Skip to main content
Application Security

Associate Cybersecurity Consultant

Run hands-on application, network, and cloud security testing with structured senior review and direct customer interaction from day one.

๐Ÿ“ Mumbai / Remote ๐Ÿ—“ Full-time ๐Ÿ“Š Junior
application securitypenetration testingOWASP Top 10burp suitemanual testingreportingAPI securitycloud security

Ready to apply?

Send us your CV and a short note on why this role excites you.

Apply Now โ†’

Usually responds within 2 business days

About the Role

Security Brigade is hiring an Associate Cybersecurity Consultant to join our offensive security practice. You will run hands-on security assessments: web and mobile application testing, network vulnerability and penetration testing, source code review, configuration review, cloud security, and API security. Every engagement is reviewed end-to-end through our L1/L2/L3 senior chain, so you grow under structured mentorship. You will work directly with customers across BFSI, fintech, healthcare, government, and tech-sector enterprises. This is a strong fit for engineers one to three years out of college who want a real path into deep offensive security.

What You'll Do

  • โ–ธ Run web and mobile application security testing, vulnerability assessments, source code reviews, configuration reviews, cloud security, and API security testing
  • โ–ธ Profile applications, model threats, and design test cases to target identified threats across modern stacks
  • โ–ธ Identify and exploit vulnerabilities in applications and networks; document with reproducible proof-of-concept
  • โ–ธ Manage engagement timelines and customer interactions across delivery
  • โ–ธ Produce reports against internal templates with clear remediation guidance
  • โ–ธ Run customer-facing remediation conversations with engineering teams
  • โ–ธ Research emerging security topics and new attack techniques, and write the tools and scripts to operationalise them
  • โ–ธ Contribute to internal knowledge-sharing and Lemon platform improvements

What We're Looking For

  • โœ“ 1โ€“3 years of hands-on security testing experience (internships and serious lab work count)
  • โœ“ Real working understanding of common security issues, exploitation techniques, and remediation that goes beyond a memorised OWASP Top 10
  • โœ“ Disciplined manual testing approach. Scanner output is where the work starts.
  • โœ“ Working development knowledge of at least one modern programming language
  • โœ“ Strong understanding of application and network security fundamentals
  • โœ“ Strong written and spoken English for client-quality reports and direct customer interaction
  • โœ“ Familiarity with frameworks like React or Django and the threat models that come with them
  • โœ“ Working knowledge of the standard offensive toolchain (Burp Proxy, Acunetix, sqlmap, Nmap, Nessus, Metasploit)

What We Offer

  • โœ“ Competitive salary aligned to experience
  • โœ“ Hybrid + remote-friendly
  • โœ“ Sponsorship for offensive security certifications (OSCP, eWPTX, CRTO, BSCP)
  • โœ“ Internal lab environment + dedicated research time
  • โœ“ Mentorship from L2/L3 senior researchers on every engagement
  • โœ“ Active community involvement (OWASP, Null, Nullcon) supported and encouraged

Quick Facts

Team Application Security
Location Mumbai / Remote
Type Full-time
Level Junior
Posted 1 May 2026
Apply for This Role โ†’
โ† Back to all open positions