Cyber Security Engineer

AI-driven cybersecurity company focused on vulnerability management, application security, compliance automation, and Web3 security.

Mumbai, India
About TAC Security

TAC Security is the operating brand associated with TAC InfoSec Limited, a publicly listed cybersecurity company founded in 2013. Its current offerings include the ESOF vulnerability-management platform, application-security and SOC 2 readiness automation, smart-contract/Web3 security through CyberScope, IoT security assessment, and public-sector cybersecurity services.

View jobs by TAC Security

Skills

About the Role

You will conduct penetration tests and security assessments across applications and networks. You will perform web, mobile, API, SAST, and DAST testing; establish vulnerability-management processes; track new assets; and ensure assessments occur before and after applications go live.

Requirements

  • Bachelor's degree in Computer Science, Information Technology, Engineering, Business Administration, or a related field.
  • Good communication skills.
  • 1–2 years of hands-on experience with manual penetration testing and automation tools.
  • Understanding of OWASP Top 10, CIS, and NIST.
  • Knowledge of Java, Ruby, or Python.
  • Experience testing web and mobile applications using MOBSF.
  • Experience with API testing using Postman and Burp Suite.

Responsibilities

  • Conduct penetration testing and vulnerability-management activities.
  • Scan applications and networks, review findings, and perform penetration tests for further exploitation.
  • Conduct web application SAST and DAST, mobile application security testing, and API security testing.
  • Establish vulnerability-management frameworks and processes for assessment, treatment, and exceptions.
  • Elicit business and user requirements through workshops, customer meetings, user stories, process modeling, and other methods.
  • Track new assets and applications and ensure security assessments occur before and periodically after go-live.
  • Manage VAPT and secure configuration management processes.