Application Security Analyst – Java / DevSecOps
Location: Mysuru, India (Work from Office)
Engagement: Full-time
Shift: US shift
Industry: Transportation & Logistics
About the Client
Our client is a leading North American transportation and logistics provider. It delivers premium, time-critical freight services to freight forwarders, airlines, third-party logistics providers and large enterprise shippers. As its engineering organisation grows, it is building a mature DevSecOps and Secure SDLC capability.
The Role
We're looking for an experienced Application Security Analyst to act as the trusted security advisor to software development teams. You'll embed security across the whole lifecycle: design, development, testing and deployment.
You'll work closely with developers, architects, DevOps and cloud engineers. Together you'll drive shift-left security, promote secure-by-design principles and raise security maturity across engineering. This role suits people who have worked as AppSec Consultants, DevSecOps Engineers, Product Security Engineers or Security Champions, and who enjoy both hands-on security work and enabling developers.
What You'll Do
- Be the primary application security advisor to development, DevOps and engineering teams.
- Provide security guidance through design, development, testing and deployment.
- Carry out secure code reviews of Java applications and services.
- Review application architectures and lead threat modelling to catch risks early.
- Establish and promote DevSecOps practices across development teams.
- Integrate security controls and automated testing into CI/CD pipelines.
- Mentor developers on secure coding, OWASP Top 10, API security, authentication, authorisation and cryptography.
- Design and deliver secure coding training, workshops and security awareness programmes.
- Help teams understand, prioritise and remediate vulnerabilities.
- Analyse and validate findings from SAST, DAST, SCA, penetration tests and vulnerability assessments.
- Work with DevOps and cloud teams to secure containerised and cloud-native applications.
- Support investigations into application-layer security incidents.
- Champion security best practice and help build a Security Champion culture.
What You'll Bring
Essential
- 5+ years in Application Security, DevSecOps, Secure Software Development or a related security function.
- Strong understanding of Secure SDLC, DevSecOps methodologies and AppSec best practice.
- Strong proficiency in Java, Spring Boot, REST APIs and modern application architectures.
- Hands-on experience with secure code reviews and threat modelling.
- Working knowledge of OWASP Top 10, CWE, secure design principles and AppSec testing methods.
- Hands-on experience with security tools such as Semgrep, Trivy, SonarQube, Snyk, Veracode or Checkmarx.
- Experience integrating security into CI/CD using Azure DevOps, GitHub Actions, Jenkins, GitLab, JFrog, Jit.io or similar.
- Knowledge of OAuth 2.0, OpenID Connect, SAML, MFA and identity security.
- Understanding of container and cloud security in Azure, AWS or GCP.
- Experience advising, mentoring and training development teams.
- Strong communication skills and the ability to influence engineering teams.
Desirable
- Experience leading DevSecOps or AppSec initiatives in an enterprise.
- Certifications such as CSSLP, GWAPT, GWEB, CEH, Security+, AZ-500 or AWS Security Specialty.
- Experience building Security Champion programmes.
- Agile and DevOps delivery experience.
- Knowledge of Kubernetes, Docker, Terraform and cloud-native security.
Why Apply
- A visible, influential role shaping how an enterprise engineering organisation builds secure software.
- A balance of hands-on security work and developer enablement.
- Exposure to modern Java, cloud-native and CI/CD tooling at enterprise scale.