Be an Early Applicant
The Role
Perform manual secure source code reviews across web, API, mobile, cloud-native, and microservices applications. Identify vulnerabilities involving access control, injection, authentication, cloud and container security, business logic, and AI/LLM risks. Conduct threat modeling, secure architecture reviews, API and cloud security assessments, IaC reviews, and Secure SDLC assessments. Provide developer-focused remediation guidance and review enterprise-scale codebases using leading application security tools.
Summary Generated by Built In
Hiring: DevSecOps Associate - Source Code Review Security
Location: Mumbai
No of Openings: 1
Key Responsibilities
Perform deep manual source code reviews across web, API, mobile, cloud-native, and microservices architectures
Identify and validate critical security vulnerabilities including:
- Broken Access Control
- Injection Flaws
- Authentication & Authorization Issues
- SSRF, XXE, Deserialization
- Business Logic Vulnerabilities
- Privilege Escalation
- Cloud & Container Security Weaknesses
- AI/LLM Security Risks
- Conduct:
- Secure Architecture Reviews
- Threat Modeling
- API Security Assessments
- Cloud Security Reviews
- Infrastructure-as-Code (IaC) Reviews
- Secure SDLC Assessments
- Technical Expertise Required
- Java, Spring Boot, .NET, Python, Node.js, Go, Rust, PHP
- React, Angular, Vue, Next.js
- Android & iOS Security
- Kubernetes, Docker, Terraform
- OWASP ASVS, OWASP Testing Guide, MITRE CWE, NIST Frameworks
3.Security Tooling Experience
- Checkmarx
- Fortify
- Veracode
- Semgrep
- Snyk
- Trivy
What We're Looking For
- 1-2+ years of Application Security experience
- Expertise in Manual Secure Code Review
- Strong Secure SDLC and DevSecOps background
- Ability to provide developer-focused remediation guidance
- Experience reviewing enterprise-scale codebases and security architectures
Preferred Certifications
If you have a passion for secure software development, offensive security, and building resilient applications at scale, we'd love to hear from you.
Skills Required
- 1–2+ years of application security experience
- Expertise in manual secure code review
- Strong Secure SDLC and DevSecOps background
- Ability to provide developer-focused remediation guidance
- Experience reviewing enterprise-scale codebases and security architectures
- Experience with Java, Spring Boot, .NET, Python, Node.js, Go, Rust, PHP, and modern web frameworks
- Experience with Android and iOS security
- Experience with Kubernetes, Docker, and Terraform
- Knowledge of OWASP ASVS, OWASP Testing Guide, MITRE CWE, and NIST frameworks
- Experience with Checkmarx, Fortify, Veracode, Semgrep, Snyk, or Trivy
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
Talakunchi Networks Private Limited is a global information-security consulting company that helps organizations protect their IT infrastructure. Its services include vulnerability assessment and penetration testing (VAPT), website and network security audits, threat monitoring and management, security consulting, compliance audits, exposure scanning, governance, risk, and compliance support, and security training. The company has been a CERT-In-empanelled IT security auditor since 2018.







