Job Title: Application Security Engineer / Source Code Review
Experience:4 to 9 Yrs
Location: Mumbai
Key Responsibilities:
- Perform Source Code Review (SCR), Web/Mobile Application Security Testing, and API Security Assessments for internal and external applications.
- Conduct security assessments annually and whenever significant code, module, or UI changes occur.
- Identify, validate, and report vulnerabilities with CVSS-based severity, impact, proof of concept (PoC), and remediation recommendations.
- Perform manual verification and eliminate false positives where required.
- Ensure testing aligns with OWASP Secure Coding Practices, OWASP Top 10 (Web/Mobile), and OWASP API Security Top 10.
- Support development teams in vulnerability remediation, re-testing, and closure.
- Prepare security reports, dashboards, MIS, and vulnerability tracking with remediation status.
- Assist with internal/external audits, security advisories, and threat intelligence activities.
- Manage application security tools, including user administration, upgrades, backups, OEM/vendor coordination, and tool maintenance.
- Conduct secure coding awareness sessions and collaborate with stakeholders to improve application security posture.
Required Skills:
- Hands-on experience in Source Code Review, Web/Mobile/API Security Testing, and Secure SDLC.
- Strong knowledge of OWASP Top 10, OWASP API Security Top 10, Secure Coding Practices, and CVSS.
- Experience with application security tools, vulnerability management, and security reporting.
- Good communication, stakeholder management, and audit support skills.
Interested candidates can share their resumes to Email: [email protected]
Pay: Up to ₹1,000,000.00 per year
Benefits:
- Health insurance
- Paid time off
- Provident Fund
Work Location: In person