TRPD-26-04978
Cyber Security Consultant (Application Security & Control Assessments)
Hiring a Cyber Security Consultant (2–9 years) in Bengaluru for a permanent role focused on hands-on application security reviews (web/API/mobile) plus governance-oriented security control testing, risk assessments, and compliance reviews. The consultant will assess design and operating effectiveness of controls across applications and supporting network/cloud environments, identify OWASP Top 10 issues, perform threat modeling and security architecture reviews, validate remediation via re-testing, and support audit/regulatory evidence reviews. Strong knowledge of secure SDLC, network and cloud security (AWS/Azure/GCP), IAM/auth protocols (OAuth2/OIDC/SAML/JWT), and standards like OWASP/NIST/CIS/MITRE is required; AI/LLM security awareness is expected.
Position summary
- Location
- India
- Workplace
- Hybrid
- Employment
- Full Time
- Experience
- Minimum 2 years and Maximum 9 years
Role overview
Why This Role Matters.
Hiring a Cyber Security Consultant (2–9 years) in Bengaluru for a permanent role focused on hands-on application security reviews (web/API/mobile) plus governance-oriented security control testing, risk assessments, and compliance reviews. The consultant will assess design and operating effectiveness of controls across applications and supporting network/cloud environments, identify OWASP Top 10 issues, perform threat modeling and security architecture reviews, validate remediation via re-testing, and support audit/regulatory evidence reviews. Strong knowledge of secure SDLC, network and cloud security (AWS/Azure/GCP), IAM/auth protocols (OAuth2/OIDC/SAML/JWT), and standards like OWASP/NIST/CIS/MITRE is required; AI/LLM security awareness is expected.
Your Impact
Deliver Enterprise Value
Help organisations solve complex business problems through modern technology, consulting expertise and measurable outcomes.
Collaboration
Work Across Teams
Collaborate with consultants, architects, engineers and client stakeholders throughout the project lifecycle.
Growth
Learn Continuously
Gain exposure to enterprise technologies, certifications, mentoring and real-world project experience.
Career Path
Grow With Ubique
Build a long-term consulting career with opportunities to take on greater responsibility and leadership over time.
Responsibilities
What You'll Be Doing.
Every role at Ubique contributes directly to solving meaningful business challenges for our clients.
Conduct application security control reviews against organizational security requirements and industry best practices.
Perform cybersecurity risk assessments and document risks, impacts, and mitigation recommendations.
Conduct compliance assessments against regulatory and industry frameworks.
Evaluate security governance processes and identify control gaps.
Review access management, logging, monitoring, vulnerability management, and data protection controls.
Support audit and regulatory assessment activities by providing security expertise and evidence reviews.
Conduct security reviews of web application, API, Network and Cloud systems.
Knowledge on AI&LLM security vulnerabilities.
Identify vulnerabilities aligned with OWASP Top 10.
Conduct threat modeling and security architecture reviews.
Review application security controls and provide remediation recommendations.
Technology stack
Tools & Technologies.
The platforms and technologies you'll use to build modern, enterprise-grade solutions.
Application Security
AppSec
Secure SDLC
Web Application Security
API Security
Mobile Application Security
Threat Modeling
Security Architecture Review
OWASP Top 10
NIST
CIS Benchmarks
MITRE ATT&CK
Risk Assessment
Control Testing
Control Effectiveness
Compliance Review
Audit Support
IAM
Access Management
Logging
Requirements
Skills & Experience.
We value curiosity, collaboration and continuous learning. If you don't meet every requirement but believe you can make an impact, we'd still love to hear from you.
Essential
Required Qualifications
Application Security (AppSec) fundamentals
Secure SDLC practices
Hands-on web application security testing
Hands-on API security testing
Hands-on mobile application security testing
Security control testing (design and operating effectiveness)
Security control reviews/control effectiveness assessments
Cybersecurity risk assessments (risk/impact/mitigation documentation)
Compliance assessments against cybersecurity frameworks/standards
Security governance process evaluation and control gap identification
Access management/IAM control review
Logging and monitoring control review
Vulnerability management control review
Data protection control review
Network security concepts and infrastructure security assessments
Cloud security experience (AWS or Azure or GCP)
Authentication and authorization frameworks: OAuth2, OpenID Connect, SAML, JWT
OWASP Top 10 vulnerability identification
Threat modeling
Security architecture reviews
Preferred
Nice to Have
Knowledge of AI & LLM security vulnerabilities
Certifications: CISA
Certifications: CEH
Certifications: CCSP
Certifications: AWS Security Specialty
Certifications: Azure Security Engineer Associate
Certifications: OSCP
Bachelor’s/Master’s degree in Information Security/Computer Science or related (Tier 1/2 preferred)
What you'll gain
More Than Just A Job.
We're committed to helping every team member grow professionally, personally and technically while working on meaningful projects.
Global Exposure
Collaborate with international clients and multicultural teams on enterprise programmes.
Continuous Learning
Expand your expertise through mentoring, certifications and hands-on project experience.
Career Growth
Take ownership, develop leadership skills and grow your consulting career over time.
Flexible Working
Hybrid and remote collaboration designed around trust and delivering exceptional outcomes.
People First
Join a supportive culture where collaboration, respect and long-term relationships come first.
Enterprise Projects
Work on meaningful technology initiatives for leading organisations across industries.
Apply
Apply for Cyber Security Consultant (Application Security & Control Assessments)
One page, about two minutes. We only ask for what we actually need to have a first conversation.