Information Security Consultant
eSec Forte TechnologiesGurugram, HR, IndiaSeptember 30, 2026
On-site
Full-time
Pentesting
Mid · 1–5 yrs
About the Role
As an Information Security Consultant, you will conduct detailed security assessments and penetration tests for client web applications and APIs. This involves identifying vulnerabilities, analyzing their impact, and providing actionable remediation guidance to enhance the security posture of critical digital assets.
Key Responsibilities
- Perform comprehensive penetration testing on web applications and APIs using industry-standard methodologies and frameworks.
- Identify and exploit a wide range of vulnerabilities, including OWASP Top 10, business logic flaws, authentication bypasses, and authorization issues.
- Utilize security testing tools such as Burp Suite (PortSwigger) for in-depth analysis, traffic manipulation, and exploitation.
- Conduct static and dynamic application security testing (SAST/DAST) using platforms like Invicti (Netsparker) or HCL AppScan when appropriate for client engagements.
- Develop detailed, technically accurate reports outlining identified vulnerabilities, their associated risk levels, and practical, prioritized remediation recommendations.
- Collaborate directly with client development and security teams to explain technical findings, demonstrate exploit scenarios, and guide them through effective patching strategies.
- Stay abreast of emerging web application and API attack vectors, security best practices, and evolving industry standards.
Requirements
- 1-5 years of experience in information security, with a dedicated focus on web application and API penetration testing.
- Any graduate degree.
- Demonstrated proficiency in performing security assessments for both web applications and APIs.
- Solid understanding of common web vulnerabilities (e.g., OWASP Top 10, SANS Top 25) and their exploitation techniques.
- Hands-on experience with industry-standard security testing tools, particularly Burp Suite (PortSwigger).
- Ability to articulate complex technical issues and remediation strategies clearly and concisely in both written reports and verbal presentations.
- Familiarity with various programming languages and frameworks commonly used in web and API development (e.g., Java, Python, .NET, Node.js).
Nice-to-Have
- Experience with automated DAST/SAST tools such as Invicti (Netsparker), HCL AppScan, Checkmarx, or Snyk.
- Familiarity with security testing for cloud-native applications or microservices architectures on platforms like AWS, Azure, or GCP.
- Scripting skills (e.g., Python, PowerShell) for automating testing tasks or developing custom exploits.
- Knowledge of mobile application security testing principles.
Benefits
- Health insurance for the employee and dependents
- Professional security-certification reimbursement (e.g., OSWE, GWAPT, CEH)
- Annual learning and skill-development allowance
- Sponsored conference / training attendance
- Flexible work arrangements
Skills
web application testing and api testing
Qualification
Anu graduate
Job Details
Experience
Mid · 1–5 yrs
Tools & Tech
AWS
Azure
Burp Suite
Checkmarx
GCP
Java
Node.js
PowerShell
Python
Snyk
Preferred Certs
CEH
GWAPT
OSWE