Skip to content
securityjobs

Jobs /Application Security jobs in India /Associate Cybersecurity Consultant

Security Brigade· 150+

Associate Cybersecurity Consultant

  • Mumbai · Hybrid
  • full time
  • application security
  • penetration testing
  • OWASP Top 10
  • burp suite
  • manual testing
  • reporting
  • API security
  • cloud security

About the role

Security Brigade is hiring an Associate Cybersecurity Consultant to join our offensive security practice. You will run hands-on security assessments: web and mobile application testing, network vulnerability and penetration testing, source code review, configuration review, cloud security, and API security. Every engagement is reviewed end-to-end through our L1/L2/L3 senior chain, so you grow under structured mentorship. You will work directly with customers across BFSI, fintech, healthcare, government, and tech-sector enterprises. This is a strong fit for engineers one to three years out of college who want a real path into deep offensive security.

What you’ll work on

  • Run web and mobile application security testing, vulnerability assessments, source code reviews, configuration reviews, cloud security, and API security testing
  • Profile applications, model threats, and design test cases to target identified threats across modern stacks
  • Identify and exploit vulnerabilities in applications and networks; document with reproducible proof-of-concept
  • Manage engagement timelines and customer interactions across delivery
  • Produce reports against internal templates with clear remediation guidance
  • Run customer-facing remediation conversations with engineering teams
  • Research emerging security topics and new attack techniques, and write the tools and scripts to operationalise them
  • Contribute to internal knowledge-sharing and Lemon platform improvements

What we’re looking for

  • 1–3 years of hands-on security testing experience (internships and serious lab work count)
  • Real working understanding of common security issues, exploitation techniques, and remediation that goes beyond a memorised OWASP Top 10
  • Disciplined manual testing approach. Scanner output is where the work starts.
  • Working development knowledge of at least one modern programming language
  • Strong understanding of application and network security fundamentals
  • Strong written and spoken English for client-quality reports and direct customer interaction
  • Familiarity with frameworks like React or Django and the threat models that come with them
  • Working knowledge of the standard offensive toolchain (Burp Proxy, Acunetix, sqlmap, Nmap, Nessus, Metasploit)

Benefits

  • Competitive salary aligned to experience
  • Hybrid + remote-friendly
  • Sponsorship for offensive security certifications (OSCP, eWPTX, CRTO, BSCP)
  • Internal lab environment + dedicated research time
  • Mentorship from L2/L3 senior researchers on every engagement
  • Active community involvement (OWASP, Null, Nullcon) supported and encouraged

About Security Brigade

A CERT-In empanelled, ISO 27001 certified cybersecurity firm working with over 1,000 clients across BFSI, fintech, e-commerce and manufacturing since 2008. Home of ShadowMap and B-52.

Similar roles

  • Security BrigadeVerified employer

    Security Researcher (Web Application)

    2 weeks ago
    • Mumbai · Hybrid
    • Application Security
    • web application penetration testing
    • burp suite
    • OWASP
    • API security
    • manual testing
    • +1

    245 views

  • Security BrigadeVerified employer

    PHP Developer, Lemon Platform

    2 weeks ago
    • Mumbai · Hybrid
    • Product & Platform Engineering
    • PHP
    • Laravel
    • Symfony
    • jQuery
    • MySQL
    • +3

    1 applicant276 views

  • Security BrigadeVerified employer

    Python Developer, Security Tooling

    2 weeks ago
    • Mumbai · Hybrid
    • Security Engineering & Development
    • Python
    • HTTP
    • TCP/IP
    • Linux
    • MySQL
    • +3

    243 views

  • Security BrigadeVerified employer

    GRC Analyst

    2 weeks ago
    • Delhi / Mumbai · Hybrid
    • GRC, Risk & Audit
    • ISO 27001
    • SOC 2
    • PCI DSS
    • RBI
    • SEBI
    • +7

    380 views

Hiring for a security role? Post it free. No account, no card, reviewed by a person, usually within a working day.