Application Security Analyst (Java)

Mach 1 Global Supply Chain Services

Mysuru

On-site

INR 1,200,000 - 2,400,000

Full time

7 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Mach 1 Global Supply Chain Services is seeking an experienced Application Security Analyst focused on Java to guide developers in building secure software across the enterprise. You will collaborate with software development, DevOps, and cloud teams to embed security into the SDLC, identify vulnerabilities, and promote secure coding practices.

The role requires hands-on experience with Java, Spring Boot, and security tooling, and you will lead secure coding training, threat modeling, and

Qualifications

  • 5+ years of experience in Application Security, or Secure Software Development.
  • Strong proficiency in Java, Spring Boot, REST APIs, and modern application architectures.
  • Experience with OWASP Top 10, CWE, secure coding standards, and threat modeling.
  • Hands-on experience with security tools such as SemGrep, Trivvy, SonarQube, Snyk, or similar solutions.
  • Knowledge of secure authentication technologies including OAuth 2.0, OpenID Connect, SAML, and MFA.
  • Familiarity with CI/CD pipelines, JIT.io, Azure DevOps, Git, Jenkins, GitHub Actions, or similar platforms.
  • Understanding of cloud security principles and container security (Docker/Kubernetes) preferred.

Responsibilities

  • Perform secure code reviews of Java applications and services.
  • Guide teams to identify and remediate vulnerabilities using SAST/DAST/ SCA and pen tests.
  • Integrate security controls and automated security testing into CI/CD pipelines.
  • Advise on secure coding practices, OWASP Top 10, API security, auth and cryptography.
  • Conduct threat modeling and security architecture reviews for new apps and major changes.
  • Support vulnerability remediation efforts and validate fixes.
  • Develop and deliver secure coding training for Java developers.
  • Assist with security incident investigations involving application-layer vulnerabilities.
  • Collaborate with DevOps and cloud teams to secure containerized and cloud-native apps.

Skills

Java
Spring Boot
REST APIs
Threat modeling
Secure coding practices
CI/CD
Cloud security

Tools

SemGrep
Trivy
SonarQube
Snyk
OAuth 2.0
OpenID Connect
SAML
Docker
Kubernetes
Jenkins
GitHub Actions
Azure DevOps

Job description

Application Security Analyst (Java)
Position Summary

We are seeking an experienced Application Security Analyst with a strong focus on Java application security to help guide our developers to maintain secure software across the enterprise. As a member of the security team, this role partners closely with software development, DevOps, and cloud teams to integrate security into the software development lifecycle (SDLC), identify and remediate vulnerabilities, and promote secure coding practices.

Key Responsibilities
  • Perform secure code reviews of Java applications and services.
  • Provide guidance to identify, assess, and remediate application security vulnerabilities using SAST, DAST, SCA, and penetration testing results.
  • Integrate security controls and automated security testing into CI/CD pipelines.
  • Provide guidance to development teams on secure coding practices, OWASP Top 10, API security, authentication, authorization, and cryptography.
  • Conduct threat modeling and security architecture reviews for new applications and major system changes.
  • Support vulnerability remediation efforts and validate fixes.
  • Develop and deliver secure coding training and awareness programs for Java developers.
  • Assist with security incident investigations involving application-layer vulnerabilities.
  • Collaborate with DevOps and cloud engineering teams to secure containerized and cloud-native applications.
Required Qualifications
  • 5+ years of experience in Application Security, or Secure Software Development.
  • Strong proficiency in Java, Spring Boot, REST APIs, and modern application architectures.
  • Experience with OWASP Top 10, CWE, secure coding standards, and threat modeling.
  • Hands-on experience with security tools such as SemGrep, Trivvy, SonarQube, Snyk, or similar solutions.
  • Knowledge of secure authentication technologies including OAuth 2.0, OpenID Connect, SAML, and MFA.
  • Familiarity with CI/CD pipelines, JIT.io, Azure DevOps, Git, Jenkins, GitHub Actions, or similar platforms.
  • Understanding of cloud security principles and container security (Docker/Kubernetes) preferred.
Others

Mode & Location: Work from Office / Mysore

Shift: US Shifts

Notice Period: Immediate / 30 Days / Serving Notice Period

Compensation: As per Industry Standard

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

US Software Group Inc • Bengaluru

Hybrid
INR 9,033,000 - 11,744,000
Application Security Consultant
Application Security Consultant

ERM Placement Services • Delhi

On-site
INR 1,200,000 - 1,800,000
Application Security Analyst
Application Security Analyst

Tata Consultancy Services • Mumbai

On-site
INR 900,000 - 1,500,000
Application Security Consultant
Application Security Consultant

ERM Placement Services • Kolkata District

On-site
INR 2,800,000 - 4,000,000
Junior Application Security Analyst
Junior Application Security Analyst

Pineswift Technologies • Dadri

On-site
INR 600,000 - 1,200,000
Application Security (AppSec) – Security Analyst (Freshers / Experienced)
Application Security (AppSec) – Security Analyst (Freshers / Experienced)

ESP Engineered • Mumbai

On-site
INR 600,000 - 1,200,000
Application Security Engineer
Application Security Engineer

Cloudxtreme • Hyderabad

On-site
INR 1,400,000 - 2,600,000
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2COMS Consulting Pvt. Ltd. • Bengaluru Urban

On-site
INR 1,500,000 - 2,100,000
Application Security Analyst
Application Security Analyst

VMC Soft Technologies, Inc • Bengaluru

On-site
INR 4,000,000 - 6,500,000
Application Security Engineer (6 Months Contract)
Application Security Engineer (6 Months Contract)

Weekday AI (YC W21) • Hyderabad

On-site
INR 1,500,000 - 2,000,000