Assistant Manager | Web/Mobile/API Application Security | Bengaluru | Cyber Defense & Resilience | A
Deloitte
Deloitte
Join our Cyber Defense & Resilience team as an Assistant Manager focused on Web, Mobile, and API Application Security. You will play a crucial role in ensuring the security of our applications by validating controls and remediation measures. This position offers an exciting opportunity to contribute to Deloitte's mission of protecting valuable assets and enabling new opportunities through effective cyber risk management.
We are looking for a proactive Application Security Engineer with practical experience in assessing the security of web, mobile, and API applications. Your expertise will be vital in identifying, validating, and reporting vulnerabilities, fostering collaboration with development teams, and championing secure software development practices.
Key responsibilities include conducting thorough security assessments and penetration tests for web, mobile (Android/iOS), and APIs. You will identify, validate, and meticulously report vulnerabilities, referencing standards like OWASP Top 10. Performing both manual and automated testing for authentication, authorization, business logic, and data validation is essential. Furthermore, you will support secure code reviews, offer remediation guidance, assist with threat modeling, and prepare clear technical reports for stakeholders.
Candidates should possess 2–5 years of dedicated experience in Application Security, Penetration Testing, or Vulnerability Assessment. A strong grasp of web, mobile, and API security concepts is required, along with hands-on proficiency in tools such as Burp Suite, OWASP ZAP, MobSF, and Postman. A solid understanding of authentication mechanisms, session management, encryption, and secure coding principles is necessary. Familiarity with common programming languages and application architectures is also expected.
While not mandatory, certifications like OSCP, eWPT, GWAPT, CEH, or CSSLP are highly valued. Experience with DevSecOps, CI/CD security integration, and cloud application security would be a significant advantage.
Deloitte
IT Consulting