Perform manual and automated application security and penetration testing across web, mobile, APIs, microservices and cloud environments. Validate cloud and DevSecOps controls, integrate security into CI/CD (SAST/DAST/SCA), manage vulnerabilities, automate testing, and support compliance (ISO27001, SOC2, GDPR). Assess AI/LLM security risks when present.
ResponsibilitiesApplication Security Testing
- Perform manual and automated security testing of
- Web applications
- Mobile applications (Android/iOS)
- Microservices / Microfrontends
- Conduct
- OWASP Top 10 testing
- API security testing
- Business logic testing
- Authentication & authorization validation
- Session management testing
- File upload security testing
- Input validation testing
- Execute black-box, grey-box and white-box penetration tests.
- Identify exploitable vulnerabilities.
- Assess exploitability and business impact.
- Validate remediation effectiveness.
Validate security of cloud-hosted environments including:
- Identity & Access Management
- Secrets Management
- Storage Security
- Network Security Groups
- Kubernetes security
- Container security
- Serverless functions
- Cloud misconfiguration assessments
Partner with engineering teams to:
- Review security requirements
- Review threat models
- Verify secure coding practices
- Validate security fixes
- Recommend design improvements
Integrate security testing into CI/CD pipelines by managing and optimizing:
- SAST
- DAST
- SCA (Software Composition Analysis)
- Container image scanning
- Secret scanning
- IaC scanning
- Verify vulnerabilities reported by scanners.
- Eliminate false positives.
- Prioritize findings using CVSS.
- Track remediation.
- Conduct regression testing.
Assess AI-enabled features for:
- Prompt Injection
- Jailbreak attempts
- Data leakage
- Insecure output handling
- Model abuse
- RAG vulnerabilities
- Sensitive information exposure
Support security initiatives related to:
- ISO 27001
- SOC 2
- GDPR
Provide evidence during internal and external audits.
AutomationDevelop security automation scripts for:
- Vulnerability validation
- API fuzzing
- Security regression
- Test data generation
- Security reporting
Strong understanding of
- OWASP Top 10
- API Security Top 10
- Authentication mechanisms
- OAuth2
- OpenID Connect
- JWT
- Cryptography fundamentals
- Secure Session Management
- XSS
- CSRF
- SQL Injection
- SSRF
- XXE
- Deserialization attacks
- RCE
- Privilege Escalation
Hands-on experience with tools such as
- Burp Suite Professional
- OWASP ZAP
- Postman
- Nmap
- Metasploit
- Nessus
- Nikto
- SQLMap
- MobSF
- SonarQube
- Snyk
- Checkmarx
- Veracode
Working knowledge of at least one language
- Python
- Java
- C#
- JavaScript
Ability to read application code to understand vulnerabilities.
Nice to HaveExperience with
- Kubernetes
- Docker
- Terraform
- GitHub Advanced Security
- CodeQL
- AI-assisted security testing
- LLM security
- Red Team exercises
- Bug bounty participation
- Capture The Flag (CTF)
- Bachelor's degree in Computer Science, Information Security, or related field.
- 4–8 years of experience in application security or security testing.
- Security certifications are desirable:
- OSCP
- OSWE
- CEH
- GWAPT
- CISSP (optional)
Disprz Chennai, Tamil Nadu, IND Office
S. No 67, Okkiam, 6th Floor, Smartworks Coworking Spaces Pvt. Ltd Olympia Pinnacle, S. No. 69/ 24I, 1-2A, OMR,, Chennai, Tamil Nadu, India, 600097
Similar Jobs
Cloud • Information Technology • Consulting
Lead and execute non-functional and Operational Acceptance Testing for BFSI systems, validating performance, security, scalability, resilience, failover, backup/restore, DR drills, monitoring, and compliance with SLAs and ITIL. Collaborate with DevOps, infrastructure, security, and QA teams; document findings and improve operational testing frameworks for payment and FOREX systems.
Top Skills:
DevOpsForexGmplusItilNetrevealOn-PremPayplusRtgsSwift
Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Manage enterprise customer accounts as a trusted technical advisor, driving platform adoption, measurable business value, and technical ROI. Develop success plans, troubleshoot complex hardware, software, and API issues, manage escalations, conduct root-cause analysis, and lead technical reviews. Collaborate with Sales, Support, Product, and Engineering while communicating effectively with technical and executive stakeholders. Use AI tools to improve customer insights and outcomes, and contribute to knowledge sharing and team development.
Top Skills:
AIAPIsGainsightGongInternet Of Things (Iot)JIRAPaasPythonSaaSSalesforceTableauZendesk
Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Tests liquidity risk and regulatory reporting releases across PRA, EBA, HKMA, and US Federal Reserve requirements. Responsibilities include SQL-based data validation, test strategy and execution, defect management, UAT dashboards, requirements gathering, data-gap analysis, issue resolution, and stakeholder communication. The role also supports finance data quality initiatives, regulatory compliance, operating-model transitions, change implementation, and coordination across Finance, Risk, Business, and IT teams.
Top Skills:
ExcelMicrosoft PowerpointMicrosoft ProjectMicrosoft VisioMicrosoft WordQuality CentreSQL
What you need to know about the Chennai Tech Scene
To locals, it's no secret that South India is leading the charge in big data infrastructure. While the environmental impact of data centers has long been a concern, emerging hubs like Chennai are favored by companies seeking ready access to renewable energy resources, which provide more sustainable and cost-effective solutions. As a result, Chennai, along with neighboring Bengaluru and Hyderabad, is poised for significant growth, with a projected 65 percent increase in data center capacity over the next decade.



