Application Security / VAPT Engineer – Web & API Security
BlueBox InfosoftMatch Score
Against your primary resumeLogin to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Protocol Intelligence
Data-driven signals on your job's competitivenessLog in to see why each signal reads the way it does.
Job Description
Structured overview of role & requirementsAbout This Role
Perform manual and automated VAPT of Web Applications and APIs to identify security vulnerabilities including OWASP Top 10, IDOR/BOLA, XSS, SQL Injection, CSRF, and API-specific issues.
Conduct security testing on authentication, authorization, sessions, APIs, and business logic, going beyond automated scanner results.
Document vulnerabilities with impact analysis, evidence, severity, and remediation guidance, and collaborate with developers for root cause analysis and retesting.
Minimum Requirements
Minimum 2 years experience in Application Security, VAPT, or Penetration Testing.
Strong knowledge of Web & API Security concepts, particularly OWASP Top 10 vulnerabilities.
Hands-on experience with security tools like Burp Suite, OWASP ZAP, Postman, Nmap or equivalents.
Understanding of HTTP/HTTPS protocols, REST APIs, JSON, tokens, cookies, and SQL.
Ideal Candidate Profile
Experience with manual Web/API security testing and business logic validation, beyond automated scans.
Background as a software developer (especially in .NET/C#/ASP.NET/MVC/Web API) transitioning into Application Security preferred.
Demonstrates strong attacker mindset combined with the ability to understand code and security implications for effective vulnerability identification and remediation.
