> Markdown version of [/jobs/ext/658034-sr-application-security-engineer-intl-india](https://www.wearedevelopers.com/jobs/ext/658034-sr-application-security-engineer-intl-india). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Application Security Engineer - INTL India - **Company:** Insight Global - **Location:** Atlanta, GA, United States - **Experience:** Expert - **Salary:** $18,720.0 - $27,040.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Application Programming Interfaces (APIs), Business Logic, Software System Penetration Testing, Microsoft Azure, Burp Suite, Cloud Computing, Computer Programming, Data Validation, Software Design Patterns, Hypertext Transfer Protocols (HTTP), Virtual Private Networks (VPN), Mobile Application Software, Python (Programming Language), Network Security, Lightweight Directory Access Protocols (LDAP), Microsoft SQL Server, Network Service, Nmap, OAuth, Open Web Application Security, Secure Coding, Mobile Security, Software Engineering, Web Applications, Remote Desktop Protocol (RDP), Software Security, Firewalls (Computer Science), Backend, Api Design, Api Gateway, Restful APIs, Pagination, Api Management, Vulnerability Analysis, Microservices - **Published:** June 26, 2026 - **Apply:** https://www.juju.com/job/00000000gb3xtt ## About the Role 4-7 years of experience in Application Security, including web applications, mobile applications, infrastructure, and API penetration testing ESSENTIAL SKILLS Application & API Security Strong hands-on experience performing manual web application penetration testing Deep knowledge of OWASP Web, API, and Mobile Top 10 vulnerabilities Experience following OWASP WSTG and structured testing methodologies Ability to perform application mapping and attack surface discovery Strong skills in authentication and authorization testing Experience testing input validation and error handling Ability to validate both client-side and server-side attack vectors Hands-on experience testing RESTful APIs in authenticated and unauthenticated contexts Ability to test authorization controls, role separation, token handling, API keys, OAuth and JWT misuse Experience testing rate limiting, pagination, and business logic abuse Ability to integrate API testing into broader application security assessments Experience testing mobile applications with backend API dependency awareness Strong understanding of client-side versus server-side trust boundaries Infrastructure & Network Security Hands-on experience performing internal and external infrastructure penetration tests Knowledge of network service enumeration, including SMB, RDP, LDAP, MSSQL, HTTP/S Experience identifying firewall, VPN, cloud endpoint, and network misconfigurations Strong understanding of Active Directory attacks, including Kerberoasting, AS-REP roasting, and privilege escalation Ability to validate lateral movement paths, credential reuse, weak permissions, and privilege escalation vectors Experience aligning infrastructure testing with PTES methodology Strong understanding of all PTES phases Penetration Testing Execution & Reporting Ability to scope, execute, and document full-cycle penetration tests Experience validating exploitability and business impact, not just scanner findings Ability to combine automated scanning with manual exploitation for accurate results Experience performing retesting and validating remediation closure Proficiency with industry-standard tools, including Burp Suite (manual testing, extensions, API testing), Nmap, and SQLmap Strong experience producing clear, actionable penetration test reports Experience tracking findings through the full remediation lifecycle Secure Development & Collaboration Experience working within a Secure Software Development Lifecycle (SSDLC) Ability to perform architecture reviews and threat modeling (e.g., STRIDE) Experience supporting static, dynamic, and manual security testing efforts Ability to partner with development teams during design, build, and release phases Ability to support leadership discussions on application and infrastructure risk posture and trends Advanced Application Exploitation Proven ability to identify complex business logic flaws across web, API, and mobile applications Experience chaining low- and medium-severity findings into high-impact attack paths Advanced web exploitation experience, including SSRF, deserialization, cache poisoning, and template injection Deep familiarity with microservices-based and API-driven architectures Experience testing APIs protected by OAuth2, JWTs, service tokens, and API gateways Ability to advise teams on secure API design patterns, not just vulnerabilities Mobile & Client-Side Security Experience performing manual mobile security testing beyond automated scanners Ability to identify client-side trust issues versus backend enforcement gaps Risk Communication & Leadership Strong executive-level communication skills, including attack path storytelling and business impact translation Ability to correlate application vulnerabilities with infrastructure weaknesses Experience validating attack paths involving network misconfigurations, privilege escalation, and lateral movement Understanding of how cloud segmentation, firewalling, and network controls affect application exposure Experience embedding security testing into SSDLC and CI/CD pipelines Ability to guide teams on threat modeling, secure design decisions, and pre-production security gates Comfort leading remediation discussions and constructively challenging weak fixes Experience mentoring junior AppSec or penetration testing team members Experience creating and reviewing penetration testing reports Programming experience (Python or similar) Certifications & Advanced Expertise One or more relevant certifications such as OSCP, CRTO, OSWP, OSEP, PNPT, or similar Advanced Active Directory attack path knowledge, including delegation abuse, DCsync, DCshadow, and BloodHound analysis Experience reducing and validating attack paths Cloud & Identity Security Practical offensive security experience in Azure or Microsoft 365 (Entra ID) and/or GCP Experience with identity abuse, misconfigured roles and policies, workload identity takeover, OAuth application abuse, and cross-tenant risks ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Developing the Backend with Stefan Lingler, CTO at Shpock](https://www.wearedevelopers.com/videos/100360-developing-the-backend-with-stefan-lingler-cto-at-shpock) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Nest.js - TypeScript in the backend can also be clean](https://www.wearedevelopers.com/videos/1033-nest-js-typescript-in-the-backend-can-also-be-clean) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools)