📢 New: get today's jobs on our WhatsApp Channel
Jobiglo

No results.

Senior Security Engineer – Vulnerability Management & Penetration Testing

Truveta · Hyderabad

Senior 🇬🇧 English
API security testing OWASP Top 10 SAST DAST Dependency scanning Container scanning Azure Kubernetes security Bug bounty Red teaming OSCP CEH GWAPT

Job description

About the role

Truveta is seeking a Senior Security Engineer to lead vulnerability management and penetration testing across its applications and infrastructure. The role is hands‑on, focusing on identifying, validating, and remediating security issues while building scalable processes to improve the overall security posture.

Key responsibilities

  • Own the full vulnerability management lifecycle: continuous scanning of applications, infrastructure, and dependencies, risk‑based prioritization, tracking, and remediation.
  • Perform penetration testing on web applications, APIs, and cloud environments, validating findings and eliminating false positives.
  • Partner with engineering teams to fix vulnerabilities and prevent recurrence.
  • Implement and manage security tools for SAST, DAST, dependency, infrastructure, and container scanning.
  • Develop repeatable testing methodologies, automation, and adversarial testing to simulate real‑world attacks.
  • Track metrics, report on risk posture, and contribute to secure development practices.

Required profile

  • 5–9+ years of experience in security engineering, vulnerability management, or penetration testing.
  • Hands‑on experience with web and API security testing and common vulnerabilities (OWASP Top 10, misconfigurations, authentication flaws).
  • Strong understanding of attack techniques, exploitation methods, and cloud environments (Azure preferred).
  • Relevant certifications such as OSCP, CEH, or GWAPT are a plus.

Required skills

  • Web application security testing
  • API security testing
  • OWASP Top 10 knowledge
  • SAST and DAST tools
  • Dependency, infrastructure, and container scanning
  • Azure cloud environment
  • CI/CD pipeline automation for security testing
  • Kubernetes and container security
  • Bug bounty or red‑team experience
  • OSCP, CEH, GWAPT certifications

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec Truveta.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

Apply now →

By continuing, you accept our terms of use.

Already have an account? Login

A question about this job?

Ask it here: you will get the full job summary by e-mail, right away.

💬 Chat with us on Telegram

Published 1 month ago

Expires 1 week from now

33 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

Truveta

Hyderabad