Application Security Analyst – Java / DevSecOps

Hireflex247 India Private Limited

India

On-site

INR 1,500,000 - 2,700,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Hireflex247 India Private Limited is hiring an Application Security Analyst to act as the trusted security advisor to software development teams. You will embed security across the lifecycle—design, development, testing and deployment—and work with DevOps and cloud engineers to drive shift-left security.

The role involves secure code reviews of Java applications, threat modelling, and promoting DevSecOps practices across teams. Strong Java & cloud security experience is expected.

Qualifications

  • 5+ years in Application Security, DevSecOps, Secure Software Development or a related security function.
  • Strong understanding of Secure SDLC, DevSecOps methodologies and AppSec best practice.
  • Strong proficiency in Java, Spring Boot, REST APIs and modern application architectures.
  • Hands-on experience with secure code reviews and threat modelling.
  • Working knowledge of OWASP Top 10, CWE, secure design principles and AppSec testing methods.

Responsibilities

  • Be the primary application security advisor to development, DevOps and engineering teams.
  • Provide security guidance through design, development, testing and deployment.
  • Carry out secure code reviews of Java applications and services.
  • Review architectures and lead threat modelling to catch risks early.
  • Establish and promote DevSecOps practices across development teams.
  • Integrate security controls into CI/CD pipelines.
  • Mentor developers on secure coding, OWASP Top 10, API security, authentication and cryptography.
  • Design and deliver secure coding training, workshops and security awareness programmes.
  • Help teams understand, prioritise and remediate vulnerabilities.
  • Analyse findings from SAST, DAST, SCA and pen tests.
  • Work with DevOps and cloud teams to secure containerised and cloud-native apps.
  • Support investigations into application-layer security incidents.
  • Champion security best practice and build a Security Champion culture.

Skills

Java
Spring Boot
REST APIs
Secure SDLC
DevSecOps
AppSec
OWASP Top 10
Threat Modelling
Secure Code Reviews
CI/CD security
SAST/DAST/SCA
Cloud Security

Tools

Semgrep
Trivy
SonarQube
Snyk
Veracode
Checkmarx
Azure DevOps
GitHub Actions
Jenkins
GitLab
JFrog
Jit.io

Job description

Application Security Analyst – Java / DevSecOps

Location: Mysuru, India (Work from Office)
Engagement: Full-time
Shift: US shift
Industry: Transportation & Logistics

About the Client

Our client is a leading North American transportation and logistics provider. It delivers premium, time-critical freight services to freight forwarders, airlines, third-party logistics providers and large enterprise shippers. As its engineering organisation grows, it is building a mature DevSecOps and Secure SDLC capability.

The Role

We're looking for an experienced Application Security Analyst to act as the trusted security advisor to software development teams. You'll embed security across the whole lifecycle: design, development, testing and deployment.

You'll work closely with developers, architects, DevOps and cloud engineers. Together you'll drive shift-left security, promote secure-by-design principles and raise security maturity across engineering. This role suits people who have worked as AppSec Consultants, DevSecOps Engineers, Product Security Engineers or Security Champions, and who enjoy both hands-on security work and enabling developers.

What You'll Do
  • Be the primary application security advisor to development, DevOps and engineering teams.
  • Provide security guidance through design, development, testing and deployment.
  • Carry out secure code reviews of Java applications and services.
  • Review application architectures and lead threat modelling to catch risks early.
  • Establish and promote DevSecOps practices across development teams.
  • Integrate security controls and automated testing into CI/CD pipelines.
  • Mentor developers on secure coding, OWASP Top 10, API security, authentication, authorisation and cryptography.
  • Design and deliver secure coding training, workshops and security awareness programmes.
  • Help teams understand, prioritise and remediate vulnerabilities.
  • Analyse and validate findings from SAST, DAST, SCA, penetration tests and vulnerability assessments.
  • Work with DevOps and cloud teams to secure containerised and cloud-native applications.
  • Support investigations into application-layer security incidents.
  • Champion security best practice and help build a Security Champion culture.
What You'll Bring

Essential

  • 5+ years in Application Security, DevSecOps, Secure Software Development or a related security function.
  • Strong understanding of Secure SDLC, DevSecOps methodologies and AppSec best practice.
  • Strong proficiency in Java, Spring Boot, REST APIs and modern application architectures.
  • Hands-on experience with secure code reviews and threat modelling.
  • Working knowledge of OWASP Top 10, CWE, secure design principles and AppSec testing methods.
  • Hands-on experience with security tools such as Semgrep, Trivy, SonarQube, Snyk, Veracode or Checkmarx.
  • Experience integrating security into CI/CD using Azure DevOps, GitHub Actions, Jenkins, GitLab, JFrog, Jit.io or similar.
  • Knowledge of OAuth 2.0, OpenID Connect, SAML, MFA and identity security.
  • Understanding of container and cloud security in Azure, AWS or GCP.
  • Experience advising, mentoring and training development teams.
  • Strong communication skills and the ability to influence engineering teams.

Desirable

  • Experience leading DevSecOps or AppSec initiatives in an enterprise.
  • Certifications such as CSSLP, GWAPT, GWEB, CEH, Security+, AZ-500 or AWS Security Specialty.
  • Experience building Security Champion programmes.
  • Agile and DevOps delivery experience.
  • Knowledge of Kubernetes, Docker, Terraform and cloud-native security.
Why Apply
  • A visible, influential role shaping how an enterprise engineering organisation builds secure software.
  • A balance of hands-on security work and developer enablement.
  • Exposure to modern Java, cloud-native and CI/CD tooling at enterprise scale.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Analyst (Java)
Application Security Analyst (Java)

Mach 1 Global Supply Chain Services • Mysuru

On-site
INR 1,200,000 - 2,400,000
Application Security Engineer
Application Security Engineer

US Software Group Inc • Bengaluru

On-site
INR 9,033,424 - 11,743,451
Application security
Application security

Codincity Digital Technologies • Chennai District

On-site
INR 3,500,000 - 5,500,000
Lead Engineer - Cyber Security
Lead Engineer - Cyber Security

Mphasis • Bengaluru

On-site
INR 3,500,000 - 7,000,000
Application Security (AppSec) / DevSecOps Engineer
Application Security (AppSec) / DevSecOps Engineer

Zoho • India

Remote
INR 1,200,000 - 2,000,000
Senior Application Security Engineer
Senior Application Security Engineer

Hyland • Hyderabad

On-site
INR 2,500,000 - 4,200,000
Application Security Engineer
Application Security Engineer

Ola • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Application Security Analyst
Application Security Analyst

ZS • Maharashtra

On-site
INR 600,000 - 1,200,000
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
Security Expert (Application / Web Security) (Min 5 Years)
Security Expert (Application / Web Security) (Min 5 Years)

AagatiServe Pvt Ltd • India

On-site
INR 1,000,000 - 1,500,000