Application Security Tester (Web, Mobile & API) – BFSI Domain

Posted 2 Days Ago
Be an Early Applicant
Mumbai, Maharashtra, IND
In-Office
Junior
Information Technology • Consulting • Cybersecurity
The Role
Performs web, mobile, and API security testing for BFSI applications. Identifies and validates vulnerabilities including authentication, authorization, injection, sensitive data exposure, and business logic issues. Uses Burp Suite, MobSF, OWASP ZAP, and Postman; conducts retesting, prepares vulnerability reports, supports remediation validation, and responds to client queries. Requires 1–2 years of experience, application security fundamentals, and a relevant bachelor’s degree.
Summary Generated by Built In
Application Security Tester (Web, Mobile & API) – BFSI Domain
Experience: 1–2 Years
Location: Thane Ghodbunder Road(Onsite)
Domain: BFSI (Banking / Financial Services / Insurance)

Role Overview
We are looking for a motivated Application Security Tester with 1–2 years of hands-on experience in Web, Mobile, and API Security Testing, preferably within the BFSI domain. The candidate should have strong fundamentals in application security testing methodologies and vulnerability assessment aligned with industry standards.

Key Responsibilities
    • Perform Web Application Security Testing using industry-standard methodologies such as OWASP Top 10
    • Conduct Mobile Application Security Testing (Android/iOS – basic to intermediate level)
    • Perform API Security Testing using tools like Postman and Burp Suite
    • Identify vulnerabilities such as:
    • Authentication & authorization issues
    • Injection flaws
    • Sensitive data exposure
    • Business logic issues
    • Validate vulnerabilities and perform retesting after fixes
    • Prepare detailed vulnerability assessment reports
    • Support client queries and remediation validation
    • Follow secure testing practices aligned with BFSI expectations

Required Skills
Mandatory:
    • Hands-on experience in Web Application Security Testing
    • Basic experience in Mobile App Security Testing
    • Understanding of API Security Testing concepts
    • Familiarity with:
    • Burp Suite
    • MobSF
    • OWASP ZAP
    • Knowledge of:
    • OWASP Top 10
    • Basic secure coding issues
    • Authentication & session management vulnerabilities
Good to Have:
    • Exposure to BFSI applications
    • Understanding of API authentication (JWT / OAuth basics)
    • Experience with runtime testing tools like Frida or Objection
    • Certification (any one preferred):
    • eWPT
    • eMAPT
    • CEH (Practical exposure preferred over theory)

Qualification
    • Bachelor’s Degree in Computer Science / IT / Cybersecurity or equivalent
    • Strong understanding of application security fundamentals

Soft Skills
    • Good report writing skills
    • Ability to communicate vulnerabilities clearly
    • Willingness to learn BFSI security expectations
    • Ability to work in a structured testing environment




Skills Required

  • 1–2 years of hands-on experience in web application security testing
  • Basic experience in mobile application security testing
  • Understanding of API security testing concepts
  • Familiarity with Burp Suite, MobSF, and OWASP ZAP
  • Knowledge of OWASP Top 10 and basic secure coding issues
  • Knowledge of authentication and session management vulnerabilities
  • Bachelor’s degree in Computer Science, IT, Cybersecurity, or equivalent
  • Exposure to BFSI applications
  • Understanding of JWT and OAuth authentication basics
  • Experience with Frida or Objection
  • eWPT, eMAPT, or CEH certification
  • Strong report writing and vulnerability communication skills
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
403 Employees
Year Founded: 2016

What We Do

Talakunchi Networks Private Limited is a global information-security consulting company that helps organizations protect their IT infrastructure. Its services include vulnerability assessment and penetration testing (VAPT), website and network security audits, threat monitoring and management, security consulting, compliance audits, exposure scanning, governance, risk, and compliance support, and security training. The company has been a CERT-In-empanelled IT security auditor since 2018.

Similar Jobs

Ericsson Logo Ericsson

Head ASP Management

Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
In-Office
Mumbai, Maharashtra, IND
88000 Employees
10-12 Annually

Capco Logo Capco

Testing - Testing L2 (2.1-5 years)-29629-1

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Hybrid
Mumbai, Maharashtra, IND
6000 Employees

Capco Logo Capco

Data Analyst

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Hybrid
Mumbai, Maharashtra, IND
6000 Employees

Capco Logo Capco

Functional Testing with Banking Domain - Functional Testing with Banking Domain L2 (2.1-5 years)-29297-1

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Hybrid
Mumbai, Maharashtra, IND
6000 Employees

Similar Companies Hiring

Axle Health Thumbnail
Artificial Intelligence • Healthtech • Information Technology • Logistics
Santa Monica, CA
25 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account