Job Description
Summary
Join Deloitte India as a Manager in Application Security specializing in Web, Mobile, and API security. This role is ideal for professionals experienced in penetration testing (VAPT), vulnerability assessment, and secure application development. Based in Hyderabad, you will lead security assessments for high-profile clients, guide remediation efforts, and ensure compliance with industry standards like OWASP, MSTG, PCI DSS, ISO 27001, and NIST. Enhance your career in cybersecurity leadership, threat mitigation, and risk management while working with a global team of experts.
Job Details at a Glance
| Job Title | Manager – Web, Mobile & API Application Security |
|---|---|
| Location | Hyderabad, India |
| Employment Type | Full-Time |
| Shift | Office-based |
| Experience Required | 5+ years in Application Security / Penetration Testing |
| Tools & Technologies | Burp Suite, OWASP ZAP, Postman, MobSF, Frida, Drozer, adb, Python, Bash, PowerShell |
| Education | B.E / B.Tech in Computer Science, Information Security, or related fields |
| Requisition ID | 90103 |
| Date Posted | October 6, 2025 |
| Company | Deloitte Touche Tohmatsu India LLP |
Key Responsibilities
As a Manager – Application Security, you will:
- Lead penetration testing for Web, Mobile (iOS/Android), and API applications (REST/SOAP/GraphQL)
- Conduct Vulnerability Assessment and Exploitation aligned with OWASP Top 10, MSTG, and API Security Top 10
- Prepare detailed security assessment reports with proof-of-concept, risk ratings, and remediation guidance
- Collaborate with development, infrastructure, and business teams to provide actionable security recommendations
- Validate remediation fixes and perform post-assessment verification
- Simulate real-world attacks while adhering to client-approved scope and methodologies
- Stay updated with the latest threats, exploits, tools, and attack techniques
- Ensure compliance with international standards like PCI DSS, ISO 27001, NIST
- Communicate findings effectively to both technical and non-technical stakeholders
Required Skills & Experience
- Hands-on experience in Web, Mobile, and API penetration testing using industry-standard tools: Burp Suite, OWASP ZAP, Postman, MobSF, Frida, Drozer, adb
- Strong knowledge of:
- OWASP Top 10 and API Security Top 10
- Mobile Security Testing Guide (MSTG)
- Secure coding practices for Web, Mobile, and API
- Scripting skills for automation (Python, Bash, PowerShell)
- Understanding of authentication mechanisms (OAuth2, JWT, SAML) and common misconfigurations
- Familiarity with cloud application security (AWS, Azure, GCP) is an advantage
- Strong analytical, problem-solving, and client communication skills
Preferred Certifications
- OSCP, OSWE, OSEP, OSED, GWAPT
Educational Qualifications
- Bachelor’s or Master’s degree in Computer Science, Information Security, or related field
Managerial Role Expectations
- Lead with integrity, empathy, and inclusivity
- Inspire and motivate teams while building diverse capabilities
- Apply strategic thinking and analytical skills to solve complex business problems
- Ensure quality delivery, risk mitigation, and client satisfaction
- Embrace change and innovation while leveraging technology ethically
Why Deloitte?
- Work in a collaborative and innovative environment solving complex cyber challenges
- Access professional growth opportunities through Deloitte University and global initiatives
- Be part of a team committed to inclusion, impact, and ethical practices
- Enjoy a flexible, safe, and supportive workplace
Apply Now
Take the next step in your career as a Manager – Web, Mobile & API Application Security at Deloitte India.
Click here to apply on Deloitte’s official careers page