Perform manual and automated application security and penetration testing across web, mobile, APIs, microservices and cloud environments. Validate cloud and DevSecOps controls, integrate security into CI/CD (SAST/DAST/SCA), manage vulnerabilities, automate testing, and support compliance (ISO27001, SOC2, GDPR). Assess AI/LLM security risks when present.
ResponsibilitiesApplication Security Testing
- Perform manual and automated security testing of
- Web applications
- Mobile applications (Android/iOS)
- Microservices / Microfrontends
- Conduct
- OWASP Top 10 testing
- API security testing
- Business logic testing
- Authentication & authorization validation
- Session management testing
- File upload security testing
- Input validation testing
- Execute black-box, grey-box and white-box penetration tests.
- Identify exploitable vulnerabilities.
- Assess exploitability and business impact.
- Validate remediation effectiveness.
Validate security of cloud-hosted environments including:
- Identity & Access Management
- Secrets Management
- Storage Security
- Network Security Groups
- Kubernetes security
- Container security
- Serverless functions
- Cloud misconfiguration assessments
Partner with engineering teams to:
- Review security requirements
- Review threat models
- Verify secure coding practices
- Validate security fixes
- Recommend design improvements
Integrate security testing into CI/CD pipelines by managing and optimizing:
- SAST
- DAST
- SCA (Software Composition Analysis)
- Container image scanning
- Secret scanning
- IaC scanning
- Verify vulnerabilities reported by scanners.
- Eliminate false positives.
- Prioritize findings using CVSS.
- Track remediation.
- Conduct regression testing.
Assess AI-enabled features for:
- Prompt Injection
- Jailbreak attempts
- Data leakage
- Insecure output handling
- Model abuse
- RAG vulnerabilities
- Sensitive information exposure
Support security initiatives related to:
- ISO 27001
- SOC 2
- GDPR
Provide evidence during internal and external audits.
AutomationDevelop security automation scripts for:
- Vulnerability validation
- API fuzzing
- Security regression
- Test data generation
- Security reporting
Strong understanding of
- OWASP Top 10
- API Security Top 10
- Authentication mechanisms
- OAuth2
- OpenID Connect
- JWT
- Cryptography fundamentals
- Secure Session Management
- XSS
- CSRF
- SQL Injection
- SSRF
- XXE
- Deserialization attacks
- RCE
- Privilege Escalation
Hands-on experience with tools such as
- Burp Suite Professional
- OWASP ZAP
- Postman
- Nmap
- Metasploit
- Nessus
- Nikto
- SQLMap
- MobSF
- SonarQube
- Snyk
- Checkmarx
- Veracode
Working knowledge of at least one language
- Python
- Java
- C#
- JavaScript
Ability to read application code to understand vulnerabilities.
Nice to HaveExperience with
- Kubernetes
- Docker
- Terraform
- GitHub Advanced Security
- CodeQL
- AI-assisted security testing
- LLM security
- Red Team exercises
- Bug bounty participation
- Capture The Flag (CTF)
- Bachelor's degree in Computer Science, Information Security, or related field.
- 4–8 years of experience in application security or security testing.
- Security certifications are desirable:
- OSCP
- OSWE
- CEH
- GWAPT
- CISSP (optional)
Disprz Chennai, Tamil Nadu, IND Office
S. No 67, Okkiam, 6th Floor, Smartworks Coworking Spaces Pvt. Ltd Olympia Pinnacle, S. No. 69/ 24I, 1-2A, OMR,, Chennai, Tamil Nadu, India, 600097
Similar Jobs
Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
Leads delivery of enterprise conversational AI platforms, including chatbots and voice bots. Oversees Agile execution, technical architecture, cloud-native engineering, CI/CD, Terraform, Responsible AI, and AI adoption. Partners with product, security, architecture, and business teams while managing risks and executive communication. Mentors engineers and technical leads, supports hiring and performance management, and ensures scalable, secure, compliant, and operationally excellent solutions.
Top Skills:
Agentic AiAmazon ConnectAmazon LexAWSAzureCcaasCi/CdConversational AiDevOpsDevsecopsFive9Generative AiGenesysGoogle AdkGCPGoogle DialogflowLlmsNiceNode.jsPythonRagShift-Left EngineeringTerraformTypescript
Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
Leads quality engineering for contact center, BOT, RPA, and enterprise applications. Owns test strategy, planning, automation, performance testing, deployment validation, release readiness, and post-release monitoring. Develops and maintains automated scripts, enhances testing frameworks, establishes QA governance and metrics, analyzes quality trends, and mentors QA teams. Collaborates with technical and business stakeholders while applying AI tools, CI/CD, and DevOps practices to improve quality and scalability.
Top Skills:
AIApi TestingBotC#Ci/CdCyaraDatabase TestingDevOpsIntegration TestingJavaJavaScriptPerformance TestingPythonRpaUi Testing
Automotive
Drives execution of complex, cross-functional transformation initiatives by managing project plans, schedules, risks, dependencies, and executive reporting. Coordinates teams across Quality, Engineering, Product Development, Manufacturing, and other functions; facilitates decision-making and accountability; applies project-management governance and tools; coaches employees on project practices; supports TMO operations; and improves transformation delivery processes.
Top Skills:
JIRAMicrosoft ProjectPlannerRallySmartsheet
What you need to know about the Chennai Tech Scene
To locals, it's no secret that South India is leading the charge in big data infrastructure. While the environmental impact of data centers has long been a concern, emerging hubs like Chennai are favored by companies seeking ready access to renewable energy resources, which provide more sustainable and cost-effective solutions. As a result, Chennai, along with neighboring Bengaluru and Hyderabad, is poised for significant growth, with a projected 65 percent increase in data center capacity over the next decade.


