TymblHub

© 2026 TymblHub

Application Security Engineer - SSDLC

Reserve Bank Information Technology
Posted on
Reserve Bank Information Technology logo

Experience
3 - 8 yrs
Job Location
Bengaluru, India
Vacancy
1
Designation
Application Security Engineer
Job Type
ONSITE

Job Description

Role: Application Security Engineer


Experience range: 3 years - 8 years


Reporting Structure

Reports to the Platform Software Security Services Lead/ Manager


Education

Bachelors Degree in Engineering/Master Degree in Engineering in CSE/CS/IT/IT Security or Cyber Security Specialization/B.Sc/M.Sc/MCA (IT/Computer) preferred


Experience/ Qualifications

1. Experience in the following process areas:

  • Secure SDLC Methodologies for Waterfall/ Agile software development
  • Should be well-versed with Security best practices like OWASP and NIST guidelines
  • Ability to perform security review of microservices architecture, API Security
  • Hands on experience on Source Code reviews - SAST solution
  • Hands on experience on Dynamic Application Security Testing - DAST
  • Hands on experience in Software Composition Analysis - SCA
  • Hands on experience in performing Tech Stack Review
  • Comfortable working in an environment that practices Agile development, engaging Product Owner and other stakeholders
  • Good knowledge of Cloud platform/VMware
  • Ability to identify vulnerabilities & threat actors in the application cycle and communicate effectively to the stake holders.
  • Threat Modelling PASTA, STRIDE etc (Good to Have)

2. Possesses ability to quickly understand the technical and functional aspects of the project to be able to communicate effectively with different stakeholders.

3. Excellent written and verbal communication skills in English, high integrity, strong work ethic and ability to empathize with the customer.

4. Ability to work effectively in a fast-paced, project-oriented environment

5. Ability to prioritize and execute tasks

6. Ability to handle sensitive and confidential information

7. Strong analytical and problem-solving skills



Responsibilities

1. Perform security best practices review followed by Development team

2. Perform SCA and report vulnerabilities and recommendations

3. Perform Tech Stack review and report findings along with recommendations.

  1. Perform code review (supporting SAST Tool) and remove false positives if any, and report valid security issues to development team
  2. Perform DAST on the various applications and remove false positives if any, and report valid security issues to development team
  3. Contribution to RFP process and assist in Implementing SSDLC Tools.

7. Escalate issues and risks and proactively takes ownership for resolution

8. Track milestones and deliverables and provide regular status reporting to respective stakeholders


Certifications

CSSLP/CISSP/SSCP or equivalent certification are desirable (Good to Have).

Application/API Security Threat Modelling/API Security product Implementations, Specialization or OWASP certifications or Agile Certifications are a plus


Employment Type

All positions are on fixed term contract on a full-time basis exclusively for ReBIT, initially for a period of five years, extendable by mutual consent


Location

Navi Mumbai, Bangalore


No Referrers Available

There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.