- Perform manual and automated security testing of
- Web applications
- Mobile applications (Android/iOS)
- Microservices / Microfrontends
- Conduct
- OWASP Top 10 testing
- API security testing
- Business logic testing
- Authentication & authorization validation
- Session management testing
- File upload security testing
- Input validation testing
- Execute black-box, grey-box and white-box penetration tests.
- Identify exploitable vulnerabilities.
- Assess exploitability and business impact.
- Validate remediation effectiveness.
- Identity & Access Management
- Secrets Management
- Storage Security
- Network Security Groups
- Kubernetes security
- Container security
- Serverless functions
- Cloud misconfiguration assessments
- Review security requirements
- Review threat models
- Verify secure coding practices
- Validate security fixes
- Recommend design improvements
- SAST
- DAST
- SCA (Software Composition Analysis)
- Container image scanning
- Secret scanning
- IaC scanning
- Verify vulnerabilities reported by scanners.
- Eliminate false positives.
- Prioritize findings using CVSS.
- Track remediation.
- Conduct regression testing.
- Prompt Injection
- Jailbreak attempts
- Data leakage
- Insecure output handling
- Model abuse
- RAG vulnerabilities
- Sensitive information exposure
- ISO 27001
- SOC 2
- GDPR
- Vulnerability validation
- API fuzzing
- Security regression
- Test data generation
- Security reporting
- OWASP Top 10
- API Security Top 10
- Authentication mechanisms
- OAuth2
- OpenID Connect
- JWT
- Cryptography fundamentals
- Secure Session Management
- XSS
- CSRF
- SQL Injection
- SSRF
- XXE
- Deserialization attacks
- RCE
- Privilege Escalation
- Burp Suite Professional
- OWASP ZAP
- Postman
- Nmap
- Metasploit
- Nessus
- Nikto
- SQLMap
- MobSF
- SonarQube
- Snyk
- Checkmarx
- Veracode
- Python
- Java
- C#
- JavaScript
- Kubernetes
- Docker
- Terraform
- GitHub Advanced Security
- CodeQL
- AI-assisted security testing
- LLM security
- Red Team exercises
- Bug bounty participation
- Capture The Flag (CTF)
- Bachelor's degree in Computer Science, Information Security, or related field.
- 4–8 years of experience in application security or security testing.
- Security certifications are desirable:
- OSCP
- OSWE
- CEH
- GWAPT
- CISSP (optional)
Skills Required
- Bachelor's degree in Computer Science, Information Security, or related field
- 4-8 years of experience in application security or security testing
- Strong understanding of OWASP Top 10, API Security Top 10, authentication mechanisms, OAuth2, OpenID Connect, JWT, cryptography fundamentals, secure session management, XSS, CSRF, SQLi, SSRF, XXE, deserialization, RCE, privilege escalation
- Hands-on experience with security tools: Burp Suite Professional, OWASP ZAP, Postman, Nmap, Metasploit, Nessus, Nikto, SQLMap, MobSF, SonarQube, Snyk, Checkmarx, Veracode
- Practical experience with penetration testing (black/grey/white box), API security testing, business logic testing, and vulnerability validation/prioritization using CVSS
- Experience integrating security into CI/CD and DevSecOps workflows (SAST, DAST, SCA, container image/secret/IaC scanning)
- Working knowledge of at least one programming language (Python, Java, C#, JavaScript) and ability to read application code
- Experience validating cloud-hosted environments including IAM, secrets management, storage security, network security groups, Kubernetes and container security, serverless, and cloud misconfiguration assessments
- Security certifications (OSCP, OSWE, CEH, GWAPT, CISSP) are desirable
- Nice-to-have: Kubernetes, Docker, Terraform, GitHub Advanced Security, CodeQL, AI/LLM security testing, red team experience, bug bounties, CTF participation
What We Do
Disprz is an AI-powered, mobile upskilling and reskilling suite, helping enterprises unlock business potential by enabling organization-wide skilling, while personalizing learning for the individual. Be it knowledge or frontline workers, Disprz identifies and benchmarks employees’ skills needed for different job roles, assesses their current levels, creates impactful learning pathways, drives hyper-personalized learning to bridge skill gaps and drives learning adoption. Disprz makes available insightful analytics that link back skilling to business performance. Our goal is to empower organizations to drive the right skills to create immediate and sustained business impact - be it higher sales, better customer service, impactful leadership, or digital transformation. In addition to Disprz’s LMS and LXP platforms, our unique frontline enablement solution (FLE) is a mobile learning platform designed to address the unique needs of the distributed workforce. With multilingual options and a mobile-first approach, it helps keep the deskless workforce engaged & productive while learning. It includes features such as KPI-linked coaching, proctored assessments and on-the-job training workflows to enable them to be job-ready from Day 1. Our capability-building platform powers 250+ leading organizations like Amazon,Uber, Airtel, Bajaj Allianz, and Tata Motors, to name a few. 1.8 million + learners across the United States, India, Southeast Asia, and the Middle East, leverage our skills enhancement platform.







