Application security consultant
AadiSwan Info Consultants · New delhi, India
FULL TIMEpermanent
Job Description
We are looking for an experienced Application Security Consultant to strengthen the security posture of enterprise web applications, APIs, and backend systems built on ASP. NET Web Forms,. NET Core, and Angular JS.
Key Responsibilities:-
Conduct security assessments of web apps, APIs, and frontend systems
Identify and remediate vulnerabilities aligned with OWASP Top 10 and SANS/CWE
Perform threat modelling (STRIDE), secure code reviews, and penetration testing
Secure Angular JS frontends (XSS, DOM-based attacks, template injection, CSP implementation)
Implement encryption best practices (data-at-rest, TLS/SSL, AES/RSA, secure hashing)
Harden APIs and servers (secure headers, HSTS, CSP, IIS/Nginx hardening)
Conduct SAST, DAST, SCA and dependency assessments (Nu Get & npm)
Threat Modelling Analysis & Documentation
Strengthen authentication & IAM (OAuth 2.0, JWT, MFA)
Perform DB security testing (SQL Server, Oracle, Postgre SQL) including privilege review, misconfigurations, and injection risks
Integrate security into CI/CD pipelines and support Dev Sec Ops initiatives
Static and Dynamic Security Scan Tools:-
(Check Marx, SCA, SYNK, Sonar Qube, CAST, HCL App Sec, OWASP ZAP, Fortify), OWASP TOP 10, Dev Sec Ops. Security Logging, Post Man, Database Security, Cloud Security, Software Development & Implementation in Microsoft Technology (ASP. NET,. NET Core, MVC 5.0, 4.0, C#, WCF, SQL SERVER, Azure, SOLID principles, API)
Required Skills:-
Strong expertise in ASP. NET Web Forms,. NET Core, Angular JS security
Hands-on with tools like Burp Suite, OWASP ZAP, Postman, SQLMap
Deep understanding of SQL Injection, XSS, CSRF, Broken Access Control, Insecure Deserialization
Experience with secure HTTP headers, CSP, TLS configuration
Knowledge of OWASP guidelines and secure SDLC practices
Good to have BFSI / Fintech domain.
Good to have: Application Security AI Tools
If you have strong hands-on experience in securing. NET enterprise applications and APIs end-to-end, we’d love to connect.
DM -
Key Responsibilities:-
Conduct security assessments of web apps, APIs, and frontend systems
Identify and remediate vulnerabilities aligned with OWASP Top 10 and SANS/CWE
Perform threat modelling (STRIDE), secure code reviews, and penetration testing
Secure Angular JS frontends (XSS, DOM-based attacks, template injection, CSP implementation)
Implement encryption best practices (data-at-rest, TLS/SSL, AES/RSA, secure hashing)
Harden APIs and servers (secure headers, HSTS, CSP, IIS/Nginx hardening)
Conduct SAST, DAST, SCA and dependency assessments (Nu Get & npm)
Threat Modelling Analysis & Documentation
Strengthen authentication & IAM (OAuth 2.0, JWT, MFA)
Perform DB security testing (SQL Server, Oracle, Postgre SQL) including privilege review, misconfigurations, and injection risks
Integrate security into CI/CD pipelines and support Dev Sec Ops initiatives
Static and Dynamic Security Scan Tools:-
(Check Marx, SCA, SYNK, Sonar Qube, CAST, HCL App Sec, OWASP ZAP, Fortify), OWASP TOP 10, Dev Sec Ops. Security Logging, Post Man, Database Security, Cloud Security, Software Development & Implementation in Microsoft Technology (ASP. NET,. NET Core, MVC 5.0, 4.0, C#, WCF, SQL SERVER, Azure, SOLID principles, API)
Required Skills:-
Strong expertise in ASP. NET Web Forms,. NET Core, Angular JS security
Hands-on with tools like Burp Suite, OWASP ZAP, Postman, SQLMap
Deep understanding of SQL Injection, XSS, CSRF, Broken Access Control, Insecure Deserialization
Experience with secure HTTP headers, CSP, TLS configuration
Knowledge of OWASP guidelines and secure SDLC practices
Good to have BFSI / Fintech domain.
Good to have: Application Security AI Tools
If you have strong hands-on experience in securing. NET enterprise applications and APIs end-to-end, we’d love to connect.
DM -
Details
| Company | AadiSwan Info Consultants |
| Location | New delhi, India |
| Type | FULL TIME |
| Niche | general |
| Experience | permanent |
