Talentmate
India
14th September 2026
2609-46589-1
About This Job
Tonik
Location: Chennai, Tamil Nadu, India
Work Mode: On-site
Industry: Banking
Job Description
Job Title: Application Security Analyst
Location: DLF Cybercity, Porur, Chennai- India
Experience: 4 - 8 Years
About The Job
We are looking for an Application Security Analyst who will ensure that mobile and web applications are developed, deployed, and maintained based on security standards and best practices to protect the organization from potential threats and vulnerabilities. This role will work closely with development, network security, and technology teams to embed security throughout the software development lifecycle.
Job Responsibilities
Mobile and Web Application Penetration Testing
Perform static and dynamic analysis of Android and iOS applications to uncover insecure data storage, weak cryptography, SSL pinning/root detection bypass, and other mobile application risks.
Test anti-tampering and device binding controls such as RASP, root/jailbreak detection, device attestation, and biometric authentication implementation.
Conduct web application penetration testing against the OWASP Top 10, including injection, broken authentication/session management, and access control vulnerabilities, across customer and internal-facing web portals.
Document findings with risk ratings, proof of concept, and remediation recommendations, and perform retesting through closure.
API Security Testing
Conduct API penetration testing on internal and externally exposed APIs using the OWASP API Security Top 10 as the baseline methodology.
Test authentication and session handling, mTLS enforcement, token replay/reuse scenarios, and authorization controls.
Evaluate rate limiting, throttling, and anti-automation controls against brute force, credential stuffing, and enumeration attacks on customer-facing APIs.
Review API Gateway and WAF rule effectiveness against attack payloads and coordinate with the Network Security team on ruleset fine-tuning.
Secure SDLC and Application Security Governance
Embed security checkpoints across the SDLC, including security requirements review at the design phase, secure code review, and pre-release security sign-off.
Support integration of SAST/DAST in CI/CD pipelines and triage automated scan findings for accuracy and risk relevance.
Track application security findings and remediation status through risk registers, KPIs, and reports.
Conduct periodic application security awareness sessions for developers on secure coding practices and common vulnerabilities.
Preferred Experience And Qualifications
| Role Level: | Not Applicable | Work Type: | Full-Time |
|---|---|---|---|
| Country: | India | City: | Chennai ,Tamil Nadu |
| Company Website: | http://www.tonikbank.com | Job Function: | Cybersecurity |
| Company Industry/ Sector: |
Other | ||
Searching, interviewing and hiring are all part of the professional life. The TALENTMATE Portal idea is to fill and help professionals doing one of them by bringing together the requisites under One Roof. Whether you're hunting for your Next Job Opportunity or Looking for Potential Employers, we're here to lend you a Helping Hand.
Disclaimer: talentmate.com is only a platform to bring jobseekers & employers together. Applicants are advised to research the bonafides of the prospective employer independently. We do NOT endorse any requests for money payments and strictly advice against sharing personal or bank related information. We also recommend you visit Security Advice for more information. If you suspect any fraud or malpractice, email us at abuse@talentmate.com.