The Role
Conduct advanced web, mobile, and API penetration testing; perform red team application assessments; develop automation and bypass tools; research WAF evasion; reverse-engineer applications; identify business logic vulnerabilities; produce technical reports; support secure design reviews and remediation; and mentor junior security testers.
Summary Generated by Built In
Location: Navi Mumbai
Employment Type: Full-Time
Experience: 3–6+ Years
About the Role
We are looking for a highly skilled Application Security / Offensive Security Engineer with a strong Red Team mindset to join our team. The role involves advanced penetration testing across Web, Mobile (Android & iOS), and APIs, focusing on real-world exploitation, vulnerability chaining, and bypassing modern security controls such as WAFs and client-side protections. If you thrive on deep technical challenges, scripting, and continuous research into emerging attack techniques, this role is for you.
Key Responsibilities
· Perform in-depth Web, Mobile, and API penetration testing with emphasis on exploitation and chaining vulnerabilities.
· Conduct Red Team-style application assessments across WAPT, MAPT, and API engagements.
· Develop custom scripts and tools to automate testing and bypass client-side security controls.
· Research and implement WAF evasion and bypass techniques.
· Reverse-engineer client-side and backend application logic.
· Identify business logic flaws and advanced attack paths.
· Deliver high-quality technical reports with reproduction steps, impact analysis, and remediation guidance.
· Stay updated with the latest vulnerabilities, attack techniques, and frameworks.
· Collaborate with development and security teams for secure design reviews and remediation.
Required Skills & Qualifications
· Strong hands-on experience in Web, Mobile (Android/iOS), and API Penetration Testing.
· Solid understanding of OWASP Top 10 (Web, Mobile, API).
· Experience with Java and JavaScript debugging.
· Ability to read, understand, and analyze JavaScript and Python code.
· Proficiency in Python (or equivalent scripting language) for automation and bypass tooling.
· Knowledge of modern web frameworks (React, Angular, Vue, Node.js, Spring Boot).
· Strong grasp of authentication, authorization, session management, and token-based security (OAuth, JWT, SAML).
· Familiarity with WAF technologies and bypass methodologies.
· Hands-on experience with Burp Suite, Frida, Objection, Postman, and mobile reversing tools.
Preferred Certifications
· OSCP
· eWPTX / eMAPT
· CRTP
Behavioural & Professional Attributes
· Strong research-driven and attacker mindset.
· Ability to work independently and lead complex security engagements.
· Excellent documentation and communication skills.
· Detail-oriented with a passion for deep technical problem-solving.
· Capability to mentor junior security testers.
Why Join Us?
· Opportunity to work on cutting-edge offensive security projects.
· Exposure to advanced Red Team engagements.
· Collaborative environment with continuous learning and growth.
Skills Required
- 3-6+ years of relevant experience
- Hands-on experience in web, mobile Android/iOS, and API penetration testing
- Strong understanding of OWASP Top 10 for web, mobile, and API security
- Experience with Java and JavaScript debugging
- Ability to read, understand, and analyze JavaScript and Python code
- Proficiency in Python or an equivalent scripting language for automation and bypass tooling
- Knowledge of React, Angular, Vue, Node.js, and Spring Boot
- Understanding of authentication, authorization, session management, OAuth, JWT, and SAML
- Familiarity with WAF technologies and bypass methodologies
- Hands-on experience with Burp Suite, Frida, Objection, Postman, and mobile reversing tools
- OSCP certification
- eWPTX or eMAPT certification
- CRTP certification
- Ability to work independently and lead complex security engagements
- Excellent documentation and communication skills
- Ability to mentor junior security testers
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
Talakunchi Networks Private Limited is a global information-security consulting company that helps organizations protect their IT infrastructure. Its services include vulnerability assessment and penetration testing (VAPT), website and network security audits, threat monitoring and management, security consulting, compliance audits, exposure scanning, governance, risk, and compliance support, and security training. The company has been a CERT-In-empanelled IT security auditor since 2018.






