Job Title:  Assistant Manager | Web/Mobile/API Application Security | Bengaluru | Cyber Defense & Resilience | A

Job requisition ID ::  108794
Date:  Jul 27, 2026
Location:  Bengaluru
Designation:  Assistant Manager
Entity:  Deloitte Touche Tohmatsu India LLP

Assistant Manager | Web/Mobile/API Application Security | Bengaluru | Cyber Defense & Resilience | A
Job requisition ID : 108794 
Location: Bengaluru
Entity: Deloitte Touche Tohmatsu India LLP 

The Team

Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at     how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks. Learn more about  Cybersecurity  

 

Your Work Profile

Responsible for validating security controls and remediation measures implemented by Development and DevOps teams, ensuring vulnerabilities are effectively addressed and applications meet Secure SDLC and compliance requirements.

We are seeking a motivated Application Security Engineer with hands-on experience in Web, Mobile, and API Security Assessments. The ideal candidate will be responsible for identifying, validating, and reporting application security vulnerabilities, collaborating with development teams, and supporting secure software development practices.

Key Responsibilities

  • Perform security assessments and penetration testing of web applications, mobile applications (Android/iOS), and APIs.
  • Identify, validate, and report vulnerabilities aligned with OWASP Top 10, OWASP Mobile Top 10, and OWASP API Security Top 10.
  • Conduct manual and automated security testing, including authentication, authorization, business logic, and data validation testing.
  • Support secure code review activities and provide remediation guidance to development teams.
  • Assist with threat modeling, security risk assessments, and security validation during SDLC.
  • Prepare clear technical reports and present findings to stakeholders.

Required Qualifications

  • 2–5 years of experience in Application Security, Penetration Testing, or Vulnerability Assessment.
  • Strong understanding of web application, mobile application, and API security concepts.
  • Hands-on experience with tools such as Burp Suite, OWASP ZAP, MobSF, Postman, and related security testing tools.
  • Good understanding of authentication mechanisms, session management, encryption, and secure coding practices.
  • Familiarity with common programming languages and application architectures.

Preferred Qualifications

  • OSCP (Offensive Security Certified Professional) certification preferred.
  • Additional certifications such as eWPT, GWAPT, CEH, or CSSLP are a plus.
  • Experience with DevSecOps, CI/CD security integration, and cloud application security is advantageous.
  • Btech, BE, Diploma