Application Penetration Tester

1 week ago


Lower Parel Mumbai Maharashtra, India Mswipe Technologies Pvt. Ltd Full time

**Job Title**: Application Penetration Tester & Secure Code Reviewer (Urgent Requirement)

**Location**: Mumbai (Hybrid)

**Department**: Information Security / Application Security

**Reports To**: CISO, Mswipe Technologies Pvt. Ltd.

**Role Overview**

Mswipe Technologies is seeking a skilled **Application Security Specialist** proficient in **penetration testing and secure code review** to strengthen the security posture of its payment and fintech platforms.

This role requires close collaboration with developers, QA, and infrastructure teams to embed security within the **Secure SDLC (SSDLC)** and **DevSecOps** environment.

**Key Responsibilities**

**1. Application Penetration Testing**
- Identify vulnerabilities related to **OWASP Top 10** categories such as Injection, Broken Authentication, Security Misconfigurations, and Sensitive Data Exposure.
- Simulate real-world attack vectors to assess exploitability and impact.
- Validate fixes and perform **retesting** post-remediation.
- Prepare detailed reports with **risk severity, technical details, business impact, and mitigation recommendations.**:
**2. Secure Code Review**
- Conduct **manual and tool-assisted code reviews** (Java, Python,.NET, Node.js, PHP, etc.) to detect security weaknesses aligned with **CWE/SANS Top 25**.
- Identify issues such as **improper input validation, insecure deserialization, broken access control, SQL injection**, and other common coding flaws.
- Provide **secure coding recommendations** and work closely with developers to remediate issues.
- Develop and maintain **Mswipe’s secure coding guidelines, checklists, and best practices.**:

- Participate in **code walkthroughs** and educate developers on secure coding techniques.

**3. Collaboration & Security Integration**
- Collaborate with product, engineering, and QA teams to **embed security within SDLC** stages.
- Support **threat modeling** and **architecture security reviews** for new features or system integrations.
- Conduct **developer training sessions** on OWASP, secure coding, and common attack prevention.

**Required Skills & Experience**
- Strong understanding of **OWASP Top 10**, **CWE/SANS Top 25**, and **OWASP ASVS** standards.
- Hands-on experience with tools such as:

- **Burp Suite Pro**, **OWASP ZAP**, **Postman**, **MobSF**, **Frida**, **Drozer**, **apktool**, **Metasploit**:

- **SAST tools**: SonarQube, Checkmarx, Fortify, Veracode
- **DAST tools**: OWASP ZAP, Netsparker, Acunetix
- Familiarity with **secure coding practices** in Java, JavaScript, Python, or similar languages.
- Knowledge of **API security**, **JWT/OAuth2**, and **cryptographic controls**.
- Strong communication skills to translate technical risks into business context.

**Preferred Certifications**
- **Offensive Security**: OSCP, OSWE, eWPT, GPEN, GWAPT (Anyone is Mandatory)
- **AppSec & Secure Coding**: CSSLP, CEH (Practical), eCPPT (Anyone is Mandatory)
- **Compliance Familiarity**: PCI DSS, ISO 27001, SOC 2

**Soft Skills**
- Analytical and methodical approach to problem-solving.
- Attention to detail and thorough documentation habits.
- Excellent written and verbal communication.
- Team player with proactive attitude and learning mindset.

**Performance Indicators**
- Reduction in recurring vulnerabilities across sprints.
- Code review coverage and vulnerability closure rate.
- Developer feedback and improvement in secure coding maturity.

**Work Mode & Environment**
- **Hybrid role**: 3 days per week from Mswipe’s Mumbai office.
- Opportunity to work closely with **security engineers, DevOps, and product teams** in an agile setup.

Pay: ₹900,000.00 - ₹1,100,000.00 per year

**Benefits**:

- Health insurance
- Paid sick time
- Provident Fund

Work Location: In person



  • Mumbai, Maharashtra, India Suzva Software Technologies Full time ₹ 5,00,000 - ₹ 15,00,000 per year

    Level 3 Resource Application Penetration Tester (APT)Were looking for a handson Application Penetration Tester (APT) to join our security team and lead offensive testing of web applications, mobile apps (iOS/Android), and APIs (REST/GraphQL/gRPC).Youll plan and execute manual and automated assessments, discover realworld vulnerabilities, produce clear...

  • Penetration Tester

    2 weeks ago


    Mumbai, Maharashtra, India Prescient Security Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Penetration Tester – Retest & QA Team, Remote (India) At Prescient Security, we are on a mission to simplify security and compliance. Our core values are: • Bring Order to Chaos • Be Accountable & See it Through • 1000% With You • Support & Collaborate • Think Outside the Box Summary: As a Penetration Tester on our Retest and QA team,...

  • Penetration Tester

    1 week ago


    Mira Road, Mumbai, Maharashtra, India TESTRIQ QA Lab Full time

    **Benefits**: **Here are just some of the perks you’ll get as a member of**: **Health Care**: Employee State Insurance **Flexibility**: Flexible work hours, Holidays as per Indian calendar, PL, CL, & paid parental leave. **Commute**: Office No: - 2 & 3, 2nd Floor, Ashley Tower, Beverly Park, adj. to PVR Multiplex, Mira Road East, Thane -...

  • Penetration Tester

    1 week ago


    Pune, Maharashtra, India MSCI Inc Full time

    Job Description - Penetration Tester (240000HL) - Job Number: 240000HL Requisition Title : Penetration Tester **Description**: **Your team responsibilities** Penetration Tester & Python Developer **What we offer you** - At MSCI we are passionate about what we do, and we are inspired by our purpose - to power better investment decisions. You’ll be part...

  • Penetration Tester

    6 days ago


    Mumbai, Maharashtra, India CyberNX Technologies Pvt Ltd. Full time

    Location: Thane Experience - 3 Years Job Responsibilities: Research and experiment with different types of attacks. Develop methodologies for penetration testing. Review code for security vulnerabilities. Automate common testing techniques to improve efficiency. Write technical and executive reports. Communicate findings to both technical staff and...


  • Mumbai, India Dminds Solutions Inc. Full time

    Job Title: Senior Android Penetration TesterLocation: RemoteEmployment Type: ContractExperience Level: 10+ years (with specialization in Mobile Security)Looking for Immediate Joiners OnlyRole OverviewWe are seeking a highly skilled Senior Android Penetration Tester to lead advanced mobile application security testing and vulnerability assessments. The role...


  • Mumbai Central, Mumbai, Maharashtra, India UPay Full time

    **Location**: Remote (Company based in Dubai, UAE) **Job Type**: Full-Time, Remote **Salary**: $8,000 - $10,000 USD/month **Payment Method**: Monthly wallet transfer **About Spark Shield Technology** Spark Shield Technology is a UAE-based cybersecurity company dedicated to helping organizations defend against ever-evolving digital threats. We specialize...

  • Penetration Tester

    1 week ago


    Mumbai, India Paralok Information Security Pvt.Ltd. Full time

    Information Security Analyst Charter Responsibilities: Monitor computer networks for security issues. Performing Web Application Penetration Testing, Mobile Application Penetration Testing and Network penetration testing (both Manual as well as Automated) Investigate security breaches and other cyber security incidents. Install security measures and operate...

  • Penetration Tester

    13 hours ago


    Mumbai, India CyberNX Technologies Pvt Ltd. Full time

    Job Responsibilities - Research and experiment with different types of attacks. - Develop methodologies for penetration testing. - Review code for security vulnerabilities. - Automate common testing techniques to improve efficiency. - Write technical and executive reports. - Communicate findings to both technical staff and executive leadership. - Validate...

  • Test Analyst

    7 days ago


    Mumbai, Maharashtra, India NEC Software Solutions Full time

    Company Description NEC Software Solutions India Private Limited is based in Mumbai Worli Airoli and Bangalore with an employee strength of 1300 It is one of the foremost providers of end- to-end IT services across various sectors We work with diverse industry verticals which include publishing media financial services retail healthcare and technology...