Job Description
Sr App Security Engineer / Lead
Grade: IS3 | Location: Offshore India | Tower: DCC
Role Summary
Implements and operates the security controls defined by the App Security Architect. Responsible for day-to-day SAST/DAST scan execution, vulnerability triage, remediation tracking, and security hardening across the platform.
Key Responsibilities
Execute and monitor SAST scans (Snyk/Checkmarx) across all microservices and frontend applications within the CI/CD pipeline
Execute DAST scans (OWASP ZAP) against deployed environments and triage findings
Track vulnerability remediation assign findings to development teams, verify fixes, and maintain the security findings register
Implement and maintain security configurations: API gateway WAF rules, mTLS certificates, RBAC policies, and secrets rotation
Support SIEM integration implementation configure event emission hooks and validate event schema
Conduct security code reviews for high-risk components (authentication, payment processing, audit logging)
Produce security scan reports for each sprint and phase review
Support penetration testing readiness preparation
Required Skills Experience
7+ years in application security engineering, with at least 2 years securing banking, fintech, or financial services platforms
Hands-on experience with Snyk, Checkmarx, or equivalent SAST tools integrated into CI/CD pipelines
Experience with OWASP ZAP or Burp Suite for DAST scanning
Knowledge of OAuth2/OIDC, JWT, mTLS, and API security patterns
Familiarity with Kubernetes security (RBAC, network policies, pod security standards)
Understanding of OWASP Top 10 and secure coding practices for Java and Angular applications
Familiarity with security and compliance requirements in regulated financial services (PCI-DSS, ISO 27001, or equivalent)
Nice to Have
Experience with HashiCorp Vault or cloud-native secrets management
AWS or Azure security certifications
Familiarity with SIEM platforms (Splunk, IBM QRadar, or Microsoft Sentinel)