Security Analyst – Application Security VAPT
Job Summary
Job Title: Security Analyst Application Security VAPT & CERTIn Empanelment/Experience (Mandatory)
Experience: 5 Years
Location: Client Location
Certification: CEH (Certified Ethical Hacker) Mandatory
Job Summary
We are seeking an experienced Security Analyst with strong expertise in Application Security and
VAPT to join our security team. The ideal candidate will be responsible for conducting
comprehensive security assessments of web and mobile applications performing secure code
reviews and supporting the organization in strengthening its overall application security posture.
Key Responsibilities
- Perform Vulnerability Assessment and Penetration Testing (VAPT) for web applications mobile
- applicationsnetwork and APIs.
- Conduct Static Application Security Testing (SAST) to identify security vulnerabilities in source code.
- Perform Dynamic Application Security Testing (DAST) to detect runtime vulnerabilities in applications.
- Carry out Secure Code Reviews to identify security flaws and recommend remediation.
- Perform Software Composition Analysis (SCA) to identify vulnerabilities in third-party libraries and open-source components.
- Identify analyze and validate security vulnerabilities and provide detailed risk-based reports with remediation recommendations.
- Work closely with development and DevOps teams to ensure secure coding practices and assist invulnerability remediation.
- Conduct re-testing and validation of vulnerabilities after remediation.
- Prepare and present detailed security assessment reports to internal stakeholders and clients.
Required Skills
- Strong hands-on experience in Web Application VAPTAPIs and Mobile Application VAPT.
- Solid understanding of OWASP Top 10 API Security Top 10 and common application security vulnerabilities.
- Experience in SAST DAST and SCA tools and methodologies.
- Knowledge of secure coding principles and common programming vulnerabilities.
- Experience in manual penetration testing techniques and vulnerability validation.
- Understanding of authentication authorization session management and cryptographic security issues.
Tools & Technologies
- Hands-on experience with the following tools is required:
- SonarQube Fortify Burp Suite and Other application security and penetration testing tools
Education
- Bachelors degree in Computer Science Cyber Security Information Technology or any other
- CEH (Certified Ethical Hacker) Mandatory
Preferred Skills
- Knowledge of CI/CD security integration.
- Experience in cloud security testing (AWS / Azure / GCP) is an added advantage.
- Strong communication skills for client interaction and technical reporting.
Soft Skills
- Strong analytical and problem-solving skills
- Ability to work independently and manage multiple assessments
- Good documentation and reporting capabilities