This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an Application Security Engineer II - Contract based in India.
As an Application Security Engineer II, you will play a key role in triaging and validating security vulnerability submissions across large-scale managed security programs. You will assess incoming reports for validity, accuracy, exploitability, and severity while helping ensure that critical vulnerabilities are identified and communicated quickly. The role provides exposure to a wide range of application security challenges and advanced security research techniques. You will work with skilled security researchers and collaborate directly with clients when additional technical information is needed. Beyond web application security, you may encounter programs covering mobile, hardware, IoT, embedded systems, desktop environments, and emerging technologies such as Web3. This is a strong opportunity to deepen your offensive security expertise while contributing to a fast-moving, globally distributed security environment.
Accountabilities:
- Triage and validate incoming security vulnerability submissions across managed security programs, assessing reports for technical validity, accuracy, impact, exploitability, and severity.
- Investigate reported vulnerabilities using industry-standard application security and penetration-testing techniques, with strong attention to OWASP Top Ten vulnerability classes such as XSS, SQL injection, XXE, IDOR, SSTI, and SSRF.
- Communicate directly with security researchers when additional evidence, reproduction steps, clarification, or technical information is required to validate a submission.
- Collaborate with client stakeholders to communicate significant findings, clarify technical details, and support effective vulnerability remediation and risk management.
- Participate in incident response activities by escalating and communicating high-severity vulnerabilities and ensuring critical findings receive appropriate attention.
- Use tools such as Burp Suite or other interception proxies, along with security testing utilities including Nmap, SQLMap, and tools available through Kali Linux.
- Contribute to improving triage and validation workflows by using scripting or development skills to design, build, or enhance internal security tooling and automation.
- Support security assessment across a broad range of technologies, potentially including web applications, mobile applications, desktop systems, hardware, IoT, embedded systems, Web3/blockchain, and thick clients such as Electron applications.
- Manage individual projects and assigned investigations independently while remaining an active contributor to the broader security team and meeting agreed deadlines.
- Bachelor’s degree in a relevant field or equivalent professional experience in security consulting, application security, penetration testing, or security assessment.
- Demonstrated passion for security research, vulnerability discovery, penetration testing, or application security, ideally supported by published research, write-ups, contributions, or other evidence of technical engagement with the security community.
- Strong practical knowledge of application security and OWASP Top Ten vulnerabilities, with the ability to assess complex findings and determine their validity and severity.
- High proficiency with Burp Suite or another interception proxy and working experience with industry-standard security testing tools such as Nmap, SQLMap, and Kali Linux utilities.
- Strong analytical and investigative skills, with the ability to reproduce vulnerabilities, understand attack paths, assess technical impact, and make sound triage decisions.
- Experience or interest in scripting or software development, particularly where programming can be used to improve security testing, triage, validation, or automation workflows.
- Ability to work independently on technical investigations and projects while collaborating effectively with distributed teams and security professionals.
- Strong organization and time-management skills, with the ability to prioritize multiple submissions and complete tasks within expected timelines.
- Excellent written and verbal communication skills, including the ability to influence, clarify technical findings, and communicate effectively with both technical and non-technical stakeholders.
- Experience with hardware, Web3/blockchain, desktop, mobile, thick-client, or broader security triage is valuable, reflecting the diverse environments covered by the role.
- Relevant security certifications are advantageous.
- 6-month contract opportunity in a fully remote, work-from-home environment in India.
- Exposure to a large and diverse portfolio of security programs, providing the opportunity to work across many different technologies and organizations.
- Direct exposure to advanced vulnerability research and cutting-edge security testing methodologies from experienced security researchers.
- Opportunities to deepen expertise across application security, penetration testing, vulnerability triage, incident response, and emerging technology environments.
- Broad technical exposure spanning web, mobile, desktop, hardware, IoT, embedded systems, thick clients, and Web3/blockchain technologies.
- Opportunity to develop and improve security tooling, automation, and triage processes using scripting and development skills.
- Collaborative environment with experienced security professionals and international stakeholders.
- Strong opportunity for continuous technical learning and professional growth within the cybersecurity field.
- Compensation and any additional contract benefits are determined by the hiring company and will be discussed during the recruitment process.
- Reasonable accommodations are available for qualified individuals who require them to participate in the application or interview process or perform the essential functions of the role.

