Assistant Manager | Web/Mobile/API Application Security | Pune | Cyber Defense & Resilience | Attack (Pune, IN)
Deloitte
Deloitte
Join our Cyber Defense & Resilience team as an Assistant Manager in Pune, focusing on Attack. You will play a crucial role in strengthening our application security posture by validating security controls and ensuring vulnerabilities are effectively remediated.
This position is ideal for a motivated Application Security Engineer with practical experience in Web, Mobile, and API security assessments. Your expertise will be vital in identifying, validating, and reporting security weaknesses, fostering collaboration with development teams, and promoting secure software development lifecycles.
Key responsibilities include conducting in-depth security assessments and penetration tests for web, mobile (Android/iOS), and APIs. You will identify and report vulnerabilities in line with OWASP Top 10 standards. The role involves performing manual and automated testing, including authentication, authorization, and business logic checks.
You will also support secure code reviews, assist with threat modeling and risk assessments, and contribute to security validation throughout the SDLC. Preparing clear technical reports and presenting findings to stakeholders will be an integral part of this role.
A minimum of 2 to 5 years of experience in Application Security, Penetration Testing, or Vulnerability Assessment is required. A strong grasp of web, mobile, and API security principles is essential, along with hands-on experience with tools like Burp Suite, OWASP ZAP, MobSF, and Postman.
Familiarity with authentication mechanisms, encryption, and secure coding practices is necessary. While not mandatory, certifications such as OSCP, eWPT, GWAPT, CEH, or CSSLP are highly valued. Experience with DevSecOps, CI/CD integration, and cloud security is also advantageous. A B.Tech, BE, or Diploma is required.
Deloitte
Information Technology & Services