Information Security Consultant
eSec Forte TechnologiesGurugram, HR, IndiaSeptember 30, 2026
On-site
Full-time
Application Security
Mid · 2–4 yrs
About the Role
This Information Security Consultant role focuses on executing in-depth security assessments across web, mobile, and API applications, meticulously identifying critical vulnerabilities and architectural weaknesses. You will be responsible for providing precise, actionable remediation strategies to our diverse client base, directly contributing to their enhanced security posture through hands-on testing, expert analysis, and strategic consultation.
Key Responsibilities
- Perform in-depth penetration testing and vulnerability assessments for web, mobile, and API applications, identifying security weaknesses and potential exploit paths across various technology stacks.
- Utilize industry-standard and proprietary tools such as Burp Suite (PortSwigger), Invicti (Netsparker), and HCL AppScan to execute detailed security scans, conduct manual validation, and develop proof-of-concept exploits.
- Analyze application architecture and design, applying both Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) methodologies to uncover security flaws early in the development lifecycle.
- Develop comprehensive, technically precise reports detailing identified vulnerabilities, their business impact, risk ratings, and precise, actionable recommendations for remediation tailored to client environments.
- Collaborate directly with client development and security teams to articulate complex technical findings, provide guidance on secure coding practices, and support the end-to-end vulnerability resolution process.
- Stay current with the latest application security threats, attack techniques, and defensive countermeasures, actively researching emerging vulnerabilities and integrating new knowledge into assessment practices and advisories.
- Contribute to the continuous improvement of eSec Forte's application security testing methodologies, internal tools, and best practices, ensuring adherence to global standards and regulatory requirements.
- Support incident response activities related to application security breaches by providing expert forensic analysis, root cause identification, and remediation guidance as needed.
Requirements
- 2-4 years of dedicated experience in information security, with a strong focus on application security testing across web, mobile, and API platforms.
- Bachelor of Engineering (BE) or Bachelor of Technology (BTECH) degree in Computer Science, Information Technology, or a related field.
- Demonstrated proficiency in manual and automated penetration testing techniques for various application types, including a deep understanding of HTTP/S protocols and mobile application frameworks.
- Solid understanding of common application vulnerabilities, including the OWASP Top 10, CWE, and SANS Top 25, along with their exploitation and effective mitigation strategies.
- Hands-on experience with security testing tools such as Burp Suite (PortSwigger), Invicti (Netsparker), HCL AppScan, or similar commercial and open-source solutions.
- Ability to communicate complex technical security issues clearly and concisely to both technical development teams and non-technical business stakeholders, both verbally and in written reports.
- Work Mode: This is an onsite position based in Gurugram, requiring regular presence at the client location or eSec Forte office.
Nice-to-Have
- Practical experience with Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) tools and processes, including platforms like Checkmarx, Snyk, or JFrog, and integrating them into CI/CD pipelines.
- Familiarity with secure software development lifecycles (SSDLC), DevSecOps principles, and security architecture reviews.
- Relevant industry certifications such as Offensive Security Certified Professional (OSCP), Offensive Security Web Assessor (OSWE), or Certified Ethical Hacker (CEH) with a focus on web/API security.
- Experience with scripting languages (e.g., Python, Bash, PowerShell) for automating security tasks, developing custom exploits, or performing data analysis.
Benefits
- Health insurance for the employee and dependents
- Professional security-certification reimbursement (e.g., OSCP, OSWE)
- Annual learning and skill-development allowance
- Sponsored conference / training attendance
- Flexible work arrangements
Skills
Web, mobile, Api testing, SAST and DAST
Qualification
BE/BTECH
Job Details
Experience
Mid · 2–4 yrs
Tools & Tech
Bash
Burp Suite
Checkmarx
PowerShell
Python
Snyk
Preferred Certs
CEH
OSCP
OSWE