Conduct advanced web, mobile, and API penetration testing; perform red team application assessments; develop automation and bypass tools; research WAF evasion; reverse-engineer applications; identify business logic vulnerabilities; produce technical reports; support secure design reviews and remediation; and mentor junior security testers.
Location: Navi Mumbai
Employment Type: Full-Time
Experience: 3–6+ Years
About the Role
We are looking for a highly skilled Application Security / Offensive Security Engineer with a strong Red Team mindset to join our team. The role involves advanced penetration testing across Web, Mobile (Android & iOS), and APIs, focusing on real-world exploitation, vulnerability chaining, and bypassing modern security controls such as WAFs and client-side protections. If you thrive on deep technical challenges, scripting, and continuous research into emerging attack techniques, this role is for you.
Key Responsibilities
· Perform in-depth Web, Mobile, and API penetration testing with emphasis on exploitation and chaining vulnerabilities.
· Conduct Red Team-style application assessments across WAPT, MAPT, and API engagements.
· Develop custom scripts and tools to automate testing and bypass client-side security controls.
· Research and implement WAF evasion and bypass techniques.
· Reverse-engineer client-side and backend application logic.
· Identify business logic flaws and advanced attack paths.
· Deliver high-quality technical reports with reproduction steps, impact analysis, and remediation guidance.
· Stay updated with the latest vulnerabilities, attack techniques, and frameworks.
· Collaborate with development and security teams for secure design reviews and remediation.
Required Skills & Qualifications
· Strong hands-on experience in Web, Mobile (Android/iOS), and API Penetration Testing.
· Solid understanding of OWASP Top 10 (Web, Mobile, API).
· Experience with Java and JavaScript debugging.
· Ability to read, understand, and analyze JavaScript and Python code.
· Proficiency in Python (or equivalent scripting language) for automation and bypass tooling.
· Knowledge of modern web frameworks (React, Angular, Vue, Node.js, Spring Boot).
· Strong grasp of authentication, authorization, session management, and token-based security (OAuth, JWT, SAML).
· Familiarity with WAF technologies and bypass methodologies.
· Hands-on experience with Burp Suite, Frida, Objection, Postman, and mobile reversing tools.
Preferred Certifications
· OSCP
· eWPTX / eMAPT
· CRTP
Behavioural & Professional Attributes
· Strong research-driven and attacker mindset.
· Ability to work independently and lead complex security engagements.
· Excellent documentation and communication skills.
· Detail-oriented with a passion for deep technical problem-solving.
· Capability to mentor junior security testers.
Why Join Us?
· Opportunity to work on cutting-edge offensive security projects.
· Exposure to advanced Red Team engagements.
· Collaborative environment with continuous learning and growth.
Similar Jobs
Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Leads complex, cross-functional scientific learning projects for Medical Affairs. Develops curricula, e-learning, and blended learning programs; partners with medical, scientific, agency, and learning systems teams; manages multiple projects, timelines, budgets, and priorities; evaluates emerging e-learning technologies; and updates existing learning resources across therapeutic areas.
Top Skills:
Articulate StorylineDigital Learning TechnologyE-Learning Authoring ToolsLearning Management Systems
Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Leads multiple software engineering teams through new product development from concept to implementation. Provides technical and strategic leadership across architecture, Java and Spring-based applications, cloud-native systems, microservices, CI/CD, quality initiatives, automation, and real-time platforms. Manages stakeholders, project metrics, cross-location coordination, business execution, team development, and strategic technology direction while ensuring consistent delivery and security practices.
Top Skills:
AICi/CdDigital Native ArchitectureJavaMicroservicesPivotal Cloud FoundryReal-Time Online SystemsScaled Agile FrameworkSpring BootSpring Framework
Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Designs, develops, tests, deploys, and maintains secure software solutions across the full SDLC. Leads technical solution planning, production support, incident remediation, technology evaluations, and proof-of-concept initiatives. Creates technical documentation, ensures testing and quality compliance, coordinates offshore development, supports vendor collaboration, and mentors team members through training and knowledge transfer.
What you need to know about the Mumbai Tech Scene
From haggling for the best price at Chor Bazaar to the bustle of Crawford Market, the energy of Mumbai's traditional markets is a key part of the city's charm. And while these markets will always have their place, the city also boasts a thriving e-commerce scene, ranking among the largest in the region. Driven by online sales in everything from snacks to licensed sports merchandise to children's apparel, the local industry is worth billions, with companies actively recruiting to meet the demands of continued growth.


