Skip to content
securityjobs

Jobs /Application Security jobs in India /Security Researcher (Web Application)

Security Brigade· 150+

Security Researcher (Web Application)

  • Mumbai · Hybrid
  • full time
  • web application penetration testing
  • burp suite
  • OWASP
  • API security
  • manual testing
  • reporting

About the role

Security Brigade is hiring a Security Researcher to join our application security practice. You will run hands-on web application penetration tests for enterprise customers across BFSI, fintech, healthcare, and SaaS. The work is backed by our Lemon audit-management platform and reviewed through our L1/L2/L3 senior chain, so you grow under structured supervision from day one. You will own the full lifecycle: scoping with the customer, executing the test, documenting findings with proof-of-concept evidence, walking remediation owners through fixes, and revalidating closures. The role is a strong fit for engineers two to four years into application security who want depth and a direct path to senior research as we scale.

What you’ll work on

  • Run web application penetration tests end-to-end on customer applications
  • Apply manual testing techniques alongside Burp / OWASP ZAP / custom tooling
  • Document findings with clear proof-of-concept, business impact, and remediation guidance that engineering teams can act on
  • Walk customer engineering teams through findings; advise on fixes; revalidate closures
  • Contribute to internal research, methodology updates, and Lemon platform improvements

What we’re looking for

  • 2+ years of hands-on web application penetration testing experience
  • Strong working knowledge of OWASP Top 10 (web) and common business-logic flaw patterns
  • Proficient with Burp Suite (Pro a plus), and comfortable writing custom payloads / extensions where needed
  • Comfortable reading and reasoning about modern application stacks (React / Angular / Vue front-ends; Node / Django / Rails / Spring back-ends; REST + GraphQL APIs)
  • Excellent written English for report-quality output
  • Practical lab experience on Hack The Box, PortSwigger Web Security Academy, or TryHackMe a strong signal

Benefits

  • Competitive salary aligned to experience
  • Hybrid + remote-friendly
  • Sponsorship for OSCP, OSWE, BSCP, or equivalent certifications
  • Internal lab environment for research time
  • Direct mentorship from L2/L3 senior researchers on every engagement

About Security Brigade

A CERT-In empanelled, ISO 27001 certified cybersecurity firm working with over 1,000 clients across BFSI, fintech, e-commerce and manufacturing since 2008. Home of ShadowMap and B-52.

Similar roles

  • Security BrigadeVerified employer

    Associate Cybersecurity Consultant

    2 weeks ago
    • Mumbai · Hybrid
    • Application Security
    • application security
    • penetration testing
    • OWASP Top 10
    • burp suite
    • manual testing
    • +3

    1 applicant250 views

  • Security BrigadeVerified employer

    PHP Developer, Lemon Platform

    2 weeks ago
    • Mumbai · Hybrid
    • Product & Platform Engineering
    • PHP
    • Laravel
    • Symfony
    • jQuery
    • MySQL
    • +3

    1 applicant276 views

  • Security BrigadeVerified employer

    Python Developer, Security Tooling

    2 weeks ago
    • Mumbai · Hybrid
    • Security Engineering & Development
    • Python
    • HTTP
    • TCP/IP
    • Linux
    • MySQL
    • +3

    243 views

  • Security BrigadeVerified employer

    GRC Analyst

    2 weeks ago
    • Delhi / Mumbai · Hybrid
    • GRC, Risk & Audit
    • ISO 27001
    • SOC 2
    • PCI DSS
    • RBI
    • SEBI
    • +7

    380 views

Hiring for a security role? Post it free. No account, no card, reviewed by a person, usually within a working day.