ASAI job platform logo
  1. Home
  2. /Jobs
  3. /Security Engineer Jobs in Pune
  4. /Security Compliance
SonataOne

Security Compliance

Pune · Senior

Recently posted - highest visibilityVerified listingPosted 2d ago

Applicants who checked fit first are 3.1× more likely to hear back

Your match scoreCalculated · locked
86Overall
64Skills
97Experience

Your score for this role already exists

ASAI compared this JD against 41 signals - skills, seniority, domain, stack overlap etc. Add a resume and it unlocks in about 30 seconds.

No credit card · 1 tap with Google

What we know about this role

Hiring pulse

HIGH

SonataOne is actively reviewing profiles and moving candidates through the pipeline right now.

Apply window

First 72 hours

Still inside it - posted 2d ago

Early applicants get seen before the pile builds.

Not a repost

The first time we've seen this listing - it hasn't been closed and reopened.

Skills required

55 listed
CI/CDPenetration TestingInfrastructure SecuritySecurity AnalysisReviewing ApplicationsPrivilege EscalationWeb ServersBurp Suite+47 more
CI/CDPenetration TestingInfrastructure SecuritySecurity AnalysisReviewing Applications

You almost certainly match several of these already. Unlock your skill map to see the matches, the gaps, and what to fix first.

Job description

Job Description

Job Title- Security Engineer (VAPT & Remediation)
Location- Pune | Hybrid
Experience- 5–8 Years
Primary Skills- VAPT / Penetration Testing, Web & API Security, Vulnerability Remediation, Cloud & Infrastructure Security

ABOUT THE ROLE

This is a hands-on security engineering role responsible for the complete vulnerability lifecycle—identifying vulnerabilities, validating their impact, implementing remediation, and confirming that fixes are effective. The role involves penetration testing and security reviews across applications, APIs, mobile applications, infrastructure, and cloud environments, along with direct remediation through application code and infrastructure configuration.

ROLES AND RESPONSIBILITIES

Security Analysis & Testing

  • Plan and execute penetration tests across web applications, APIs, mobile applications, thick clients, and supporting infrastructure.

  • Review application and infrastructure security covering authentication, authorization, session management, data flows, secrets management, network exposure, and cloud configurations.

  • Identify vulnerabilities beyond automated scanners through manual testing, including business logic flaws, chained vulnerabilities, and privilege escalation.

  • Execute and tune vulnerability scans across applications, hosts, and cloud environments.

  • Triage, deduplicate, and prioritize findings based on exploitability, business impact, and CVSS.

  • Track vulnerabilities through remediation and maintain accurate risk status.

  • Retest fixes and close findings only after confirming successful remediation.

Remediation & Patching

  • Remediate vulnerabilities directly in application code across different languages and frameworks.

  • Fix infrastructure and configuration vulnerabilities involving web servers, TLS, cloud IAM, network rules, containers, Kubernetes, IaC, and CI/CD pipelines.

  • Apply security patches and upgrades to operating systems, frameworks, libraries, and third-party components.

  • Raise pull requests or configuration changes for vulnerabilities owned by other teams and drive them through completion.

Reporting & Communication

  • Prepare clear security findings with reproduction steps, evidence, risk ratings, and remediation guidance.

  • Communicate security risks and remediation requirements effectively to developers, DevOps teams, and business stakeholders.

QUALIFICATIONS & REQUIRED SKILLS

  • 5+ years of experience in penetration testing, application security, or security engineering with hands-on vulnerability remediation experience.

  • Strong understanding of VAPT methodologies, OWASP Top 10, OWASP ASVS, and secure application design.

  • Experience with manual penetration testing using Burp Suite Professional.

  • Strong knowledge of web and API security, including REST, GraphQL, SOAP, gRPC, OAuth 2.0, OpenID Connect, and JWT.

  • Experience identifying injection, authentication/session flaws, IDOR/BOLA, SSRF, deserialization, XXE, race conditions, business logic vulnerabilities, mass assignment, rate limiting, and authorization issues.

  • Hands-on mobile security testing across iOS and Android using tools such as Frida, Objection, MobSF, jadx, Ghidra, or Hopper.

  • Experience with thick-client security testing, reverse engineering, memory/local storage analysis, DLL hijacking, and client-side trust issues.

  • Infrastructure security testing experience using Nmap, Nessus, and Metasploit.

  • Working knowledge of Active Directory, Linux, and Windows security hardening.

  • Ability to read and modify code in multiple languages, with strong proficiency in at least two of Java, C#/.NET, JavaScript/TypeScript, Python, PHP, Go, Swift, or Kotlin.

  • Scripting experience using Python, Bash, or PowerShell.

  • Practical experience with Git workflows, pull requests, and code reviews.

  • Working knowledge of Nginx, Apache, IIS, TLS, Docker, Kubernetes, Terraform, or CloudFormation.

MANDATORY SKILLS

  • VAPT / Penetration Testing

  • Web Application Security & OWASP

  • API Security

  • Burp Suite Professional

  • Vulnerability Assessment & Remediation

  • Mobile / Thick Client Security Testing

  • Infrastructure & Network Security

  • Secure Coding & Vulnerability Remediation

  • Python / Bash / PowerShell Scripting

  • Git & Code Review

  • Docker / Kubernetes

  • Cloud Security Fundamentals across AWS, Azure, and GCP

GOOD TO HAVE SKILLS

  • Public security research, CVEs, bug bounty, or CTF experience.

  • SAST, DAST, and SCA integration into CI/CD pipelines.

  • Experience with security tooling such as Aikido.

  • Threat modeling and secure design reviews.

  • Knowledge of CIS benchmarks, CSPM, and tools such as Prowler.

  • SIEM, log analysis, incident response, and MITRE ATT&CK fundamentals.

  • Experience supporting SOC incident triage and detection engineering.

  • Knowledge of ISO 27001, SOC 2, and PCI DSS compliance requirements related to vulnerability remediation.

SUCCESS MEASURES

  • Security findings are remediated and successfully retested within agreed timelines.

  • Development and DevOps teams are supported through hands-on remediation.

  • Recurring vulnerability classes reduce through root-cause remediation.

  • Cloud misconfigurations and patch exposure windows remain minimal.

ABOUT SONATA SOFTWARE

Sonata Software is an AI-first modernization engineering company that helps enterprises transform legacy systems into intelligent, scalable business platforms. Powered by its Platformation™ framework and Harmoni.AI platform, Sonata delivers AI-led modernization across cloud, data, AI, Dynamics, test automation, and managed services. Headquartered in Bengaluru, India, Sonata has more than $1.2 billion in revenue and 6,400+ AI engineers supporting global delivery across regions including the US, UK, India, Malaysia, Mexico, Australia, DACH, and the Nordics. With deep partnerships across Microsoft, AWS, Salesforce, and Snowflake, Sonata helps Fortune 500 enterprises accelerate innovation, improve efficiency, and drive sustainable growth. For more information, please visit www.sonata-software.com.

Free · no signup

Get tomorrow's jobs before you have to search

Daily job drops, skill trends and free resources - posted straight to the group. Leave any time.

Join WhatsAppJoin Telegram

No spam. Just jobs and resources.

Why people use ASAI

Someone shared one job with you. ASAI keeps finding the rest.

  • Scored, not searched. Every role ranked against your actual profile.

  • Alerts as often as hourly. Reach new roles while the pile is still small.

  • Skill gaps, spelled out. See exactly which requirements you don't meet yet.

  • Verified jobs, only. Say no to ghost jobs. Your time deserves respect.

More Security Engineer roles in Pune

See all

Lead - Security Architecture

NT Careers · Pune

Senior Staff Engineer, Product Security

Druva · Pune

Senior Network Engineer

Ensono · Pune

Security Research Engineer

Cowbell Cyber Inc. · Pune

Keep browsing

All open roles at SonataOneAll Security Engineer jobs in Pune

Two ways in

Applicants who checked fit first are 3.1× more likely to hear back

Your match scoreCalculated · locked
86Overall
64Skills
97Experience

Your score for this role already exists

ASAI compared this JD against 41 signals - skills, seniority, domain, stack overlap etc. Add a resume and it unlocks in about 30 seconds.

No credit card · 1 tap with Google

Free · no signup

Get tomorrow's jobs before you have to search

Daily job drops, skill trends and free resources - posted straight to the group. Leave any time.

Join WhatsAppJoin Telegram

No spam. Just jobs and resources.

Why people use ASAI

Someone shared one job with you. ASAI keeps finding the rest.

  • Scored, not searched. Every role ranked against your actual profile.

  • Alerts as often as hourly. Reach new roles while the pile is still small.

  • Skill gaps, spelled out. See exactly which requirements you don't meet yet.

  • Verified jobs, only. Say no to ghost jobs. Your time deserves respect.

ASAI job platform logo

A job platform finally, balanced in your favour.

Jobs by CityJobs by CompanyGuidesHow We VerifyAboutPrivacy PolicyTerms of Service

Built in India 🇮🇳

© 2026 ASAI. All rights reserved.