TymblHub

© 2026 TymblHub

L3 Product Security / Application Security Engineer (DevSecOps)

Esds Software Solutions
Posted on
Esds Software Solutions logo

Experience
4 - 9 yrs
Salary (CTC)
₹6L - ₹15L
Job Location
Mumbai, India
Vacancy
5
Designation
Product Security Engineer
Job Type
Not specified

Job Description

L3 Product Security / Application Security Engineer (DevSecOps & SOC)

Location: Mumbai / Nashik (Onsite)
Experience: 58 Years

Are you passionate about building secure applications and integrating security into every stage of the software development lifecycle? We are looking for an experienced L3 Product Security / Application Security Engineer to join our Cyber Security team.

Key Responsibilities

  • Design and implement Product Security and Application Security best practices.
  • Perform Secure SDLC reviews, threat modeling, and secure architecture assessments.
  • Conduct Application Security Assessments, Vulnerability Assessments, and Penetration Testing (VAPT).
  • Integrate security controls into CI/CD pipelines as part of DevSecOps practices.
  • Perform SAST, DAST, SCA, and code security reviews using industry-standard tools.
  • Identify, prioritize, and drive remediation of security vulnerabilities.
  • Collaborate with Development, DevOps, Infrastructure, Cloud, and SOC teams to improve security posture.
  • Support security incident investigations related to applications and provide technical expertise to SOC teams.
  • Develop and enhance security monitoring and detection use cases for application threats.
  • Ensure compliance with secure coding standards and industry security frameworks.

Required Skills

  • Product Security
  • Application Security (AppSec)
  • DevSecOps
  • Secure SDLC
  • Threat Modeling
  • Secure Code Review
  • SAST / DAST / SCA
  • Vulnerability Assessment & Penetration Testing (VAPT)
  • API Security
  • OWASP Top 10 / OWASP ASVS
  • CI/CD Security
  • Docker & Kubernetes Security
  • Cloud Security (Azure/AWS)
  • Networking Fundamentals (TCP/IP, HTTP/HTTPS, DNS, SSL/TLS)

SOC Knowledge (Preferred)

Candidates should have exposure to or experience with:

  • Security Operations Center (SOC)
  • SIEM (Microsoft Sentinel, Splunk, IBM QRadar)
  • Incident Response
  • Threat Hunting
  • EDR/XDR (Microsoft Defender XDR, CrowdStrike, SentinelOne)
  • MITRE ATT&CK Framework
  • Log Analysis & Security Monitoring

Security Tools

Experience with one or more of the following:

  • Burp Suite
  • OWASP ZAP
  • Checkmarx
  • Veracode
  • Fortify
  • SonarQube
  • Snyk
  • Nessus
  • Qualys
  • Rapid7
  • Nmap
  • Metasploit

Preferred Certifications

  • CISSP
  • CSSLP
  • OSCP / OSWE
  • CEH
  • CompTIA Security+
  • Microsoft SC-200 / SC-100
  • AWS Security Specialty
  • Azure Security Engineer Associate

What We're Looking For

5–8 years of experience in Product Security, Application Security, or DevSecOps.
Strong understanding of secure coding practices and application security testing.
Hands-on experience with vulnerability management and penetration testing.
Ability to collaborate with SOC teams on security monitoring and incident response.
Excellent analytical, problem-solving, and communication skills.