| Company | Deloitte Touche Tohmatsu India LLP |
| Job Title | Assistant Manager – Web/Mobile/API Application Security |
| Job Requisition ID | 110732 |
| Location | Pune, Maharashtra, India |
| Business Area | Cyber Defense & Resilience – Attack |
| Experience Required | 2–5 years in Application Security, Penetration Testing, or Vulnerability Assessment |
| Education | B.Tech / BE / Diploma |
| Role Overview | Conduct application security assessments for web, mobile, and API applications, identify vulnerabilities, validate remediation, and support Secure SDLC and compliance requirements. |
| Web Security | Web application security testing, penetration testing, authentication, authorization, business logic, and data validation testing |
| Mobile Security | Android and iOS application security assessments and vulnerability testing |
| API Security | API security assessments, vulnerability identification, validation, and remediation guidance |
| Security Standards | OWASP Top 10, OWASP Mobile Top 10, OWASP API Security Top 10 |
| Security Tools | Burp Suite, OWASP ZAP, MobSF, Postman, and related application security testing tools |
| Key Responsibilities | Perform manual and automated security testing, identify and report vulnerabilities, validate security controls, and ensure remediation measures effectively address identified risks. |
| Secure Code Review | Support secure code review activities and provide actionable remediation recommendations to development teams. |
| Threat Modeling | Assist with threat modeling, security risk assessments, and security validation throughout the Software Development Lifecycle (SDLC). |
| DevSecOps | Exposure to DevSecOps, CI/CD security integration, and cloud application security is advantageous. |
| Security Knowledge | Authentication mechanisms, session management, encryption, secure coding practices, application architectures, and common programming languages |
| Reporting | Prepare clear technical security reports and communicate findings and remediation recommendations to stakeholders. |
| Certifications | OSCP preferred; eWPT, GWAPT, CEH, or CSSLP are additional advantages |
| Ideal Candidate | An Application Security professional with hands-on experience in web, mobile, and API penetration testing, strong OWASP knowledge, security testing tools expertise, and an understanding of secure software development practices. |
| Career Level | Assistant Manager |