TymblHub

© 2026 TymblHub

Application Security Engineer

Vee Healthtek
Posted on
Vee Healthtek logo

Experience
3 - 5 yrs
Job Location
Bengaluru, India
Vacancy
1
Designation
Application Security Engineer
Job Type
Not specified

Job Description

Job Title: Application Security Engineer

Experience: 3 5 Years (Mid-Level)

1. Key Responsibilities
  • Vulnerability Management & Triage: Analyze and verify security findings from automated tools (SAST/DAST/SCA) to filter false positives and prioritize critical issues for development teams.

  • Secure Code Review: Perform manual security reviews of source code (e.g., Java, Python, JavaScript) to identify logic flaws and security vulnerabilities that tools often miss.

  • Threat Modeling: Collaborate with developers during the design phase to identify potential security flaws and architectural risks before coding begins.

  • DevSecOps Integration: Integrate security testing tools (e.g., SonarQube, Checkmarx, Burp Suite) into CI/CD pipelines to automate security checks.
  • Developer Training: Mentor development teams on secure coding standards (e.g., OWASP Top 10) and remediation strategies for identified vulnerabilities.
  • Penetration Testing: Conduct gray-box or white-box security assessments on web applications and APIs.

2. Mandatory Skills (Must-Have)
  • Application Security Expertise: Deep knowledge of the OWASP Top 10 (e.g., SQL Injection, XSS, IDOR) and SANS Top 25 software errors, including how to exploit and fix them.

  • Programming Proficiency: Strong ability to read and write code in at least one major language used by your organization (e.g., Java, Python, Go, or JavaScript). Note: They must be able to fix code, not just break it.

  • Security Tooling: Hands-on experience configuring and tuning SAST (Static Analysis), DAST (Dynamic Analysis), and SCA (Software Composition Analysis) tools.

  • CIS Benchmark Knowledge: Understanding of CIS Benchmarks for operating systems, cloud platforms, and middleware. Ability to review configurations, identify deviations, and guide teams to implement hardened security baselines across servers, endpoints, and cloud workloads.

  • Web & API Security: Solid understanding of web protocols (HTTP/HTTPS), API security (REST/GraphQL), authentication mechanisms (OAuth, SAML, JWT), and encryption standards.

  • Scripting & Automation: Ability to write scripts (Python, Bash) to automate security tasks or integrate tools into the CI/CD pipeline.


3. Preferred Skills:
  • Cloud Security: Experience securing cloud-native environments (AWS, Azure, or GCP) and Infrastructure as Code (Terraform, CloudFormation).

  • Container Security: Familiarity with Docker and Kubernetes security (e.g., scanning container images, securing orchestration).

  • Certifications: Industry-recognized certifications such as OSCP (Offensive Security Certified Professional), GWAPT (GIAC Web Application Penetration Tester), CSSLP (Certified Secure Software Lifecycle Professional), or CISSP.

  • Compliance Knowledge: Familiarity with security standards like ISO 27001, HIPPA and SOC2.

  • Bug Bounty Experience: Participation in public bug bounty programs or capture-the-flag (CTF) competitions, which demonstrates practical, hands-on hacking skills.

Disclaimer : This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.

No Referrers Available

There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.