Jobiglo

No results.

This job is no longer available

This job expired on 19/08/2026. It no longer accepts applications.

Security Tester (VAPT Engineer)

SourceFuse · District de Mohali

Mid 🇬🇧 English
OWASP Top 10 SSRF SSTI XXE CSRF RCE IDOR Android iOS Dynamic analysis Frida Objection MobSF JADX Hopper Ghidra API security testing REST GraphQL SOAP gRPC OAuth JWT API keys Cloud security AWS Azure GCP IAM Prompt injection Jailbreak attacks Data leakage Model manipulation Burp Suite

Job description

About the role

SourceFuse Technologies is seeking a proactive Security Tester / VAPT Engineer with 3‑5 years of hands‑on experience. You will perform security assessments across web, mobile, API, cloud, network, and AI/LLM platforms, identify vulnerabilities, validate exploits, and guide remediation.

Key responsibilities

  • Conduct comprehensive VAPT for web applications using manual and automated techniques, covering OWASP Top 10, authentication/authorization flaws, business logic issues, and advanced attacks such as SSRF, SSTI, XXE, CSRF, RCE, IDOR.
  • Perform security testing of Android and iOS apps, including static/dynamic analysis, runtime instrumentation, reverse engineering, SSL‑pinning bypass, and local storage/keychain review.
  • Test REST, GraphQL, SOAP, and gRPC APIs for broken object level authorization, injection, rate‑limit bypass, and data exposure; validate OAuth, JWT, and API‑key mechanisms.
  • Assess cloud environments (AWS, Azure, GCP) for misconfigurations, IAM weaknesses, storage and network security issues.
  • Execute network and infrastructure VAPT: port enumeration, firewall review, internal/external testing of servers, VPNs, wireless networks, and exposed services.
  • Evaluate AI/LLM‑based applications for prompt injection, jailbreak attacks, data leakage, model manipulation, and insecure plugin integrations.
  • Prepare detailed vulnerability reports with risk ratings, PoCs, and remediation guidance; collaborate with development and DevOps teams.

Required profile

  • 3‑5 years of experience in security testing and vulnerability assessment.
  • Strong knowledge of offensive security techniques, secure development practices, and modern attack vectors.
  • Ability to work independently, produce clear documentation, and communicate findings to technical and non‑technical stakeholders.

Required skills

  • Web application VAPT (OWASP Top 10, authentication/authorization, SSRF, SSTI, XXE, CSRF, RCE, IDOR).
  • Mobile security testing (Android, iOS) – static & dynamic analysis, Frida, Objection, MobSF, JADX, Hopper, Ghidra.
  • API security testing – REST, GraphQL, SOAP, gRPC, OAuth, JWT, API keys.
  • Cloud security – AWS, Azure, GCP, IAM, storage and network configuration review.
  • Network & infrastructure testing – port enumeration, firewall assessment, VPN and wireless security.
  • AI/LLM security – prompt injection, jailbreak, data leakage, model manipulation.
  • Tools: Burp Suite, Wireshark, Nmap, Metasploit, and scripting languages for automation.

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec SourceFuse.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.
💬 Chat with us on Telegram Chat on WhatsApp

Published 3 months ago

28 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

SourceFuse

District de Mohali