We are hiring a hands-on Application Security Architect who is a strong software engineer first. You will design and run the AppSec program across the SDLC, own SAST, DAST and SCA tooling, lead secure architecture reviews and threat modeling, and write real code to build security tools and secure libraries.
This is not a GRC or scan-only role. You should be comfortable writing production-quality code.
What You Will Do
- Build and drive the application security strategy from design to CI/CD to production.
- Own SAST, DAST and SCA tools such as Checkmarx, Fortify, Semgrep, CodeQL, Burp Suite, OWASP ZAP, Snyk, Black Duck and Mend. Handle integration, rule tuning and false-positive reduction.
- Lead secure architecture and design reviews for new services and major changes.
- Write and refactor code to build internal security tools, custom scanners, vulnerability PoCs and secure-by-default libraries.
- Run manual secure code reviews and threat modeling (STRIDE, PASTA) for high-risk services.
- Set up CI/CD security gates: pre-commit hooks, pipeline scanning and break-the-build rules.
- Work with engineering teams on vulnerability remediation and act as the escalation point for security findings.
- Support penetration testing and track fixes.
- Define secure coding standards and train developers and security champions.
- Report AppSec metrics like vulnerability density, MTTR and tool coverage to leadership.
- Keep the program current with OWASP Top 10, CWE/SANS Top 25 and software supply chain threats.
What We Are Looking For
- 12+ years of experience across software development and application security.
- Strong hands-on coding in at least one backend language: Java, Python, Go, Node.js or C#.
- Deep practical experience with SAST, DAST and SCA tools, including deployment and tuning.
- Strong knowledge of OWASP Top 10, OWASP ASVS, CWE/SANS Top 25 and secure design (authentication, authorization, cryptography, input validation, session management).
- Hands-on threat modeling experience.
- Good understanding of CI/CD pipelines and DevSecOps.
- Knowledge of software supply chain security: SBOM, dependency risk and artifact signing.
- Willing to support occasional after-hours and weekend work.
Good to Have
- Container and cloud security: Docker, Kubernetes, AWS, Azure or GCP
- Experience writing custom SAST or DAST rules
- Healthcare or BFSI background, or exposure to PCI-DSS, ISO 27001, SOC 2 or HIPAA
- Certifications such as OSCP, OSWE, CSSLP, GWAPT or CISSP
Why Join
- Global ownership from a fast-growing GCC in Hyderabad
- Work on healthcare and AI-driven platforms at scale
- Health insurance for self, kids and parents, plus accident cover
- Learning and certification reimbursement
Skills
Application Security, DevSecOps, Secure Code Review, Threat Modeling, SAST, DAST, Software Composition Analysis (SCA), OWASP, Penetration Testing, Java, Python, CI/CD
#ApplicationSecurity #AppSec #DevSecOps #SecurityArchitect #ProductSecurity #CyberSecurityJobs #HyderabadJobs #GCC #OWASP