Apply with hirly
Application Security Tester (Web, Mobile & API) – BFSI Domain
Talakunchi Networks · Mumbai, India
Upload your resume to see how well you match this job — free, in seconds, no account needed.
Your resume is used only to score it against this job. If you don't create an account, it is deleted within 24 hours.
Application Security Tester (Web, Mobile & API) – BFSI Domain Experience: 1–2 Years Location: Thane Ghodbunder Road(Onsite) Domain: BFSI (Banking / Financial Services / Insurance) Role Overview We are looking for a motivated Application Security Tester with 1–2 years of hands-on experience in Web, Mobile, and API Security Testing , preferably within the BFSI domain . The candidate should have strong fundamentals in application security testing methodologies and vulnerability assessment aligned with industry standards. Key Responsibilities
- Perform Web Application Security Testing using industry-standard methodologies such as OWASP Top 10
- Conduct Mobile Application Security Testing (Android/iOS – basic to intermediate level)
- Perform API Security Testing using tools like Postman and Burp Suite
- Identify vulnerabilities such as:
- Authentication & authorization issues
- Injection flaws
- Sensitive data exposure
- Business logic issues
- Validate vulnerabilities and perform retesting after fixes
- Prepare detailed vulnerability assessment reports
- Support client queries and remediation validation
- Follow secure testing practices aligned with BFSI expectations Required Skills Mandatory:
- Hands-on experience in Web Application Security Testing
- Basic experience in Mobile App Security Testing
- Understanding of API Security Testing concepts
- Familiarity with:
- Burp Suite
- MobSF •
Owasp Zap
- Knowledge of:
- OWASP Top 10
- Basic secure coding issues
- Authentication & session management vulnerabilities Good to Have:
- Exposure to BFSI applications
- Understanding of API authentication (JWT / OAuth basics)
- Experience with runtime testing tools like Frida or Objection
- Certification (any one preferred):
- eWPT
- eMAPT
- CEH (Practical exposure preferred over theory) Qualification
- Bachelor’s Degree in Computer Science / IT / Cybersecurity or equivalent
- Strong understanding of application security fundamentals Soft Skills
- Good report writing skills
- Ability to communicate vulnerabilities clearly
- Willingness to learn BFSI security expectations
- Ability to work in a structured testing environment