HireFT
Browse JobsHow it worksPricingAboutSuccess Stories
    Back to jobs
    NT

    NTS Technology Services Private Limited

    Technology Services

    Senior Engineer, Product Security Testing

    Bangalore, IndiaOn-SiteFull-time6+ yrs experiencePosted 2w ago
    All NTS Technology Services Private Limited jobs

    Job description

    Job Description :

    Job Description Details: Senior Engineer - Product Security : Bangalore, India

    We are currently seeking a Senior Engineer, Product Security to join our Product Security team, based in Bangalore, Karnataka, India. The ideal candidate will possess a deep understanding of attack surfaces in modern compiled applications and operating systems. Candidates must demonstrate the ability to analyze closed source applications using several off-the-shelf or custom-developed tools. Additionally, the ideal candidate will be able to demonstrate exceptional organizational skills, work efficiently under minimal supervision, be able to deliver results that meet or exceed the organization’s expectations, be a strong team player, and actively participate in a fast-paced and challenging global environment.

    As part of our Product Security team, you shall perform penetration testing which includes internet,

    intranet, wireless, web application, APIs, Mobile Applications and social engineering. You shall also

    perform in-depth analysis of penetration testing results and create reports that describe findings,

    exploitation procedures, risks and recommendation

    Key Responsibilities:

    ● Hands-on experience with OWASP Web and Mobile Top 10 standards,NIST CSF, NIST SP 800,PCI

    DSS including mitigation of common threats.

    ● Strong understanding of the OWASP Top 10 for LLM Applications and OWASP Top 10 for

    Generative AI, with hands-on experience identifying and validating AI/LLM-specific security risks.

    ● Strong knowledge of OWASP Top 10 web and the ability to effectively communicate

    methodologies and techniques with development teams

    ● Execute penetration testing projects using the established methodology, tools and rules of

    engagements.

    ● Solid understanding of application security topics such as authentication, authorization,

    encryption, session management, federation, API security, etc.

    ● Extensive experience with web and mobile application security tools like code scanners

    (Checkmarx, Fortify, Ghidra, Hopper, MobSF) and dynamic analysis tools (Burp Suite, ZAP, etc.).

    ● Experienced in performing security assessments of AI models, LLM-powered applications,

    chatbots, AI agents, and AI-integrated APIs, covering both traditional and AI-specific attack

    vectors.

    ● Hands-on experience with AI security testing tools, prompt engineering, adversarial testing

    techniques, and integrating Model Context Protocol (MCP) servers with security tools to

    automate and enhance AI security assessments.

    ● Skilled in evaluating AI systems for vulnerabilities such as prompt injection, indirect prompt

    injection, sensitive information disclosure, insecure tool usage, excessive agency, model

    manipulation, and unsafe output handling.

    ● Proficient in designing and executing end-to-end AI penetration testing methodologies,

    leveraging automation and custom tooling to improve assessment efficiency and coverage.

    ● Write reports including recommendations, root cause analysis, security summary analysis, and

    project roadmaps.

    ● Review application code for security vulnerabilities and practices dangerous to security and

    privacy.

    ● Convey complex technical security concepts to technical and non-technical audiences including

    executives.

    ● Mentor junior members of the team and act as a subject matter expert for application security

    issues.

    ● Manage integration with manual and automated tools for static and dynamic testing.

    ● Conduct threat modeling and risk analysis to identify exposure and develop mitigation plans.

    ● Build security into infrastructure and architecture designs and guide the implementation with

    the operations team

    ● Experience with cloud security, particularly for AWS and/or Azure Experience with integrating

    security into a DevOps culture.

    Minimum Qualifications.

    ● Bachelor's degree/MTech with an emphasis on cyber security.

    ● Minimum 6 years of experience in Product and Application Security performing, Penetration

    Testing on Web Application, Mobile (Android and IOS) APIs, SAST, SCA, SSDLC. Threat Modeling

    and Secure design review would be an added advantage.

    ● 1-2 years of software development with at least 1 year in developing secure systems.

    ● Experience in one or more of the following modern languages/frameworks - Python, Java, Ruby,

    node.js, JavaScript, PHP, Go.

    ● Basic understanding of DevOps & DevSecOps principles and building code pipelines.

    ● A passion for application security and working knowledge of web application vulnerabilities and

    mitigations.

    ● Known for being a great communicator and collaborator with excellent written and verbal

    communication skills.

    ● Demonstrable flair for technical writing, including engagement reports, presentations and

    operating procedures

    ● Experience with severity ratings systems, and ability to calculate CVSS ratings for identified

    vulnerabilities.

    Preferred Certifications

    ● CPENT, LPT, GPEN, OSCP

    Equal Opportunity Employer

    All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, national origin, protected veteran status, disability status or any other protected characteristic.

    Reasonable Accommodation

    We are committed to providing reasonable accommodation for qualified individuals with disabilities in our job application and/or interview process. If you need assistance or accommodation in completing your application or participating in an interview due to a disability, email us at [email protected]. Please put "Reasonable Accommodation" in the subject line and provide a brief description of the type of assistance you need. This inbox will not be monitored for application status updates.

    Please refer to the privacy notice at the bottom of this page for submitting any data access, deletion, or other data subject rights requests, where permitted under your local laws and regulations.

    This job is posted with NTS Technology Services Pvt. Ltd.

    Job details are sourced from the employer's original posting.

    Open job posting
    NT

    About the company

    NTS Technology Services Private Limited

    NTS Technology Services Private Limited is a company that provides technology services.

    View all NTS Technology Services Private Limited jobs
    Industry
    Technology Services
    Open roles
    11

    Interested in this role?

    Apply with HireFT

    Free to start — no card required.

    Your fit

    How well do you match?

    Sign in to see how your résumé lines up with this role.