Sr Security Consultant – Web, Mobile, API & SCR

Talakunchi NetworksMumbai, MaharashtraOn-siteFull-timeSenior, 5–8 yearsListed 1 hour ago

Apply now

About this role

## Role Overview
We are looking for an experienced Application Security Tester with 3–6 years of hands-on experience in Web, Mobile, API Security Testing and Secure Code Review (SCR) . Experience in BFSI, UPI/payment applications and security compliance will be preferred. The candidate should have strong technical skills along with exposure to team coordination, client interaction and audit support .
## Key Responsibilities

- Perform Web Application Security Testing based on OWASP Top 10 and industry-standard methodologies.
- Conduct Mobile Application Security Testing for Android/iOS.
- Perform API Security Testing using Burp Suite, Postman, OWASP ZAP, etc.
- Conduct Secure Code Review (SCR) and identify insecure coding practices.
- Identify and validate vulnerabilities related to authentication, authorization, access control, injection, session management, sensitive data, business logic and API security.
- Perform vulnerability retesting and remediation validation .
- Prepare detailed VAPT/security assessment reports with evidence, impact and remediation recommendations.
- Perform/support security testing of UPI/payment applications , including API security, transaction flows, authentication, authorization and business logic.
- Support PCI-DSS and other security audits with VAPT reports, evidence, remediation and retest documentation.
- Coordinate with development/application teams for vulnerability remediation and closure.
- Handle client queries and participate in security review meetings.

Team Handling & Coordination

- Coordinate day-to-day activities of junior security testers.
- Allocate testing tasks and track assessment deliverables and timelines.
- Review vulnerability findings and reports for quality and technical accuracy.
- Mentor junior team members on application security testing and vulnerability validation.
- Coordinate with project managers, developers, application owners and client stakeholders.
- Support multiple security assessments and track remediation/closure.

Audit & Compliance Support

- Support PCI-DSS audits/assessments and client security compliance requirements.
- Prepare audit evidence including VAPT reports, scope, methodology, findings, remediation and retest results.
- Coordinate with auditors and stakeholders for security testing-related queries.
- Maintain assessment documentation and evidence for audit readiness.

Required Skills

- 3–6 years of hands-on Application Security / VAPT experience.
- Strong experience in Web, API and Mobile Security Testing .
- Hands-on experience in Secure Code Review .
- Strong knowledge of OWASP Top 10 and application security fundamentals.
- Understanding of JWT, OAuth, API authentication/authorization and business logic vulnerabilities .
- Hands-on experience with Burp Suite, Postman, MobSF and OWASP ZAP .
- Exposure to Frida / Objection is an advantage.
- BFSI, UPI/payment application and PCI-DSS exposure preferred.
- Good technical report writing, communication and stakeholder management skills.
- Team coordination/mentoring experience preferred.

Certifications – Preferred

- eWPT / eMAPT
- CEH
- OSCP / OSWE
- CREST or equivalent
Practical hands-on experience will be preferred over certification alone.
## Qualification

- Bachelor's degree in Computer Science / IT / Cybersecurity or equivalent.
- Strong analytical, communication and documentation skills.
- Ability to work in a structured, compliance-driven BFSI environment.