ASAI job platform logo
  1. Home
  2. /Jobs
  3. /Security Engineer Jobs in Pune
  4. /Security Compliance
SonataOne

Security Compliance

Pune · Senior

Recently posted - highest visibilityVerified listingPosted 18h ago

Applicants who checked fit first are 3.1× more likely to hear back

Your match scoreCalculated · locked
86Overall
64Skills
97Experience

Your score for this role already exists

ASAI compared this JD against 41 signals - skills, seniority, domain, stack overlap etc. Add a resume and it unlocks in about 30 seconds.

No credit card · 1 tap with Google

What we know about this role

Hiring pulse

HIGH

SonataOne is actively reviewing profiles and moving candidates through the pipeline right now.

Apply window

First 72 hours

Still inside it - posted 18h ago

Early applicants get seen before the pile builds.

Not a repost

The first time we've seen this listing - it hasn't been closed and reopened.

Skills required

55 listed
CI/CDPenetration TestingInfrastructure SecuritySecurity AnalysisReviewing ApplicationsPrivilege EscalationWeb ServersBurp Suite+47 more
CI/CDPenetration TestingInfrastructure SecuritySecurity AnalysisReviewing Applications

You almost certainly match several of these already. Unlock your skill map to see the matches, the gaps, and what to fix first.

Job description

Job Description

Security Engineer (VAPT & Remediation )

Location: Pune | Hybrid

Experience: 5-8 Years

Primary Skill:  VAPT / Penetration Testing | Web & API Security | Vulnerability Remediation | Cloud & Infrastructure Security

About the role

This is a hands-on security engineering role that owns the full cycle: find the vulnerability, prove it, fix it, and confirm it stays fixed. You will run penetration tests and security reviews across our applications and infrastructure, then remediate what you find, in application code or in configuration, whatever the fix requires.

What you will do

Security Analysis and Testing

  • Plan and execute penetration tests on web applications, APIs, mobile apps (iOS and Android), thick clients, and supporting infrastructure.

  • Review application and infrastructure security design: authentication and authorization, session handling, data flows, secrets management, network exposure, and cloud configuration.

  • Find what scanners miss through manual testing: business logic flaws, chained vulnerabilities, and privilege escalation paths.

  • Run and tune vulnerability scans across applications, hosts, and cloud accounts.

  • Triage, deduplicate, and prioritize findings by exploitability and business impact alongside CVSS.

  • Track remediation to closure and maintain an accurate view of open risk.

  • Retest fixes and close findings only when the vulnerability is confirmed resolved.

Remediation and patching

  • Fix vulnerabilities directly in application code, in whatever language or framework the application uses.

  • Fix infrastructure and configuration issues: web server and TLS settings, cloud IAM and network rules, container and Kubernetes configuration, infrastructure-as-code, and CI/CD pipeline hardening.

  • Apply patches and upgrades to operating systems, frameworks, libraries, and third-party components, and verify the exposure is closed.

  • Where code or infrastructure is owned by another team, raise the change yourself as a pull request or configuration change and drive it to merge.

Reporting and communication

  • Write clear findings with reproduction steps, evidence, risk rating, and specific remediation guidance.

  • Explain risk to developers, DevOps engineers, and non-technical stakeholders, and agree on realistic remediation timelines.

What you bring

Experience

  • 5+ years in penetration testing, application security, or security engineering, with a track record of fixing the vulnerabilities you report.

Deep VAPT expertise

  • Web: manual testing with Burp Suite Professional; OWASP Top 10 and ASVS; injection, authentication and session flaws, access control (IDOR/BOLA), SSRF, deserialization, XXE, race conditions, and business logic abuse.

  • API: REST, GraphQL, SOAP, and gRPC; OAuth 2.0, OpenID Connect, and JWT weaknesses; mass assignment, rate limiting, and object-level authorization failures.

  • Mobile (iOS and Android): static and dynamic analysis against OWASP MASVS/MASTG; Frida, Objection, MobSF, jadx, and Ghidra or Hopper; SSL pinning and root/jailbreak detection bypass; insecure storage, IPC, and deep link issues.

  • Thick client: interception of non-HTTP protocols, reverse engineering of .NET, Java, and native binaries, memory and local storage analysis, DLL hijacking, and client-side trust issues.

  • Infrastructure: network and host testing with Nmap, Nessus, and Metasploit; Active Directory fundamentals; Linux and Windows hardening.

Remediation skills

  • Able to read and modify code in multiple languages. Expect a mix that may include Java, C#/.NET, JavaScript/TypeScript, Python, PHP, Go, Swift, and Kotlin. Depth in at least two of these, and the ability to land a correct, tested fix in an unfamiliar codebase.

  • Scripting in Python, Bash, or PowerShell to automate testing and remediation.

  • Practical experience with Git-based workflows, pull requests, and code review.

  • Working knowledge of Nginx, Apache, IIS, TLS configuration, Docker, Kubernetes, and infrastructure-as-code such as Terraform or CloudFormation.

Working knowledge (fundamentals level)

  • Cloud security: IAM, networking, storage, logging, and encryption across AWS, Azure, and GCP; CIS benchmarks; CSPM and cloud audit tooling such as Prowler.

  • Vulnerability assessment: enterprise scanners, CVSS, and patch management processes.

  • SOC operations: SIEM concepts, log analysis, incident response fundamentals, and MITRE ATT&CK; able to support incident triage with attacker-perspective input and feed detection ideas back from test findings.

Communication

  • Clear written reports and the ability to explain risk and trade-offs to engineers and business stakeholders.

Nice to have

  • Public security research, CVEs, bug bounty findings, or CTF experience.

  • Experience integrating SAST, DAST, and SCA tooling such as Aikido into CI/CD pipelines.

  • Threat modeling and secure design review experience.

  • Familiarity with compliance evidence requirements (ISO 27001, SOC 2, PCI DSS) as they relate to vulnerability remediation.

What success looks like

  • Findings from your tests reach confirmed, retested fixes within agreed timelines.

  • Development and DevOps teams see you as someone who fixes problems alongside them.

  • Recurring vulnerability classes decline over time because fixes address root causes.

  • Cloud misconfiguration and patch exposure windows stay short.

 

 

Free · no signup

Get tomorrow's jobs before you have to search

Daily job drops, skill trends and free resources - posted straight to the group. Leave any time.

Join WhatsAppJoin Telegram

No spam. Just jobs and resources.

Why people use ASAI

Someone shared one job with you. ASAI keeps finding the rest.

  • Scored, not searched. Every role ranked against your actual profile.

  • Alerts as often as hourly. Reach new roles while the pile is still small.

  • Skill gaps, spelled out. See exactly which requirements you don't meet yet.

  • Verified jobs, only. Say no to ghost jobs. Your time deserves respect.

More Security Engineer roles in Pune

See all

Lead - Security Architecture

NT Careers · Pune

Senior Staff Engineer, Product Security

Druva · Pune

Senior Network Engineer

Ensono · Pune

Security Research Engineer

Cowbell Cyber Inc. · Pune

Keep browsing

All open roles at SonataOneAll Security Engineer jobs in Pune

Two ways in

Applicants who checked fit first are 3.1× more likely to hear back

Your match scoreCalculated · locked
86Overall
64Skills
97Experience

Your score for this role already exists

ASAI compared this JD against 41 signals - skills, seniority, domain, stack overlap etc. Add a resume and it unlocks in about 30 seconds.

No credit card · 1 tap with Google

Free · no signup

Get tomorrow's jobs before you have to search

Daily job drops, skill trends and free resources - posted straight to the group. Leave any time.

Join WhatsAppJoin Telegram

No spam. Just jobs and resources.

Why people use ASAI

Someone shared one job with you. ASAI keeps finding the rest.

  • Scored, not searched. Every role ranked against your actual profile.

  • Alerts as often as hourly. Reach new roles while the pile is still small.

  • Skill gaps, spelled out. See exactly which requirements you don't meet yet.

  • Verified jobs, only. Say no to ghost jobs. Your time deserves respect.

ASAI job platform logo

A job platform finally, balanced in your favour.

Jobs by CityJobs by CompanyGuidesHow We VerifyAboutPrivacy PolicyTerms of Service

Built in India 🇮🇳

© 2026 ASAI. All rights reserved.