HamburgerMenu
hirist

Test Engineer - Penetration Testing & Fraud Simulation

Talentxo
5 - 7 Years
Delhi

Posted on: 15/05/2026

Job Description

Description :

Roles & Responsibilities :


- Perform end-to-end penetration testing and application security assessments across web applications, mobile applications, and APIs, with focus on transaction-intensive and procurement platforms.

- Conduct advanced business logic testing and fraud simulation exercises to identify vulnerabilities in procurement and financial workflows.

- Simulate fraud scenarios such as bid manipulation, price tampering, replay attacks, fake approvals, maker checker bypass, audit trail manipulation, and multi-account collusion.

- Perform controlled attempts to exploit functional workflows and validate enforcement of business rules, access controls, and data validation mechanisms.

- Assess and test authentication flows, session management, token security, API security, and replay attack protections.

- Identify vulnerabilities related to concurrency handling, integration failures, fail-safe mechanisms, and transaction processing logic.

- Conduct vulnerability assessments and penetration testing using tools such as Burp Suite, OWASP ZAP, Kali Linux, Metasploit, and custom attack scripts.

- Analyze security gaps and clearly articulate business impact including financial loss, unfair transaction awards, fraud exposure, and reputational risks.

- Collaborate with development, infrastructure, and product teams to support vulnerability remediation and security hardening initiatives.

- Prepare detailed security assessment reports including risk ratings, exploit evidence, remediation recommendations, and compliance observations.

- Support security audits and contribute to improving secure development and application security practices across platforms.

- Ensure adherence to enterprise security standards, compliance requirements, and best practices for secure application development.

Ideal Candidate Criteria :


- 5+ years of total experience with at least 3+ years specifically in Application Security, Penetration Testing, or Vulnerability Assessment roles.

- Strong hands-on experience performing penetration testing across web applications, mobile applications, and APIs.

- Proven expertise in business logic testing and fraud simulation scenarios including bid manipulation, price tampering, replay attacks, fake approvals, and maker-checker bypass.

- Deep understanding of e-procurement, marketplace, and financial system fraud patterns including forged bids, transaction replay, collusion, and audit trail manipulation.

- Strong expertise in authentication security, session/token management, API penetration testing, and input manipulation techniques.

- Ability to assess and communicate business impact of vulnerabilities including financial risk, operational impact, unfair deal awards, and reputational exposure.

- Proficiency with advanced security testing tools such as Burp Suite, OWASP ZAP, Kali Linux, Metasploit, and custom scripting for attack simulation.

- Strong understanding of OWASP Top 10 vulnerabilities, secure coding principles, and application security best practices.

- Experience identifying and helping remediate critical vulnerabilities in Government, PSU, procurement, or large-scale financial systems will be preferred.

- Bachelors Degree in Engineering/IT (B.Tech/BE) or MCA is mandatory.

- Mandatory certification in at least one of the following : OSCP, OSWE, CEH Practical, or CREST.

- Strong analytical, troubleshooting, reporting, and stakeholder communication skills.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...