ASAI job platform logo
  1. Home
  2. /Jobs
  3. /Security Engineer Jobs in Mumbai
  4. /Sr Security Consultant – Web, Mobile, API & SCR
Talakunchi

Sr Security Consultant – Web, Mobile, API & SCR

Mumbai · Mid Level

Good timing - competition is buildingVerified listingPosted 12d ago

Applicants who checked fit first are 3.1× more likely to hear back

Your match scoreCalculated · locked
86Overall
64Skills
97Experience

Your score for this role already exists

ASAI compared this JD against 41 signals - skills, seniority, domain, stack overlap etc. Add a resume and it unlocks in about 30 seconds.

No credit card · 1 tap with Google

What we know about this role

Hiring pulse

MEDIUM

Talakunchi is reviewing applications at a steady pace. Expect a standard response time as they evaluate the current pool.

Apply window

First 72 hours

Window passed - posted 12d ago

Early applicants get seen before the pile builds.

Not a repost

The first time we've seen this listing - it hasn't been closed and reopened.

Skills required

11 listed
Web Application SecuritySecurity TestingBurp SuiteAccess ControlsMobile SecurityTechnical ReportApplication Programming Interface (API)Android (Operating System)+3 more
Web Application SecuritySecurity TestingBurp SuiteAccess ControlsMobile Security

You almost certainly match several of these already. Unlock your skill map to see the matches, the gaps, and what to fix first.

Job description

Role Overview

We are looking for an experienced Application Security Tester with 3–6 years of hands-on experience in Web, Mobile, API Security Testing and Secure Code Review (SCR). Experience in BFSI, UPI/payment applications and security compliance will be preferred.
The candidate should have strong technical skills along with exposure to team coordination, client interaction and audit support.

Key Responsibilities

  • Perform Web Application Security Testing based on OWASP Top 10 and industry-standard methodologies.
  • Conduct Mobile Application Security Testing for Android/iOS.
  • Perform API Security Testing using Burp Suite, Postman, OWASP ZAP, etc.
  • Conduct Secure Code Review (SCR) and identify insecure coding practices.
  • Identify and validate vulnerabilities related to authentication, authorization, access control, injection, session management, sensitive data, business logic and API security.
  • Perform vulnerability retesting and remediation validation.
  • Prepare detailed VAPT/security assessment reports with evidence, impact and remediation recommendations.
  • Perform/support security testing of UPI/payment applications, including API security, transaction flows, authentication, authorization and business logic.
  • Support PCI-DSS and other security audits with VAPT reports, evidence, remediation and retest documentation.
  • Coordinate with development/application teams for vulnerability remediation and closure.
  • Handle client queries and participate in security review meetings.

Team Handling & Coordination

  • Coordinate day-to-day activities of junior security testers.
  • Allocate testing tasks and track assessment deliverables and timelines.
  • Review vulnerability findings and reports for quality and technical accuracy.
  • Mentor junior team members on application security testing and vulnerability validation.
  • Coordinate with project managers, developers, application owners and client stakeholders.
  • Support multiple security assessments and track remediation/closure.

Audit & Compliance Support

  • Support PCI-DSS audits/assessments and client security compliance requirements.
  • Prepare audit evidence including VAPT reports, scope, methodology, findings, remediation and retest results.
  • Coordinate with auditors and stakeholders for security testing-related queries.
  • Maintain assessment documentation and evidence for audit readiness.

Required Skills

  • 3–6 years of hands-on Application Security / VAPT experience.
  • Strong experience in Web, API and Mobile Security Testing.
  • Hands-on experience in Secure Code Review.
  • Strong knowledge of OWASP Top 10 and application security fundamentals.
  • Understanding of JWT, OAuth, API authentication/authorization and business logic vulnerabilities.
  • Hands-on experience with Burp Suite, Postman, MobSF and OWASP ZAP.
  • Exposure to Frida / Objection is an advantage.
  • BFSI, UPI/payment application and PCI-DSS exposure preferred.
  • Good technical report writing, communication and stakeholder management skills.
  • Team coordination/mentoring experience preferred.

Certifications – Preferred

  • eWPT / eMAPT
  • CEH
  • OSCP / OSWE
  • CREST or equivalent
Practical hands-on experience will be preferred over certification alone.

Qualification

  • Bachelor's degree in Computer Science / IT / Cybersecurity or equivalent.
  • Strong analytical, communication and documentation skills.
  • Ability to work in a structured, compliance-driven BFSI environment.

Free · no signup

Get tomorrow's jobs before you have to search

Daily job drops, skill trends and free resources - posted straight to the group. Leave any time.

Join WhatsAppJoin Telegram

No spam. Just jobs and resources.

Why people use ASAI

Someone shared one job with you. ASAI keeps finding the rest.

  • Scored, not searched. Every role ranked against your actual profile.

  • Alerts as often as hourly. Reach new roles while the pile is still small.

  • Skill gaps, spelled out. See exactly which requirements you don't meet yet.

  • Verified jobs, only. Say no to ghost jobs. Your time deserves respect.

More Security Engineer roles in Mumbai

See all

Infrastructure Security Engineer-L2 (Palo Alto & NGFW)

Gruve · Mumbai

Presales Engineer - Cyber Security experience is a must**

SonicWall · Remote (Mumbai)

Information Security Engineer

IMC · Mumbai

SECURITY CONSULTANT

Jensen Hughes · Mumbai

Keep browsing

All open roles at TalakunchiAll Security Engineer jobs in Mumbai

Two ways in

Applicants who checked fit first are 3.1× more likely to hear back

Your match scoreCalculated · locked
86Overall
64Skills
97Experience

Your score for this role already exists

ASAI compared this JD against 41 signals - skills, seniority, domain, stack overlap etc. Add a resume and it unlocks in about 30 seconds.

No credit card · 1 tap with Google

Free · no signup

Get tomorrow's jobs before you have to search

Daily job drops, skill trends and free resources - posted straight to the group. Leave any time.

Join WhatsAppJoin Telegram

No spam. Just jobs and resources.

Why people use ASAI

Someone shared one job with you. ASAI keeps finding the rest.

  • Scored, not searched. Every role ranked against your actual profile.

  • Alerts as often as hourly. Reach new roles while the pile is still small.

  • Skill gaps, spelled out. See exactly which requirements you don't meet yet.

  • Verified jobs, only. Say no to ghost jobs. Your time deserves respect.

ASAI job platform logo

A job platform finally, balanced in your favour.

Jobs by CityJobs by CompanyGuidesHow We VerifyAboutPrivacy PolicyTerms of Service

Built in India 🇮🇳

© 2026 ASAI. All rights reserved.