Experience
5 - 10 yrs
Job Location
Bengaluru, India
Vacancy
1
Designation
Senior Security Engineer
Job Type
Not specified
Job Description
Job Summary
We are seeking a Senior Application Security Engineer to lead and enhance application security across our software development lifecycle. You will partner with engineering teams to identify security risks early, implement secure coding practices, and improve vulnerability management for applications and services.
Responsibilities
- Design, implement, and scale application security programs across SDLC (requirements, design, development, testing, and release).
- Perform security assessments of web applications, APIs, and services (static/dynamic/manual testing).
- Build and maintain security test automation (SAST/DAST/SCA workflows, custom checks, CI/CD integrations).
- Review architecture and code changes for security issues; provide actionable remediation guidance.
- Lead remediation efforts for high-severity vulnerabilities; validate fixes and ensure root-cause improvements.
- Define security standards and guardrails (threat modeling, secure design patterns, coding standards, policies).
- Collaborate with DevOps/Platform and product engineering to ensure secure deployment and runtime configurations.
- Create security documentation and training for developers (secure coding, OWASP Top 10, common attack vectors).
- Monitor security posture and drive continuous improvement using metrics and reports.
- Stay current with evolving threats, vulnerabilities, and security best practices; propose improvements.
Required Skills Qualifications
- 5+ years of experience in application security, secure software engineering, or related security engineering roles.
- Strong knowledge of web/API security (OWASP Top 10, auth/session management, input validation, access control, SSRF, XSS, SQLi, CSRF, etc.).
- Hands-on experience with SAST/DAST/SCA tools and integrating them into CI/CD pipelines.
- Proficiency with secure coding and threat modeling methodologies.
- Experience with at least one programming language (e.g., Java, Python, Go, JavaScript/TypeScript, C#) and the ability to conduct code reviews for security.
- Solid understanding of common security concepts: cryptography basics, authentication/authorization models, logging/monitoring, secure configuration.
- Experience working with vulnerability management processes (triage, prioritization, risk acceptance, verification).
Preferred Qualifications
- Experience with cloud security (AWS/Azure/GCP) and containerized environments.
- Familiarity with frameworks such as OWASP ASVS, SAMM, or similar security maturity frameworks.
- Security automation experience (custom scripts, policy-as-code, security dashboards).
- Certifications such as: OSCP, eJPT/eWPT, or AppSec-focused certifications (optional).
Soft Skills
- Strong communication skills and ability to explain security risks in business and technical terms.
- Ability to collaborate cross-functionally and influence without authority.
- Ownership mindset with strong prioritization and problem-solving skills.
Reporting / Collaboration
- Works closely with: Product Engineering, DevOps/Platform, QA, and Security leadership.
- Participates in: design reviews, incident response (as needed), and security roadmap planning.
No Referrers Available
There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.
