collusion
- Execute controlled attack simulations to test misuse of functional flows, validate business rules enforcement, access controls, session handling, and data validation mechanisms.
- Assess authentication, authorization, session/token security, and API-level vulnerabilities, including replay, injection, input tampering, and privilege escalation scenarios.
- Identify weaknesses in error handling, concurrency controls, integration failure safeguards, and audit trail integrity to ensure secure fail-safe behavior.
- Simulate procurement and marketplace fraud scenarios to uncover potential risks such as forged bids, unfair deal awards, transaction replay, and audit log manipulation.
- Use advanced tools such as Burp Suite, OWASP ZAP, Kali Linux, Metasploit, along with custom scripts for exploit and fraud simulation.
Clearly document findings with technical details, proof of concept, severity ratings, remediation guidance, and business impact including :
1. Financial loss
2. Reputational damage
3. Compliance risk
4. Unfair vendor advantage
- Collaborate with engineering and product teams to support remediation, retesting, and security hardening of high-risk vulnerabilities.
- Contribute to strengthening secure SDLC and application security best practices for large-scale Government/PSU or enterprise procurement ecosystems.
Ideal Candidate :
- Strong Application Security / Penetration Testing
- Mandatory ( Total Experience ) : Must have 5+ years of total experience, out of which minimum 3 years should be specifically in Penetration Testing / Vulnerability Assessment.
- Mandatory (Experience 2) : Must have strong hands-on experience in business logic testing and fraud simulation, including scenarios such as bid manipulation, price tampering, replay attacks, fake approvals, and maker-checker bypass.
- Mandatory (Skills 1) : Proficiency in advanced security testing tools such as Burp Suite, OWASP ZAP, Kali Linux, Metasploit, and ability to perform custom attack scripting.
- Mandatory (Skills 2) : Strong expertise in authentication, session/token security, API penetration, input manipulation, and fraud simulation, with the ability to highlight the business impact of each exploit (financial loss, unfair deal awards, reputational risk)
- Mandatory (Education) : Bachelors in Engineering/IT (B.Tech/BE) or MCA.
- Mandatory (Certification) : At least one advanced security credential : OSCP, OSWE, CEH Practical, or CREST.
- Preferred : Proven track record of identifying and helping remediate critical vulnerabilities in at least one Government/PSU or equivalent high-scale procurement/financial system.
Did you find something suspicious?
Posted by
Posted in
Quality Assurance
Functional Area
Cyber Security
Job Code
1626690