Perform manual and automated application security and penetration testing across web, mobile, APIs, microservices and cloud environments. Validate cloud and DevSecOps controls, integrate security into CI/CD (SAST/DAST/SCA), manage vulnerabilities, automate testing, and support compliance (ISO27001, SOC2, GDPR). Assess AI/LLM security risks when present.
ResponsibilitiesApplication Security Testing
- Perform manual and automated security testing of
- Web applications
- Mobile applications (Android/iOS)
- Microservices / Microfrontends
- Conduct
- OWASP Top 10 testing
- API security testing
- Business logic testing
- Authentication & authorization validation
- Session management testing
- File upload security testing
- Input validation testing
- Execute black-box, grey-box and white-box penetration tests.
- Identify exploitable vulnerabilities.
- Assess exploitability and business impact.
- Validate remediation effectiveness.
Validate security of cloud-hosted environments including:
- Identity & Access Management
- Secrets Management
- Storage Security
- Network Security Groups
- Kubernetes security
- Container security
- Serverless functions
- Cloud misconfiguration assessments
Partner with engineering teams to:
- Review security requirements
- Review threat models
- Verify secure coding practices
- Validate security fixes
- Recommend design improvements
Integrate security testing into CI/CD pipelines by managing and optimizing:
- SAST
- DAST
- SCA (Software Composition Analysis)
- Container image scanning
- Secret scanning
- IaC scanning
- Verify vulnerabilities reported by scanners.
- Eliminate false positives.
- Prioritize findings using CVSS.
- Track remediation.
- Conduct regression testing.
Assess AI-enabled features for:
- Prompt Injection
- Jailbreak attempts
- Data leakage
- Insecure output handling
- Model abuse
- RAG vulnerabilities
- Sensitive information exposure
Support security initiatives related to:
- ISO 27001
- SOC 2
- GDPR
Provide evidence during internal and external audits.
AutomationDevelop security automation scripts for:
- Vulnerability validation
- API fuzzing
- Security regression
- Test data generation
- Security reporting
Strong understanding of
- OWASP Top 10
- API Security Top 10
- Authentication mechanisms
- OAuth2
- OpenID Connect
- JWT
- Cryptography fundamentals
- Secure Session Management
- XSS
- CSRF
- SQL Injection
- SSRF
- XXE
- Deserialization attacks
- RCE
- Privilege Escalation
Hands-on experience with tools such as
- Burp Suite Professional
- OWASP ZAP
- Postman
- Nmap
- Metasploit
- Nessus
- Nikto
- SQLMap
- MobSF
- SonarQube
- Snyk
- Checkmarx
- Veracode
Working knowledge of at least one language
- Python
- Java
- C#
- JavaScript
Ability to read application code to understand vulnerabilities.
Nice to HaveExperience with
- Kubernetes
- Docker
- Terraform
- GitHub Advanced Security
- CodeQL
- AI-assisted security testing
- LLM security
- Red Team exercises
- Bug bounty participation
- Capture The Flag (CTF)
- Bachelor's degree in Computer Science, Information Security, or related field.
- 4–8 years of experience in application security or security testing.
- Security certifications are desirable:
- OSCP
- OSWE
- CEH
- GWAPT
- CISSP (optional)
Disprz Chennai, Tamil Nadu, IND Office
S. No 67, Okkiam, 6th Floor, Smartworks Coworking Spaces Pvt. Ltd Olympia Pinnacle, S. No. 69/ 24I, 1-2A, OMR,, Chennai, Tamil Nadu, India, 600097
Similar Jobs
Cloud • Information Technology • Consulting
Lead and execute non-functional and Operational Acceptance Testing for BFSI systems, validating performance, security, scalability, resilience, failover, backup/restore, DR drills, monitoring, and compliance with SLAs and ITIL. Collaborate with DevOps, infrastructure, security, and QA teams; document findings and improve operational testing frameworks for payment and FOREX systems.
Top Skills:
DevOpsForexGmplusItilNetrevealOn-PremPayplusRtgsSwift
Artificial Intelligence • Machine Learning
Lead strategy and execution for AI-first product engineering: build and scale cloud-native conversational AI and enterprise SaaS platforms, grow global engineering leadership, partner with Product/Data Science, and improve delivery velocity, quality, and operational excellence.
Top Skills:
Automatic Speech Recognition (Asr)Cloud-NativeConversational AiEmotion AiEnterprise-Grade PlatformsGenerative AiKnowledge AiLarge Language Models (Llms)Multi-CloudRetrieval-Augmented Generation (Rag)SaaSSmall Language Models (Slms)Text-To-Speech (Tts)TranscriptionWorkflow Automation
Big Data • Fintech • Information Technology • Business Intelligence • Financial Services • Cybersecurity • Big Data Analytics
The Back Office Operations Representative handles email responses, identity verification, consumer disclosures, and dispute resolution while maintaining knowledge of T&E products and processes.
Top Skills:
Microsoft Applications
What you need to know about the Chennai Tech Scene
To locals, it's no secret that South India is leading the charge in big data infrastructure. While the environmental impact of data centers has long been a concern, emerging hubs like Chennai are favored by companies seeking ready access to renewable energy resources, which provide more sustainable and cost-effective solutions. As a result, Chennai, along with neighboring Bengaluru and Hyderabad, is poised for significant growth, with a projected 65 percent increase in data center capacity over the next decade.



