Senior Engineer (Security)
Comviva · Bengaluru
- Experience3–5 yrs
- SalaryNot disclosed
- Work modeonsite
- Posted1 Oct 2026
About Comviva
Comviva is hiring in Bengaluru in technology software. This role looks for around 3+ years of experience.
Skills
- OWASP Top 10
- OWASP API Security Top 10
- OWASP Mobile Top 10
- Mobile Application Security Verification Standard
- Mobile Security Testing
- Burp Suite Professional
- MobSF
- Frida
- Objection
- JADX
- apktool
- REST APIs
- OAuth
- JWT
- HTTP/HTTPS
- TLS
- CI/CD
- DevSecOps
- SAST
- DAST
- SCA
- Vulnerability Management
- Python
- JavaScript
- Bash
- Penetration Testing
- Application Security
The role
A penetration tester at a technology software company performs application security across web, API, Android, and iOS products using OWASP, Burp Suite, and mobile security testing. Threat modeling, DevSecOps, Python, and secure SDLC practices support vulnerability remediation and AI-assisted security testing.
Full job description
Key Responsibilities
Penetration Testing & Vulnerability Assessment
Perform manual and automated penetration testing of Web, API, Android, and iOS applications. Identify, validate, and report security vulnerabilities with actionable remediation recommendations. Conduct security testing covering OWASP Top 10, OWASP API Security Top 10, and OWASP Mobile Top 10 / MASVS. Perform advanced testing across authentication, authorization, IDOR/BOLA, business logic, injection, session management, data protection, and API security.
Mobile Security Testing
Conduct Android and iOS security testing including static and dynamic analysis, reverse engineering, SSL pinning bypass, secure storage, WebView, and runtime security testing. Use tools such as MobSF, Frida, Objection, and JADX/apktool.
Tooling & DevSecOps
Use Burp Suite, Nmap, and vulnerability scanners as part of routine assessment work. Integrate and support SAST, DAST, SCA, and vulnerability scanning within CI/CD pipelines. Develop scripts and automation using Python, JavaScript, Bash, or similar to improve testing efficiency.
AI-Augmented Security Testing
Leverage AI/LLM-based tools for endpoint discovery, JavaScript analysis, test-case and payload generation, response analysis, and security reporting.
Secure SDLC & Collaboration
Participate in threat modeling, architecture reviews, and secure SDLC activities using methodologies such as STRIDE and PASTA. Collaborate with developers, architects, and DevOps teams to drive vulnerability remediation and improve overall application security posture.
Mentoring & Continuous Improvement
Mentor junior team members. Contribute to improving security testing methodologies and automation frameworks.
Required Skills
Technical — Mandatory
3–5 years of hands-on experience in application security / penetration testing. Strong hands-on experience across Web, API, Android, and iOS security testing. Strong knowledge of OWASP Top 10, OWASP API Security Top 10, MASVS/MSTG, and common vulnerability classes. Hands-on expertise with Burp Suite Professional. Working knowledge of MobSF, Frida, Objection, JADX/apktool, or equivalent mobile security tools. Solid understanding of REST APIs, OAuth, JWT, HTTP/HTTPS, TLS, and authentication/authorization mechanisms. Experience with CI/CD and DevSecOps security practices. Knowledge of SAST, DAST, SCA, and vulnerability management tools. Strong scripting and automation skills in Python, JavaScript, or Bash. Exposure to AI-powered / AI-assisted security testing tools and techniques.
Behavioural
Strong analytical and problem-solving skills. Clear written and verbal communication, particularly for reporting findings to technical and non-technical audiences. Collaborative approach across development, architecture, and operations teams.
Preferred Qualifications
Certifications such as OSCP, CEH, or equivalent. Experience with cloud, container, and microservices security. Knowledge of threat modeling, OWASP ASVS, NIST frameworks, and SANS Top 25.