Hiring.Camp

Senior Security Specialist

Lennox

·

Yesterday

Location
Chennai, IN
Department
IT
Seniority
Senior
Experience
6+ years
Closing date
Today
Source
iCIMS

Description

Company Profile

Lennox (NYSE: LII) Driven by 130 years of legacy, HVAC and refrigeration success, Lennox provides our residential and commercial customers with industry-leading climate-control solutions. At Lennox, we win as a team, aiming for excellence and delivering innovative, sustainable products and services. Our culture guides us and creates a workplace where all employees feel heard and welcomed. Lennox is a global community that values each team member’s contributions and offers a supportive environment for career development. Come, stay, and grow with us.

Job Description

We are seeking a highly skilled Senior Security Specialist (IC3) with 6-9 years of experience in Application Security & Penetration Testing (VAPT), and security testing methodologies. The ideal candidate should possess strong expertise in DAST, API Security Testing, Mobile Application Security Testing (MAST), and hands-on exposure to AI-driven security testing and AI security risks. This role will work closely with development, DevOps, architecture, and product teams to identify, assess, and remediate security vulnerabilities throughout the SDLC.

Key Responsibilities

Application Security

  • Perform end-to-end application security assessments for web, mobile, and API applications.
  • Conduct threat modeling, secure design reviews, and architecture assessments.
  • Validate security controls and identify vulnerabilities using manual and automated techniques.
  • Review remediation recommendations and support development teams during vulnerability closure.

DAST (Dynamic Application Security Testing)

  • Conduct DAST assessments using tools such as:
    • Burp Suite Enterprise/Professional
    • Invicti (Netsparker)
    • Checkmarx
  • Analyze and validate findings to eliminate false positives.
  • Support tuning and optimization of DAST tools.
  • Develop DAST scanning standards, processes, and reporting mechanisms.

API Security

  • Perform API security testing against REST, SOAP, GraphQL, and Microservices architectures.
  • Validate API security controls including:
    • Authentication & Authorization
    • OAuth 2.0 / OIDC
    • JWT Security
    • Rate Limiting
    • Input Validation
    • API Abuse Scenarios
  • Conduct testing aligned with:
    • OWASP API Security Top 10
    • OWASP ASVS
    • OWASP Testing Guide
  • Utilize tools such as:
    • Postman
    • Burp Suite
    • OWASP ZAP
    • ReadyAPI

Mobile Application Security Testing (MAST)

  • Perform Android and iOS application security assessments.
  • Conduct dynamic mobile application testing.
  • Assess data storage, encryption, certificate pinning, and API security implementations.
  • Use security tools such as:
    • MobSF
    • NowSecure
    • Burp Suite

VAPT Activities

  • Conduct vulnerability assessments and penetration tests.
  • Validate exploitability and business impact of identified vulnerabilities.
  • Prepare detailed technical and executive reports.
  • Track remediation and support closure verification activities.
  • Collaborate with development teams to reduce recurring vulnerabilities.

AI Security & Emerging Technologies

  • Assess security risks associated with AI/LLM-powered applications.
  • Understand and evaluate:
    • Prompt Injection
    • Data Leakage Risks
    • Model Poisoning
    • Insecure Plugin Integrations
    • Excessive Agency
    • Sensitive Information Disclosure
  • Familiarity with:
    • OWASP Top 10 for LLM Applications
    • GenAI Security Best Practices
    • Secure AI Development Lifecycle
  • Utilize AI-assisted security testing tools to improve assessment efficiency.

Secure SDLC Integration

  • Collaborate with development and DevOps teams.
  • Support security gates within CI/CD pipelines.
  • Participate in security reviews and release approvals.

Qualifications

  • Bachelor’s degree in computer science, Cyber Security, Information Technology, or a related field.
  • 6-9 years of experience in Application Security, VAPT, or Security Testing.
  • Strong understanding of web, mobile, and API security principles.
  • Experience interacting with development and architecture teams.
  • Excellent analytical, problem-solving, and communication skills.

Skills

CI/CDiOSAndroidPenetration TestingRESTGraphQLOAuthDevOpsMicroservicesHVAC

Similar Jobs

30

Senior Security Specialist

Zensar Technologies · Serbia, RS

Yesterday

Senior Security Specialist

Razer · Shah Alam, Malaysia

6 days ago

Senior Security Specialist

Razer · Shah Alam, Malaysia

6 days ago

Senior Security Specialist

Protection Strategies · Camp Barrett, VA

1 week ago

Senior Security Specialist

Sound Transit · Seattle, WA

1 month ago

Senior Security Specialist

altusgroup · 954 – Manchester, United Kingdom +1

1 month ago

Senior Security Specialist

Pinkerton · , IN

1 month ago

Senior Security Specialist

"TCOM, L.P." · Columbia, MD

2 months ago

Senior Security Specialist

Advanced Strategic Insight · Washington, District of Columbia

2 months ago

Senior Security Specialist

McDermott Middle East, Inc. - Jebel Ali (UAE) · Maputo, Maputo City, Mozambique, MZ

3 months ago

IAMD Senior Security Specialist

AMERICAN SYSTEMS · Arlington, VA, US

Yesterday

Senior Security Specialist - Cyber Defence

Nab · BNZ Place Auckland, 80 Queen Street, New Zealand +1 · Hybrid

3 days ago

Senior Security Specialist – Penetration Testing

LSEG · United Kingdom - Home Based +1 · Remote

1 week ago

Senior Security Specialist (Crypto / Digital Assets)

Capital · Dubai +1 · Hybrid

1 week ago

Special Security Specialist Senior

Pae · US-DC-Washington-32 (DC111), United States of America · Onsite

2 weeks ago

Epic Senior Security Specialist

Quest Diagnostics · United States, US

2 weeks ago

Cyber Security Specialist, Senior (Top Secret)

Openings - Praescient Analytics · Fairfax (REMOTE), VA · Remote

3 weeks ago

Cloud Security, Senior Specialist

Interac Corp. · Interac Corp. Head Office, Canada · Hybrid

4 weeks ago

Network Security Specialist Senior (WAF)

Worldpay is committed to protecting · US OH CIN 8500, United States of America +2 · Hybrid

1 month ago

Senior Security Specialist (Global Security)

Rbc · 16 YORK ST:TORONTO, Canada · Hybrid

1 month ago

Senior Specialist, Security Verification & Testing

Gxs · Petaling Jaya (First Avenue), Malaysia

2 months ago

Senior Security Specialist-Shanghai

Amat · Shanghai,CHN, China

3 months ago

Senior Security Specialist (Business Continuity Management)

Eset · Bratislava, Slovakia

5 months ago

Personnel Security Specialist - Senior

Pae · US-AL-Huntsville-FBIIASS (AL015), United States of America · Onsite

5 months ago

Senior Specialist Security Consultant (m/w/d)

Datev · Nürnberg Fürther Str. 111, Germany

5 months ago

Cyber Security Specialist - Senior Level | Insider Threat Management and Analysis [DITMAC0013012]

ProSidian Consulting · Quantico, VA, United States

1+ year ago

Personnel Security Specialist Senior

SiloSmashers

1+ year ago

Information Security Specialist - Senior | IT Effectiveness - Cyber Security [NPS028033]

ProSidian Consulting · Reston, VA, United States · Remote

1+ year ago

Safety and Security Senior Specialist (m/f/d)

FOUR PAWS International Animal Welfare Organisation · Vienna, AT

1+ year ago

DOE - NNSA Senior Security Specialist - Security Management Support (TEPSIII17)

ProSidian Consulting · Washington, DC, United States

1+ year ago