Grant Thornton INDUS
Posted 8mo ago

Senior Associate - Application Security Testing

Grant Thornton INDUS
Bengaluru or Kolkata
OnsiteFull Time
Responsibilities
  • testing applications
  • documenting vulnerabilities
  • preparing reports
Requirements
  • Requires 3–5 years of application security experience with SAST/DAST
  • API security testing
  • Source-code analysis
  • Secure coding
  • DevSecOps, CI/CD
  • Vulnerability management, OWASP, and NIST
Technical tools mentioned
ServiceNowRSA ArcherBurp SuiteNmapZAP ProxyVeracodeFortifyAppScanOWASP Top 10ASVSNISTGDPRCCPACI/CDDevSecOpsSASTDAST

Job description

Job Details

  • Location: Bengaluru, Kolkata
  • Experience: 3 - 5 Years
  • Job Type: H
  • Openings: 1

Role Description

Grant Thornton's Cybersecurity & Privacy Advisory practice provides risk management consulting and advisory services to the clients. Cybersecurity & Privacy Advisory practice offers an excellent opportunity to leverage your information security consulting knowledge and experience to broaden your business and project management skills in a rewarding and challenging environment. Cyber Risk team is responsible for delivering a full range of services to clients and all phases of project and engagement management for multiple clients. Responsibilities include engagement planning, directing, and completion of Security Framework assessment, Vulnerability Testing, Application Security Testing, GRC Management using tools like ServiceNow, RSA Archer, Third Party Risk Assessment, and Information Security architectural design, Privacy regulations such as GDPR, CCPA; developing and supervising other Grant Thornton engagement staff; assisting in assigned client management and practice development activities.

Responsibilities

Perform Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) across web, mobile, and API applications.
Identify, validate, and document security vulnerabilities, misconfigurations, and weaknesses in applications.
Strong knowledge of Industry standard application security tools (e.g., Burp Suite, Nmap, Zap proxy)
Collaborate with development and DevOps teams to provide remediation guidance and verify fixes.
Integrate security testing into CI/CD pipelines and DevSecOps workflows to ensure secure SDLC practices.
Conduct API security testing and ensure compliance with industry standards (OWASP Top 10, ASVS, NIST).
Prepare detailed security assessment reports and communicate findings to stakeholders.

Required Technical Skills

Hands-on experience with SAST and DAST tools (e.g., Veracode, Fortify, AppScan, Burp Suite).
Strong knowledge of API security testing methodologies and tools.
Understanding of secure coding practices, SDLC, and threat modeling.
Ability to analyze source code and debug applications for security flaws.
Familiarity with DevSecOps practices and integrating security controls into CI/CD pipelines.
Knowledge of vulnerability management and common security standards (OWASP, NIST).

About Grant Thornton INDUS

Global capability center providing audit, tax, and advisory services.