About this role
Commvault protects enterprise data, so its own applications are a high value target and this role attacks them before someone else does. It is hands on offensive security rather than governance: you run DAST, SAST and IAST against internal and customer facing applications, lead threat modelling and security assessments across the software development lifecycle for both on premises and cloud hosted environments, and manually validate and prioritise what the automated scanners throw up. That manual validation is the part worth noticing, because it is what separates a security tester from someone who forwards scanner output. You also write remediation guidance for development teams and verify their fixes, do secure code review where needed, and document findings for technical and non technical readers. Testing GenAI solutions is listed as a requirement, which is still unusual in an AppSec posting.
Who this is for
Commvault asks for a Bachelor's degree in Computer Science, Cybersecurity, Information Technology or a related field, and 5+ years of experience in application security testing or offensive security.
Required: deep understanding of the OWASP Top 10, CWE and SANS Top 25 and other security best practice. Hands on experience testing applications hosted in AWS, Azure or GCP. Familiarity with RESTful APIs, microservices architecture and container security (Docker, Kubernetes). Experience testing GenAI solutions. Strong command of scripting in Python, Bash or PowerShell for custom testing and automation. Solid understanding of secure SDLC and DevSecOps. Experience with security testing tools across three categories: static analysis (Fortify, Checkmarx, Veracode), dynamic analysis (Burp Suite Pro, OWASP ZAP, AppSpider) and software composition analysis (Snyk, Black Duck, WhiteSource).
Preferred: security certifications such as OSCP, GWAPT, GPEN, CISSP or CSSLP, infrastructure as code scanning experience (Terraform, CloudFormation), and working knowledge of compliance frameworks such as PCI DSS.
Day to day: perform detailed application security testing, lead threat modelling and assessments across the SDLC, use automated tooling to find vulnerabilities, manually validate and prioritise findings, collaborate with DevOps, engineering and cloud teams, provide remediation guidance and validate fixes, conduct secure code review as necessary, stay current on emerging threats, document findings clearly, and mentor junior security staff.
Location: Bangalore.
⚠️ Commvault opens this posting with a recruitment fraud warning: it does not conduct interviews by email or text and will never request banking details or national ID before your first day. Apply through the official link only.
Honest fit guidance: the tool list is long but the certifications are preferred rather than required, so an OSCP is not a gate. The GenAI testing requirement is the one most candidates will not have, and it is listed as a requirement rather than a preference, so be ready to talk about how you would approach prompt injection and model abuse even if you have not done it professionally.
Required: deep understanding of the OWASP Top 10, CWE and SANS Top 25 and other security best practice. Hands on experience testing applications hosted in AWS, Azure or GCP. Familiarity with RESTful APIs, microservices architecture and container security (Docker, Kubernetes). Experience testing GenAI solutions. Strong command of scripting in Python, Bash or PowerShell for custom testing and automation. Solid understanding of secure SDLC and DevSecOps. Experience with security testing tools across three categories: static analysis (Fortify, Checkmarx, Veracode), dynamic analysis (Burp Suite Pro, OWASP ZAP, AppSpider) and software composition analysis (Snyk, Black Duck, WhiteSource).
Preferred: security certifications such as OSCP, GWAPT, GPEN, CISSP or CSSLP, infrastructure as code scanning experience (Terraform, CloudFormation), and working knowledge of compliance frameworks such as PCI DSS.
Day to day: perform detailed application security testing, lead threat modelling and assessments across the SDLC, use automated tooling to find vulnerabilities, manually validate and prioritise findings, collaborate with DevOps, engineering and cloud teams, provide remediation guidance and validate fixes, conduct secure code review as necessary, stay current on emerging threats, document findings clearly, and mentor junior security staff.
Location: Bangalore.
⚠️ Commvault opens this posting with a recruitment fraud warning: it does not conduct interviews by email or text and will never request banking details or national ID before your first day. Apply through the official link only.
Honest fit guidance: the tool list is long but the certifications are preferred rather than required, so an OSCP is not a gate. The GenAI testing requirement is the one most candidates will not have, and it is listed as a requirement rather than a preference, so be ready to talk about how you would approach prompt injection and model abuse even if you have not done it professionally.
Apply on company site
Opens job-boards.greenhouse.io, the employer's own application page. Applying is always free.