
Application Security Engineeer
- ₹7L – ₹10L
- |Remote () •
- |2 years of exp
- |Full Time
In office
Not Available
About the job
We are looking for a passionate and experienced Associate Security Engineer (AppSec / Infra Security) to join our growing team at CoreShield Technologies. In this onsite role based in Bangalore, you will work closely with Engineering and DevOps teams to secure applications, infrastructure, and on-premise deployments.
This role is execution-heavy — ideal for someone who has hands-on security experience and wants to build security into real systems.
Key Responsibilities
Perform penetration testing across web applications, APIs, and networks and identify vulnerabilities.
Conduct security assessments and risk analysis for applications and infrastructure.
Work on network security controls including firewalls, VPNs, and IDS/IPS.
Identify and validate vulnerabilities such as OWASP Top 10, security misconfigurations, authentication/authorization flaws, and insecure APIs.
Collaborate with Backend and Development teams to fix vulnerabilities and implement secure coding practices.
Assist in implementing EDR, endpoint security, disk encryption, and device hardening.
Support incident analysis, log review, and threat detection activities.
Contribute to Secure SDLC practices including SAST, DAST, and dependency scanning.
Document security findings, prepare security reports, and track remediation.
Required Qualifications
Bachelor’s degree in Computer Science, Engineering, Cybersecurity, or a related field.
2+ years of hands-on experience in cybersecurity, application security, infrastructure security, penetration testing, or a related field.
Strong understanding of networking fundamentals including TCP/IP, DNS, HTTP/HTTPS, routing, and NAT.
Hands-on experience with penetration testing / VAPT tools.
Good knowledge of OWASP Top 10 vulnerabilities and exploitation techniques.
Familiarity with tools such as:
Burp Suite
Nmap
Metasploit
Basic understanding of Linux systems and shell usage.
Understanding of authentication mechanisms such as JWT, OAuth/OIDC, and session-based authentication.
Exposure to firewalls, IDS/IPS, and VPN concepts.
Good to Have
Experience with Wireshark or network traffic analysis.
Exposure to cloud security (AWS/GCP).
Understanding of DevSecOps tools such as OWASP ZAP and Trivy.
Basic scripting knowledge in Python / Bash for automation.
Knowledge of encryption fundamentals and TLS.
What We’re Looking For
Someone who has actually tested systems, not just theoretical knowledge.
Strong problem-solving mindset and the ability to think like an attacker.
Ownership mindset with the ability to drive security issues to closure.
Comfortable working in a fast-paced, on-premise and product environment.
About the company

Coreshield Technologies
Similar Jobs








