Application Security Engineer
Air India Limited
Role tags
Tech stack mentioned
Role overview
Formatting this description...
Job Title: Job Purpose To lead and execute advanced Red Team operations and vulnerability assessments across mobile, web, and API platforms. The role demands deep technical expertise in offensive security, threat simulation, and secure architecture review, with a strong focus on automation, scalability, and real-world attack emulation. Key Accountabilities Strategic Activities Red Team Operations Design and execute full-scope Red Team engagements simulating real-world adversaries across enterprise, cloud, and AI/LLM environments. Develop custom tooling and TTPs aligned with MITRE ATT&CK and MITRE ATLAS frameworks. Conduct adversary emulation covering initial access, privilege escalation, lateral movement, and Active Directory/cloud exploitation. Perform AI/LLM red teaming — prompt injection, jailbreaking, agentic/tool-abuse, and RAG pipeline attacks — per OWASP LLM Top 10. Collaborate with Blue Team/SOC to validate detection coverage and drive purple team improvements. Present attack narratives and risk-prioritized findings to technical and executive stakeholders. Mentor junior red teamers and contribute to the team's engagement methodology and KPI framework. Vulnerability Assessment & Penetration Testing Perform manual and automated VAPT for mobile apps (Android/iOS), web applications, and APIs. Identify and exploit vulnerabilities including OWASP Top 10, business logic flaws, and zero-days. Mobile Security Reverse engineer mobile apps and analyze traffic, storage, and authentication mechanisms. Use tools like Frida, MobSF, Burp Suite, and custom scripts for dynamic/static analysis. API & Web Security Test REST, GraphQL, and SOAP APIs for authentication, authorization, and data leakage issues. Perform advanced web app testing including SSRF, RCE, IDOR, and client-side vulnerabilities. Reporting & Collaboration Deliver high-quality technical reports and executive summaries. Work closely with engineering, product, and security teams to drive remediation and secure design. Team Management Manage a team and coach them on tasks to ensure successful achievement of goals. Monitor efforts, performance, and task demands and guide the team to achieve cohesiveness. Any other additional responsibility could be assigned to the role holder from time to time as a standalone project or regular work. The same would be suitably represented in the Primary responsibilities and agreed between the incumbent, reporting officer and HR. Skills Required for the role Professional certifications play a significant role in the qualifications for a security engineer. Certifications demonstrate expertise in specific areas of cybersecurity and are often required or strongly preferred by employers. Detail oriented Passion for cybersecurity Analytical Skills Problem Solving Mindset Key Performance Indicators Cybersecurity and Risk Management Vulnerability Management Compliance Adherence Security Awareness Training Effectiveness Key Interfaces Internal Interfaces Team Leads & Management Provide updates and gain recommendations on security risks, compliance status, and strategic initiatives. IT, DevOps & Application Teams Collaborate closely with IT, DevOps teams to implement security issues/ observation and get it validated. Coordinate to ensure the security of applications, including web, API and mobile. External Interfaces Regulatory Authorities Interface with regulatory authorities to ensure compliance with security regulations and standards, and to address any inquiries or audits related to security practices. Third Party Vendor Collaborate with vendors to evaluate security tool to address any security concerns or vulnerabilities. Educational and Experience Requirements Minimum Education Requirement A bachelor’s degree in computer science, Information Technology, Cybersecurity, or a related field is commonly required. Some employers may accept equivalent work experience in lieu of a degree. Minimum Requirement Desired Experience 7+ years of experience Advanced degrees such as a master’s degree or Ph.D. in Cybersecurity or a related field may be preferred for senior or specialized roles. Certification required – CRTP, OSCP, OSCE, GPEN, CEH Understanding of network protocols, architecture, and security measures. Proficiency in configuring and managing firewalls, routers, switches, and other network security devices along with application security testing which includes web/ API and mobile. Knowledge of various operating systems (Windows, Linux, Unix, etc.) and their security features. Proficiency in vulnerability assessment tools and techniques to identify, prioritize, and remediate security vulnerabilities across systems and networks. Show more