Live opening · Posted 4 days ago

Security Engineer

Sonata Software · Pune District, Maharashtra, India (On-site)
Linkedin No
You are 4 days behind. JobBeeper subscribers saw this role while it was still new.

At a glance

The key details from the original listing.

Posted 4 days ago
CompanySonata Software
LocationPune District, Maharashtra, India (On-site)
Work modeNo
SourceLinkedin
Listed4 days ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
6 min from Linkedin publishing this role to us finding it
16 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
60,930 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

Security Engineer (VAPT and Remediation)
Location: Pune (Hybrid)
Experience: 5+ years
Availability: 0-15 days
About the role
This is a hands-on security engineering role that owns the full cycle: find the vulnerability, prove it, fix it, and confirm it stays fixed. You will run penetration tests and security reviews across our applications and infrastructure, then remediate what you find, in application code or in configuration, whatever the fix requires.
What you will do
Security Analysis and Testing
Plan and execute penetration tests on web applications, APIs, mobile apps (iOS and Android), thick clients, and supporting infrastructure.
Review application and infrastructure security design: authentication and authorization, session handling, data flows, secrets management, network exposure, and cloud configuration.
Find what scanners miss through manual testing: business logic flaws, chained vulnerabilities, and privilege escalation paths.
Run and tune vulnerability scans across applications, hosts, and cloud accounts.
Triage, deduplicate, and prioritize findings by exploitability and business impact alongside CVSS.
Track remediation to closure and maintain an accurate view of open risk.
Retest fixes and close findings only when the vulnerability is confirmed resolved.
Remediation and patching
Fix vulnerabilities directly in application code, in whatever language or framework the application uses.
Fix infrastructure and configuration issues: web server and TLS settings, cloud IAM and network rules, container and Kubernetes configuration, infrastructure-as-code, and CI/CD pipeline hardening.
Apply patches and upgrades to operating systems, frameworks, libraries, and third-party components, and verify the exposure is closed.
Where code or infrastructure is owned by another team, raise the change yourself as a pull request or configuration change and drive it to merge.
Reporting and communication
Write clear findings with reproduction steps, evidence, risk rating, and specific remediation guidance.
Explain risk to developers, DevOps engineers, and non-technical stakeholders, and agree on realistic remediation timelines.
What you bring
Experience
5+ years in penetration testing, application security, or security engineering, with a track record of fixing the vulnerabilities you report.
Deep VAPT expertise
Web: manual testing with Burp Suite Professional; OWASP Top 10 and ASVS; injection, authentication and session flaws, access control (IDOR/BOLA), SSRF, deserialization, XXE, race conditions, and business logic abuse.
API: REST, GraphQL, SOAP, and gRPC; OAuth 2.0, OpenID Connect, and JWT weaknesses; mass assignment, rate limiting, and object-level authorization failures.
Mobile (iOS and Android): static and dynamic analysis against OWASP MASVS/MASTG; Frida, Objection, MobSF, jadx, and Ghidra or Hopper; SSL pinning and root/jailbreak detection bypass; insecure storage, IPC, and deep link issues.
Thick client: interception of non-HTTP protocols, reverse engineering of .NET, Java, and native binaries, memory and local storage analysis, DLL hijacking, and client-side trust issues.
Infrastructure: network and host testing with Nmap, Nessus, and Metasploit; Active Directory fundamentals; Linux and Windows hardening.
Remediation skills
Able to read and modify code in multiple languages. Expect a mix that may include Java, C#/.NET, JavaScript/TypeScript, Python, PHP, Go, Swift, and Kotlin. Depth in at least two of these, and the ability to land a correct, tested fix in an unfamiliar codebase.
Scripting in Python, Bash, or PowerShell to automate testing and remediation.
Practical experience with Git-based workflows, pull requests, and code review.
Working knowledge of Nginx, Apache, IIS, TLS configuration, Docker, Kubernetes, and infrastructure-as-code such as Terraform or CloudFormation.
Working knowledge (fundamentals level)
Cloud security: IAM, networking, storage, logging, and encryption across AWS, Azure, and GCP; CIS benchmarks; CSPM and cloud audit tooling such as Prowler.
Vulnerability assessment: enterprise scanners, CVSS, and patch management processes.
SOC operations: SIEM concepts, log analysis, incident response fundamentals, and MITRE ATT&CK; able to support incident triage with attacker-perspective input and feed detection ideas back from test findings.
Communication
Clear written reports and the ability to explain risk and trade-offs to engineers and business stakeholders.
Nice to have
Public security research, CVEs, bug bounty findings, or CTF experience.
Experience integrating SAST, DAST, and SCA tooling such as Aikido into CI/CD pipelines.
Threat modeling and secure design review experience.
Familiarity with compliance evidence requirements (ISO 27001, SOC 2, PCI DSS) as they relate to vulnerability remediation.
What success looks like
Findings from your tests reach confirmed, retested fixes within agreed timelines.
Development and DevOps teams see you as someone who fixes problems alongside them.
Recurring vulnerability classes decline over time because fixes address root causes.
Cloud misconfiguration and patch exposure windows stay short.

Work arrangement
No

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App