Posted on: 15/05/2026
Description :
Roles & Responsibilities :
- Conduct advanced business logic testing and fraud simulation exercises to identify vulnerabilities in procurement and financial workflows.
- Simulate fraud scenarios such as bid manipulation, price tampering, replay attacks, fake approvals, maker checker bypass, audit trail manipulation, and multi-account collusion.
- Perform controlled attempts to exploit functional workflows and validate enforcement of business rules, access controls, and data validation mechanisms.
- Assess and test authentication flows, session management, token security, API security, and replay attack protections.
- Identify vulnerabilities related to concurrency handling, integration failures, fail-safe mechanisms, and transaction processing logic.
- Conduct vulnerability assessments and penetration testing using tools such as Burp Suite, OWASP ZAP, Kali Linux, Metasploit, and custom attack scripts.
- Analyze security gaps and clearly articulate business impact including financial loss, unfair transaction awards, fraud exposure, and reputational risks.
- Collaborate with development, infrastructure, and product teams to support vulnerability remediation and security hardening initiatives.
- Prepare detailed security assessment reports including risk ratings, exploit evidence, remediation recommendations, and compliance observations.
- Support security audits and contribute to improving secure development and application security practices across platforms.
- Ensure adherence to enterprise security standards, compliance requirements, and best practices for secure application development.
Ideal Candidate Criteria :
- Strong hands-on experience performing penetration testing across web applications, mobile applications, and APIs.
- Proven expertise in business logic testing and fraud simulation scenarios including bid manipulation, price tampering, replay attacks, fake approvals, and maker-checker bypass.
- Deep understanding of e-procurement, marketplace, and financial system fraud patterns including forged bids, transaction replay, collusion, and audit trail manipulation.
- Strong expertise in authentication security, session/token management, API penetration testing, and input manipulation techniques.
- Ability to assess and communicate business impact of vulnerabilities including financial risk, operational impact, unfair deal awards, and reputational exposure.
- Proficiency with advanced security testing tools such as Burp Suite, OWASP ZAP, Kali Linux, Metasploit, and custom scripting for attack simulation.
- Strong understanding of OWASP Top 10 vulnerabilities, secure coding principles, and application security best practices.
- Experience identifying and helping remediate critical vulnerabilities in Government, PSU, procurement, or large-scale financial systems will be preferred.
- Bachelors Degree in Engineering/IT (B.Tech/BE) or MCA is mandatory.
- Mandatory certification in at least one of the following : OSCP, OSWE, CEH Practical, or CREST.
- Strong analytical, troubleshooting, reporting, and stakeholder communication skills.
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
QA & Testing
Job Code
1636358