Website:
nmtsecurity.com
Job details:
Experience: 4-6 years
Location: Client Site (Mumbai)
Reporting to: Engagement Lead, NMT Security
About the role
This role leads manual security testing of web application portfolio, including visa processing portals, e-visa systems, biometric/facial verification services, and appointment booking platforms handling sensitive applicant PII.
Key responsibilities
- Lead manual VAPT across web applications, APIs, and business logic flows, with emphasis on IDOR, authentication bypass, privilege escalation, and workflow abuse over automated scanning
- Design and execute test cases for appointment/slot booking systems, rescheduling flows, and facial verification/biometric services, targeting logic flaws over generic vulnerability classes
- Own end-to-end authenticated testing across multi-tenant, multi-country deployments of the same codebase
- Write clear, client-ready vulnerability reports with CVSS scoring, business impact analysis, and remediation guidance
- Mentor and review work of junior team member, validate findings before client reporting, Interface directly with the security/engineering stakeholders on findings, retest cycles, and closure Maintain strict data handling discipline given the PII sensitivity of the target environment (visa applicant data, biometric data)
Required skills
- 4-6 years in web application penetration testing / VAPT, with a portfolio of manual, non-scanner-driven findings
- Strong hands-on experience with IDOR discovery, business logic testing, and privilege escalation, not just OWASP Top 10 checklist testing
- Proficiency with Burp Suite, Postman/API testing tools, and manual request manipulation
- Experience testing authentication flows, session management, and multi-step business workflows (bookings, registrations, approvals)
- Comfortable working across multiple similar-but-distinct app instances (same codebase, different country deployments)
- Strong report writing and client communication skills
- CVEs, bug bounty track record, or OSCP/CRTP/similar certification is a strong plus
Good to have
Prior experience testing appointment/booking or govt-facing citizen service platforms
Familiarity with facial recognition/biometric verification testing
Experience in regulated/PII-heavy environments (BFSI, govt, healthcare)
Click on Apply to know more.