Senior Security Engineer

16 hours ago


Gurugram, India AIS business solution Full time

Job Tittle - Security Test Engineer

Job Type: Full-time
EXP 5+ Years
Location - Gurgaon

Roles & Responsibilities:

Perform Security Assessments: Conduct various types of security testing,
including:
1. Penetration Testing: Perform black-box, gray-box, and white-box penetration
testing on web applications, APIs, mobile applications (iOS/Android), and
network infrastructure.
2. Vulnerability Assessments: Utilize automated and manual techniques to
identify security weaknesses.
3. Static Application Security Testing (SAST): Analyze source code to identify
potential vulnerabilities.
4. Dynamic Application Security Testing (DAST): Test applications in a running
state and vulnerabilities.
5. Interactive Application Security Testing (IAST): Combine elements of SAST and
DAST for comprehensive testing.
6. Configuration Reviews: Assess the security posture of various systems and
applications.
7. Threat Modeling: Participate in threat modeling sessions to identify potential
attack vectors and vulnerabilities early in the development lifecycle.
8. Vulnerability Management:
Document identified vulnerabilities clearly and concisely, including steps to
reproduce, impact, and severity.
Communicate findings to development teams and stakeholders effectively.
Track and manage vulnerabilities through their lifecycle, from discovery to
remediation and retesting.
Provide guidance and recommendations to development teams on remediation
strategies.

9. Security Tooling & Automation:
- Utilize and configure security testing tools (e.g., Burp Suite, OWASP ZAP, Nessus,
Acunetix, Fortify, Checkmarx, Metasploit).
- Develop and implement automated security tests and scripts to improve efficiency.
- Stay up-to-date with the latest security testing tools, techniques, and best
practices.
10. Collaboration & Communication:
- Collaborate closely with development, DevOps, QA, and product teams to
integrate security into the SDLC (Secure SDLC).
- Educate and mentor developers on secure coding practices and common vulnerabilities.
- Participate in security code reviews.
- Present security findings and recommendations to technical and non-technical
audiences.
11. Research & Development:
- Stay informed about emerging security threats, attack vectors, and industry
trends.
- Contribute to the improvement of security testing methodologies and processes.
Participate in security community activities, conferences, and training.

Required Skills & Qualifications:

  • Education: Bachelor's degree in computer science, Information Security, or a
    related field (or equivalent practical experience).

  • Experience:
    Mid-Level: 3-6 years of experience in security testing, penetration testing, or
    application security.

Senior Level: 6+ years of experience in security testing, leading penetration
testing engagements and architecting secure solutions.

Technical Skills:

  • Strong understanding of web application security vulnerabilities (e.g., OWASP
    Top 10, SANS Top 25).
    o Proficiency with security testing tools (e.g., Burp Suite, OWASP ZAP, Nmap,
    Metasploit).
  • Experience with various operating systems (Linux, Windows).
  • Familiarity with scripting languages (e.g., Python, Ruby, PowerShell, Bash).
    Understanding of network protocols, firewalls, and intrusion
    detection/prevention systems.
  • Knowledge of secure coding principles and common programming languages
    (e.g., Java, Python, C#, JavaScript, ).
  • Experience with cloud security (AWS, Azure, GCP) is a strong plus.
    Familiarity with CI/CD pipelines and integrating security into automated workflows.

Soft Skills:
- Excellent analytical and problem-solving skills.
- Strong communication and interpersonal skills, with the ability to explain complex technical concepts to non-technical audiences.
- Ability to work independently and as part of a team.
- High attention to detail and a methodical approach to testing.
- Curiosity and a strong desire to learn and stay current with security trends.

Desired Certifications (Plus, but not required):
OSCP
OSWE
CEH (Certified Ethical Hacker)
CompTIA Security+
SANS certifications (e.g., GWEB, GWAPT, GPEN)
CSSLP (Certified Secure Software Lifecycle Professional)



  • Gurugram, India Senior Full time

    Company Description Senior is a UK based MNC and has operations in 12 countries and has 26 operating businesses worldwide serving number of markets. Senior's experienced manpower support, effective use of raw material as well as high technology enable it to deliver optimized components within a short development time and at most competitive prices. Senior...


  • Gurugram, India Cvent Full time

    OverviewYou are an experienced, hands-on Application Security Engineer who's passionate about building secure products, automating security workflows, and influencing development teams to embed security into the product development lifecycle. Whether you're ready to take ownership or growing your deep technical skills as aSenior Engineer, you're ready to...


  • Gurugram, India noon Full time

    About noon noon, the region's leading consumer commerce platform. On December 12th, 2017, noon launched its consumer platform in Saudi Arabia and the UAE, expanding to Egypt in February 2019. The noon ecosystem of services now includes marketplaces for food delivery, quick-commerce, fintech, and fashion. noon is a work in progress; we're six years in, but...

  • Security Engineer

    17 hours ago


    Gurugram, India Steerlean Full time

    Cloud Security Architecture : Asses, help in design and development of AWS, Azure and AWS security architectures for protecting PII/PCI data deployed into different types of cloud and cloud/hybrid systems. Improve the security around cloud-based applications, across all types (including Infrastructure, Platform, and Software as a Service...


  • Gurugram, India High Tech Infosystems Full time

    Job Title : Senior Engineer of exp : 10- 15 : Description : Are you a cybersecurity expert with hands-on experience across infrastructure, cloud, threat detection, and governance? We're looking for a Senior Cybersecurity Engineer who can design, deploy, and optimize end-to end security Youll Do :- Design & implement cybersecurity solutions across...


  • Gurugram, Hyderabad, Bengaluru, India Security and Intelligence Services Full time

    Job Description - The Senior Database Engineer will be responsible for the design, implementation, and management of DTS database systems, with a focus on Oracle and PostgreSQL and cloud-based backup solutions like Rubrik. - Operating within cloud platforms such as AWS and Oracle Cloud, this role requires deep expertise in database engineering, performance...

  • Senior Manager

    3 days ago


    Gurugram, India Questhiring Full time

    Job Description :About the job :We are seeking a highly skilled and experienced Senior Manager Application Security to lead our application security strategy, governance, and execution. This role will oversee secure software development practices, drive security reviews and testing, and partner with engineering teams to ensure security is embedded across the...


  • Gurugram, India Simpplr Full time

    Who We AreSimpplr is the AI-powered platform that unifies the digital workplace – bringing together engagement, enablement, and services to transform the employee experience. It streamlines communication, simplifies interactions, automates workflows, and elevates the everyday experience of work. The platform is intuitive, highly extensible, and built to...


  • Gurugram, India Ahead Full time

    AHEAD builds platforms for digital business. By weaving together advances in cloud infrastructure, automation and analytics, and software delivery, we help enterprises deliver on the promise of digital transformation. AtAHEAD, we prioritize creating a culture of belonging,where all perspectives and voices are represented, valued, respected, and heard. We...

  • Security Engineer

    15 hours ago


    Gurugram, India GSPANN Full time

    Role Overview We are seeking a highly skilled Security Engineer with expertise in threat simulation, the MITRE ATT&CK framework, and scripting. The ideal candidate will have a strong background in penetration testing, red teaming, or threat emulation, along with hands-on experience in BAS (Breach and Attack Simulation) tools. The role involves evaluating...