Job Opportunities

Career Opportunities

YOUGotaGift Pvt Ltd

+91 9895482001
info-ekm-in@yougotagift.com

Junior Security Test Engineer

Junior Security Test Engineer

Experience: 0–2 Years
Employment Type: Full-time
Department: Information Security / Cybersecurity


About the Role
We are looking for a Junior Security Test Engineer who is passionate about cybersecurity and interested in building a career in offensive security and application security.
The candidate will work alongside experienced security professionals to perform Vulnerability Assessment and Penetration Testing (VAPT) across web applications, APIs, mobile applications, infrastructure, and cloud environments.
This role is suitable for someone who has a strong foundation in cybersecurity and networking and is eager to develop practical penetration-testing skills through real-world assessments.
We value curiosity, problem-solving ability, willingness to learn, and hands-on skills more than certifications.

Key Responsibilities
-Web Application Security Testing
-Assist in performing web application penetration testing.
-Understand application functionality and identify potential attack surfaces.
-Perform manual testing with guidance from senior security testers.
-Test for common vulnerabilities including:
*XSS
*SQL Injection
*CSRF
*IDOR / BOLA
*Authentication issues
*Authorization issues
*Session management weaknesses
*File upload vulnerabilities
*Path traversal
*Open Redirect
*CORS misconfiguration
*Security misconfigurations
*Rate-limit weaknesses
*Sensitive information exposure
-Learn to identify and validate business logic vulnerabilities.

API Security Testing
-Assist with REST and GraphQL API security assessments.
-Analyze API requests and responses.
-Understand authentication and authorization mechanisms.
-Test basic API security controls.
-Assist in identifying:
*BOLA / IDOR
*BFLA
*Authentication bypass
*Excessive data exposure
*Injection
*Rate-limit issues
*Improper access control
-Use tools such as Burp Suite and Postman for API testing.

Mobile Application Security
-Assist with Android and/or iOS application security testing.
-Understand mobile application architecture and API communication.
-Perform basic testing for:
*Insecure data storage
*Hardcoded secrets
*Insecure communication
*Improper permissions
*Authentication issues
*Sensitive information exposure
Gain practical experience with tools such as MobSF, JADX, ADB, apktool, and Frida.

Vulnerability Assessment
-Perform vulnerability scanning using approved security tools.
-Analyze scanner results and identify potential false positives.
-Manually validate vulnerabilities before reporting them.
-Assist senior testers in vulnerability verification and exploitation.
-Maintain accurate testing notes and evidence.

Security Testing Tools
Develop hands-on familiarity with tools such as:
-Burp Suite
-OWASP ZAP
-Nmap
-Nuclei
-ffuf / Gobuster
-Nessus / OpenVAS
-SQLmap
-Postman
-Wireshark
-MobSF
-JADX
-ADB
-Git
The candidate should progressively develop the ability to perform testing manually rather than relying solely on automated scanners.


Programming & Development Knowledge
Programming experience is not mandatory, but it is a strong advantage.
Candidates with knowledge of any of the following will be preferred:
-Python
-JavaScript / TypeScript
-Bash / Shell scripting
-SQL
Ability to read and understand basic source code is highly desirable.
Development experience, even at a junior level, will be considered an advantage because it helps in understanding application logic and identifying vulnerabilities more effectively.

Security Knowledge
The candidate should have a basic understanding of:
-OWASP Top 10
-OWASP API Security
-Authentication vs Authorization
-Session management
-Access control
-Encryption vs hashing
-Common web vulnerabilities
-Vulnerability severity
-CWE and basic CVSS concepts
-Secure coding fundamentals
-Common security misconfigurations

Reporting & Documentation
-Document vulnerabilities clearly and accurately.
-Capture appropriate screenshots, requests, responses, and other evidence.
-Assist in preparing VAPT reports.
-Clearly document:
*Vulnerability
*Affected component
*Description
*Steps to reproduce
*Proof of Concept
*Impact
*Recommended remediation
-Assist in retesting vulnerabilities after remediation.

Learning & Development
The candidate will be expected to continuously improve their security skills through:
-Hands-on security assessments.
-Security labs and CTFs.
-Vulnerability research.
-CVE analysis.
-OWASP research.
-Understanding new attack techniques.
-Building security testing scripts and utilities.
-Learning modern application and API architectures.

Required Skills
-Basic understanding of cybersecurity concepts.
-Good networking fundamentals.
-Basic understanding of web application security.
-Familiarity with HTTP/HTTPS.
-Basic Linux knowledge.
-Familiarity with Burp Suite or similar proxy tools.
-Good analytical and problem-solving skills.
-Strong willingness to learn.
-Good documentation and communication skills.
-Ability to work effectively with senior security testers.

Nice to Have
-Internship or practical experience in penetration testing/VAPT.
-Experience with Burp Suite.
-Basic Python or JavaScript scripting.
-Software development experience.
-Experience with REST or GraphQL APIs.
-Basic mobile application security knowledge.
-Basic AWS/Azure/GCP knowledge.
-Familiarity with Docker or CI/CD.
-Experience with tools such as Nmap, Nuclei, ffuf, SQLmap, MobSF, or Nessus.
-Participation in CTFs, bug bounty programs, or security labs.
-Git/GitHub experience.
-Interest in security automation and DevSecOps.

Qualifications
-Bachelor's degree or equivalent in Computer Science, Cybersecurity, Information Security, IT, or a related field is preferred.
-0–2 years of experience in cybersecurity, VAPT, application security, or a related technical role.
-Fresh graduates with strong practical cybersecurity knowledge and demonstrable hands-on skills may also be considered.

Certifications
Certifications are optional and considered an added advantage, not a mandatory requirement.
Certifications such as eJPT, CEH, or equivalent may be considered a plus.
Practical skills, curiosity, technical fundamentals, and the ability to learn will be given greater importance than certifications.

What We Expect From a Junior Security Tester
We do not expect a junior resource to know everything from day one.
We expect the candidate to have the ability to learn , understand, test , validate, document and Improve
The candidate should be willing to:
-Ask the right technical questions.
-Understand why a vulnerability exists rather than simply identifying it.
-Learn from senior penetration testers.
-Perform independent research.
-Reproduce vulnerabilities accurately.
-Develop strong manual testing skills.
-Gradually take ownership of security assessments.
-Build scripting and automation capabilities over time.

Career Growth
This role provides an opportunity to develop into a Security Engineer capable of independently performing assessments as technical skills and experience grow.

Location
Kochi/Calicut

YOUGotaGift.com is the leading Digital Gift Card Company in the Middle East. Our digital gifting platform is used by individuals and businesses to celebrate, reward, motivate and show appreciation to friends, loved ones, employees, customers, and business partners. Our business solution has also been adopted by major customer loyalty programs across leading telcos, banks, airlines delivering unparalleled choice of rewards, a memorable customer service experience, and best-in-class technology tailored to partner needs.

YOUGotaGift Pvt Ltd is an equal opportunities employer. We believe passionately that employing a diverse workforce is central to our success. We make recruiting decisions based on your experience and skills. We value your passion to discover, invent, simplify and build.

Please visit YOUGotaGift.com website to know more about us

If this opportunity aligns with your career goals, kindly share your updated resume with us at techcareers@yougotagift.com

© Copyright 2026 Infopark Kochi. All rights reserved. Website design powered by logo