Role Overview
Recro is hiring a Senior Security Engineer. This is a full-time role in Indore. Part of Recro's Risk hiring. Full responsibilities, required qualifications, and the apply link are listed in the description below.
Resume Keywords to Include
Make sure these keywords appear in your resume to improve ATS scoring
Sign up free to auto-tailor your resume with all these keywords and get a higher ATS score
Job Description
Role - Application Security Engineer
Experience - 4+Yrs
Location - Bangalore
Key Responsibilities
Internal VAPT & Security Testing
● Execute internal VAPT on web applications, APIs, and React Native mobile applications, focusing on real-world attack paths.
● Perform authenticated and authorization-focused testing, including BOLA/IDOR, broken access control, and session abuse.
● Validate scanner results and provide reproducible evidence such as PoCs, request/response traces, and impact narratives.
DAST Program Support
● Improve DAST scanning reliability and signal quality by managing scope definition, scan profiles, and false positives.
● Produce verified, developer-actionable outputs for the monthly DAST cadence.
● Maintain stable test credentials and safe scanning practices for Tier-0/Tier-1 applications in coordination with the DAST owner.
Secure SDLC & DevSecOps Enablement
● Support security checks integrated into GitHub Actions, including secrets scanning and dependency hygiene.
● Provide practical remediation guidance and secure coding recommendations for Node/React/Next and API services.
● Develop reusable developer guidance, such as secure patterns and verification scripts, to reduce vulnerability recurrence.
Triage, Verification & Mobile Security
● Triage findings from SAST, SCA, and DAST sources to ensure high-confidence issues reach engineering.
● Verify fixes and ensure closure quality for high-risk issues.
● Perform mobile security testing, including API endpoint discovery, secure storage assessments, and deep link validation.
External VAPT & Bug Bounty Support
● Prepare scope, test accounts, and validation assistance for external VAPT execution.
● Assist in retest verification for external findings.
● Support bug bounty readiness through triage playbooks and severity assessment guidance.
Qualifications & Experience
● Education: Bachelor’s degree in Computer Science, Cybersecurity, Information Security,
or equivalent practical experience.
● Experience: 3–5+ years in application security, product security, or penetration testing with strong hands-on skills.
● Technical Testing: Demonstrated experience in web application and API security testing; mobile security experience is strongly preferred.
● Tooling: Proficiency with at least two of the following: Accunetix, Burp Suite, OWASP
ZAP, SonarQube (or other SAST tools), dependency scanning, or secrets scanning tools.
Technical Knowledge & Skills
● Deep understanding of OWASP Top 10 and API security risks (BOLA/IDOR, mass assignment, rate-limit abuse).
● Strong grasp of authentication and authorization models, including JWT, OIDC, and session handling.
● Working knowledge of DevSecOps practices and embedding security testing into CI workflows (GitHub Actions).
● Ability to build reproducible proofs and utilize scripting (Python/Node) for light automation.
● Familiarity with Cloudflare WAF/API Shield and API gateway architectures (Kong/AWS
API Gateway) is a plus.
Frequently Asked Questions
How do I apply for the Senior Security Engineer position at Recro?
Use the Apply button above to submit your application directly to Recro. Most applications take less than 5 minutes if your resume and contact details are ready, and you'll be routed to the employer's official application system to finish.
Where is the Senior Security Engineer position at Recro located?
This position is based in Indore. Recro has not indicated remote or hybrid options for this role, so candidates should plan for on-site work.
What does a Senior Security Engineer at Recro earn?
Recro has not disclosed a salary range in this posting. Many employers share specifics later in the interview process; you can also ask during a recruiter screen if compensation transparency is important to you.
When was the Senior Security Engineer role at Recro posted?
This role was posted on April 16, 2026 (53 days ago). It's still listed as actively hiring; we re-confirm openings against the source system multiple times per day and remove closed roles.
How much experience does the Senior Security Engineer role at Recro require?
This is a senior-level position. Most senior roles call for 5+ years of directly relevant experience. Recro lists their specific requirements in the description below, so review the must-have qualifications closely before applying.
AI-powered job search
Get every job scored to your resume
Upload your resume and get jobs ranked, your resume tailored, and employee contacts found automatically.
Get Started FreeNo credit card to start