Posted on: 31/07/2025
Position : Web Application Security Consultant
Experience : 4 + Years
Locations : Bangalore, Pune
NP : Immediate
Position Type : Contractual
Roles & responsibilities :
- Perform automated testing of running applications and static code (SAST, DAST).
- Perform manual application penetration tests on one or more of the following to discover and exploit vulnerabilities : web applications, internal applications, APIs, internal and external networks, and mobile applications
- Experience in one or more of the following is a plus : mobile application testing, Web application pen testing, application architecture, and business logic analysis.
- Need to work on application tools to perform security tests : AppScan, NetsSparker, Acunetix, Checkmarx, Veracode, BurpSuite, OWASP ZAP, and Kali Linux.
- Able to explain IDOR, Second Order SQL Injection, CSRF Vulnerability, Root cause, Remediation
Mandatory technical & functional skills :
- Minimum three (3) years of recent experience working with application tools to perform security tests : AppScan, NetsSparker, Acunetix, Checkmarx, Veracode, BurpSuite, OWASP ZAP, Kali Linux, or equivalent.
- Minimum three (3) years of performing manual penetration testing and code review against web apps, mobile apps, and APIs
- Minimum three (3) years of working with technical and non-technical audiences in reporting results and lead remediation conversations.
- Preferred one year of experience in the development of web applications and/or APIs.
- Should be able to identify and work with new tools/technologies to plug and play on client projects as needed to solve the problem at hand.
- One or more major ethical hacking certifications not required but preferred : GWAPT, CREST, OSCP, OSWE, OSWA
Did you find something suspicious?
Posted By
Posted in
CyberSecurity
Functional Area
IT Security
Job Code
1522691
Interview Questions for you
View All