Application Security (AppSec) / DevSecOps Engineer

Zoho

India

Remote

INR 1,200,000 - 2,000,000

Part time

12 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Zoho is seeking an experienced Application Security / DevSecOps Engineer to bake robust safety controls directly into automated software delivery frameworks.

The ideal candidate will bridge software engineering with security operations, implementing automated code testing gates, leading threat modeling workshops, and hardening application containers to identify and mitigate software vulnerabilities before code hits production.

Qualifications

  • 4–8 years of core software engineering or cloud DevOps experience.
  • 3+ years building application safety frameworks.
  • Strong knowledge of SAST/DAST/SCA tooling.
  • Proven security in SDLC and DevSecOps pipelines.
  • Mandatory CASE, CDP, CSSLP, or CEH certification.

Responsibilities

  • Configure and manage application scanning frameworks (SAST, DAST, SCA).
  • Triage and remediate software vulnerabilities with dev teams.
  • Lead comprehensive threat modeling assessments for new apps and features.
  • Secure containerized workloads; audit Dockerfile rules and Kubernetes isolation.
  • Drive application security investigations of incidents and malicious payloads.

Skills

DevSecOps
Threat modeling
Container security
SAST

Tools

Snyk
Checkmarx
Veracode
OWASP ZAP
Docker
Kubernetes

Job description

Application Security (AppSec) / DevSecOps Engineer

Application Security (AppSec) / DevSecOps Engineer

  • Employment Type: Contract
  • Work Mode: Remote
  • Location: Offshore
  • Total Experience Required: 4 to 8 years
  • Relevant Experience Required: 3+ years of dedicated experience securing software development lifecycles (SDLC) and engineering DevSecOps pipelines
  • Mandatory Certification: Certified Application Security Engineer (CASE), Certified DevSecOps Professional (CDP), CSSLP, or CEH
Job Summary

We are seeking an experienced Application Security / DevSecOps Engineer to bake robust safety controls directly into our automated software delivery frameworks. The ideal candidate will bridge software engineering with security operations, implementing automated code testing gates, leading threat modeling workshops, and hardening application containers to identify and mitigate software vulnerabilities before code hits production.

  • Configure and manage application scanning frameworks, orchestrating Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) tooling.
  • Triage and remediate software vulnerabilities, analyzing code flaws, open-source dependency risks, and secret exposure incidents alongside software development teams.
  • Lead comprehensive threat modeling assessments for new applications and architecture features, identifying attack surfaces and defining secure coding frameworks.
  • Secure containerized application workloads, auditing Dockerfile construction rules, verifying baseline machine images, and checking Kubernetes network isolation parameters.
  • Drive application layer incident investigations, analyzing malicious payload web requests, API tampering logs, and cross-site scripting (XSS) vectors to improve software perimeters.
Requirements
  • 4 to 8 years of core software engineering or cloud DevOps experience, with 3+ dedicated years actively designing, building, and deploying application safety frameworks.
  • Strong technical mastery of automated testing engines (e.g., Snyk , Checkmarx , Veracode, OWASP ZAP ), container security paradigms, and infrastructure-as-code hardening.
  • Deep structural understanding of the OWASP Top 10 vulnerabilities, API security perimeters, modern secure coding standards, and cryptographic signing protocols.
  • Mandatory certification: CASE, CDP, CSSLP, or CEH.
Preferred Qualifications
  • Experience implementing automated code patching routines or managing runtime application self-protection (RASP) layers.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Engineer (SAST / DAST / DevSecOps / SCA)
Application Security Engineer (SAST / DAST / DevSecOps / SCA)

Qualizeal India • Hyderabad

On-site
INR 1,200,000 - 1,800,000
Application Security & AppSec Operations Engineer
Application Security & AppSec Operations Engineer

Lonvec Technologies Private Limited • Bengaluru

On-site
INR 2,500,000 - 4,200,000
DevSecOps Engineer
DevSecOps Engineer

Delta6Labs FinTech Pvt Ltd • India

On-site
INR 1,200,000 - 1,800,000
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
Application Security Engineer
Application Security Engineer

Whitefield Careers • Bengaluru

On-site
INR 800,000 - 1,200,000
Application Security Engineer
Application Security Engineer

Yantran • Chennai District

On-site
INR 1,200,000 - 2,400,000
Staff Engineer - Application Security
Staff Engineer - Application Security

UST • Bengaluru

On-site
INR 2,400,000 - 4,200,000
Principle Engineer - Application Security
Principle Engineer - Application Security

UST • Bengaluru

On-site
INR 2,500,000 - 4,800,000
Sr Application Security Engineer
Sr Application Security Engineer

Caps Talent Technologies • Hyderabad

On-site
INR 3,500,000 - 6,000,000
Application Security Engineer
Application Security Engineer

Ola • Bengaluru

On-site
INR 1,200,000 - 2,000,000