Application security

Codincity Digital Technologies

Chennai District

On-site

INR 3,500,000 - 5,500,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Codincity Digital Technologies is seeking an experienced Senior Application Security Engineer to own the application security program for cloud-native fintech systems in Chennai. You will drive DevSecOps adoption, build security automation, and influence secure-by-default practices across the enterprise.

You will partner with IT, DevOps, Engineering, QA, and product teams to embed secure design principles, threat modeling, and vulnerability remediation into development lifecycles.

Qualifications

  • Extensive hands-on experience in application security and software development.
  • Experience building, deploying, maturing CI/CD integrated app security tools.
  • Solid understanding of web technologies, APIs, and SSO protocols.
  • Experience with SAST/DAST/SCA tooling and secure by design.

Responsibilities

  • Develop and update application security standards, secure coding principles, and threat modeling processes.
  • Maintain CI/CD integrated application security solutions, web application firewall technologies, and related tooling.
  • Provide application security support to development teams, including vulnerability explanations and remediation guidance.
  • Integrate and mature application security testing and controls into different phases of teams development lifecycles.
  • Coordinate application security program metrics and reporting.
  • Support ongoing management of application security vulnerabilities through a centralized vulnerability tracking system and defect tracking system.
  • Develop application security training methods and mentoring of security champions.
  • Partner with third party vendors to deliver software security tools and services.
  • Coordinate and partner with third party offensive security (manual pen test) engagements.
  • Provide expert consultation on application security requirements and best practices in relation to vulnerability scanning and secure application design.
  • Partner closely on security operations tasks with cross-functional teammates in Information Security, IT, DevOps, Engineering, and Quality Assurance.
  • Engage with product owners, project managers and developers to integrate security best practices into product design.

Skills

Application security
DevSecOps
Threat modeling
CI/CD integration
Cross-functional collaboration
Cloud security (Azure, GCP)

Tools

SAST
DAST
SCA

Job description

Experienced Application Security Engineer to join a growing information security team responsible for securing next-generation, cloud-native financial technology systems, in the Chennai India. As our Senior Application Security Engineer, you will be responsible for owning application security program. This role will entail delivering application security standards and solutions, driving engineering teams to evolve towards a DevSecOps model, building security automation wherever possible, and serving as formidable force for the secure by default vision across the enterprise. This role will have abundant opportunities to challenge the status-quo and work with cutting-edge technologies, tools, and platforms across all 2 major cloud providers (Azure, GCP).

What your day-to-day will look like:

  • Develop and update application security standards, secure coding principles, and threat modeling processes.
  • Maintaining CI/CD integrated application security solutions, web application firewall technologies, and related
  • Provide application security support to development teams, including reviewing and explaining application security tools and processes, providing vulnerability explanations and remediation guidance.
  • Integrate and mature application security testing and controls into different phases of teams development lifecycles.
  • Coordinate application security program metrics and reporting.
  • Support ongoing management of application security vulnerabilities through a centralized vulnerability tracking system and defect tracking system.
  • Develop application security training methods and mentoring of security champions.
  • Partner with third party vendors to deliver software security tools and services.
  • Coordinate and partner with third party offensive security (manual pen test) engagements.
  • Provide expert consultation on application security requirements and best practices in relation to vulnerability scanning and secure application design.
  • Partner closely on security operations tasks with cross-functional teammates in Information Security, IT, DevOps, Engineering, and Quality Assurance.
  • Engage with product owners, project managers and developers to integrate security best practices into product design.

We'd love to hear from you if you have:

  • Extensive combined hands-on experience in application security and software development.
  • Experience building, deploying, and maturing CI/CD integrated application security tools.
  • Solid understanding of web-based application technologies, web services/APIs, web-based authentication/single sign-on protocol and technologies.
  • Deep experience working with various development technologies including programming languages/frameworks supporting both backend and frontend development, source control management systems, and CI/CD tooling.
  • Experience with application security tools such as Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA).
  • Functional understanding in tooling integrations that support agile, CI/CD, and DevSecOps methodologies.
  • Fundamental understanding of major cloud providers (Azure, GCP).
  • Strong knowledge of software security risks and threats (OWASP top 10).
  • Familiarity with secure by design and shift left security principles.
  • Strong understanding of development methodologies, particularly Agile and DevOps.
  • Able to explain impact of vulnerabilities and mitigating strategies to both technical and non-technical stakeholders.
  • Capable taking ownership of the application security function, ability to work independently with minimal guidance and act as coach to other team members as necessary.
  • Strong communication & interpersonal skills, and experience working cross-functionally with various teams--this will be critical to success in this role.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Product Security Engineer
Senior Product Security Engineer

enableIT • Bengaluru

Hybrid
INR 3,500,000 - 5,500,000
Application Security Engineer
Application Security Engineer

US Software Group Inc • Bengaluru

Hybrid
INR 9,033,000 - 11,744,000
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2COMS Consulting Pvt. Ltd. • Bengaluru Urban

On-site
INR 1,500,000 - 2,100,000
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2coms • Bengaluru Urban

On-site
INR 1,800,000 - 2,400,000
Application Security Specialist Cyber Hygiene
Application Security Specialist Cyber Hygiene

UBS • Pune District

On-site
INR 900,000 - 1,300,000
None
Application Security Engineer
Application Security Engineer

Ola • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Application Security Engineer
Application Security Engineer

Madhees Techno Consulting Pvt Ltd • Pune District

On-site
INR 1,500,000 - 2,100,000
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2coms • Bengaluru

On-site
INR 2,500,000 - 4,000,000
TECHNICAL LEAD - Application Security
TECHNICAL LEAD - Application Security

Happiest Minds Technologies • Bengaluru

On-site
INR 3,500,000 - 6,000,000
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000