Senior Engineer (Security)
Comviva · Bengaluru
- Experience3–5 yrs
- SalaryNot disclosed
- Work modeonsite
- Levelmid
- Posted10 Sept 2026
About Comviva
Comviva is hiring in Bengaluru in technology software. This role looks for around 3+ years of experience.
Skills
- Application security
- Penetration testing
- Web security testing
- API security testing
- Android security testing
- iOS security testing
- OWASP Top 10
- OWASP API Security Top 10
- OWASP Mobile Top 10
- MASVS
- MSTG
- Burp Suite
- MobSF
- Frida
- Objection
- JADX
- REST APIs
- OAuth
- JWT
- HTTP/HTTPS
- TLS
- Authentication
- Authorization
- CI/CD
- DevSecOps
- SAST
- DAST
- SCA
- Vulnerability management
- Python
- JavaScript
- Bash
- AI-assisted security testing
- Threat modeling
- STRIDE
- PASTA
The role
An application security engineer at a technology software company performs penetration testing across web, API, Android and iOS applications, applying OWASP Top 10 and mobile security testing. The role uses Burp Suite, mobile security tools, and DevSecOps practices to uncover vulnerabilities and strengthen secure software delivery.
Full job description
Job Title: Senior Security Engineer – Application Security
Job Summary
We are looking for a passionate and hands-on Senior Security Engineer to join our Application Security team. The ideal candidate should have strong experience in penetration testing of Web, API, Android and iOS applications, along with good knowledge of DevSecOps, CI/CD security and AI-augmented security testing.
Key Responsibilities
Perform manual and automated penetration testing of Web, API, Android and iOS applications.
Identify, validate and report security vulnerabilities and provide actionable remediation recommendations.
Perform security testing covering OWASP Top 10, OWASP API Security Top 10 and OWASP Mobile Top 10/MASVS.
Conduct advanced testing for authentication, authorization, IDOR/BOLA, business logic, injection, session management, data protection and API security.
Perform Android/iOS security testing including static/dynamic analysis, reverse engineering, SSL pinning, secure storage, WebView and runtime security testing.
Use tools such as Burp Suite, MobSF, Frida, Objection, JADX, Nmap and vulnerability scanners.
Integrate and support security tools such as SAST, DAST, SCA and vulnerability scanning within CI/CD pipelines.
Develop scripts and automation using Python, JavaScript, Bash or similar languages to improve security testing efficiency.
Leverage AI/LLM-based tools for AI-augmented security testing, including endpoint discovery, JavaScript analysis, test-case/payload generation, response analysis and security reporting.
Participate in threat modeling, architecture reviews and secure SDLC activities using methodologies such as STRIDE/PASTA.
Collaborate with developers, architects and DevOps teams to drive vulnerability remediation and improve application security.
Mentor junior team members and contribute to improving security testing methodologies and automation.
Required Skills
3–5 years of hands-on experience in Application Security/Penetration Testing.
Strong hands-on experience in Web, API, Android and iOS security testing.
Strong knowledge of OWASP Top 10, API Security Top 10, MASVS/MSTG and common security vulnerabilities.
Hands-on expertise with Burp Suite Professional.
Good knowledge of MobSF, Frida, Objection, JADX/apktool or equivalent mobile security tools.
Good understanding of REST APIs, OAuth, JWT, HTTP/HTTPS, TLS and authentication/authorization mechanisms.
Experience with CI/CD and DevSecOps security practices.
Knowledge of SAST, DAST, SCA and vulnerability management tools.
Strong scripting/automation skills in Python, JavaScript or Bash.
Exposure to AI-powered/AI-assisted security testing tools and techniques.
Strong analytical, problem-solving and communication skills.
Preferred Qualifications
Certifications such as OSCP, CEH, or equivalent.
Experience with cloud, containers and microservices security.
Knowledge of Threat Modeling, OWASP ASVS, NIST and SANS Top 25