Application Security Architect, Cybersecurity

Ensemble Health Partners

Hyderabad

Hybrid

INR 3,000,000 - 5,500,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Healthcare coverage for associates
Paid time off
Retirement benefits
Recognition and wellness programs

Job summary

Ensemble Health Partners India is seeking an experienced Application Security Architect to lead security across the SDLC. You will design and drive the AppSec program, own SAST/DAST/SCA tooling, and mentor developers to embed secure coding practices.

You will read and write production-grade code across languages, perform architecture reviews, and coordinate remediation with engineering, while maintaining a focus on evolving security patterns and measurements.

Qualifications

  • Hands-on software development in one backend language and familiarity with others.
  • Extensive AppSec expertise with practical experience using SAST, DAST, and SCA tools.
  • Strong knowledge of OWASP Top 10/ASVS and secure design principles.
  • Experience with threat modeling methodologies and secure coding practices.
  • Familiarity with container/cloud security and SBOM concepts.
  • Ability to build custom security tooling and JS/Python-based scanners.

Responsibilities

  • Design and drive the application security strategy across the SDLC from design reviews to production.
  • Own and tune SAST, DAST, and SCA tooling, including integration and false-positive reduction.
  • Conduct secure architecture reviews for new features and major system changes.
  • Read, write, and refactor code to build internal tooling and secure libraries.
  • Mentor developers, deliver secure coding training, and collaborate with teams to remediate vulnerabilities.
  • Track and report AppSec metrics to leadership and evolve the program.

Skills

Backend languages
AppSec expertise
SAST/DAST/SCA
OWASP Top 10/ASVS
Threat modeling
Container security
SBOM
Security tooling
Healthcare/BFSI

Job description

Thank you for considering a career at Ensemble Health Partners India! Ensemble Health Partners - The single solution for a frictionless revenue cycle with the purpose of redefining the possible in healthcare by empowering people to be the difference. Our India Office is an extension of Ensemble's team and culture designed to augment and enhance our talent and skill base in Revenue Cycle Management in addition to our long-standing presence in technology. Leveraging our platform of services, technology, business intelligence and analytics, our teams are creating and maintaining innovative products and systems to help our revenue cycle operators achieve the most efficient, ideal outcomes for our clients. Our teams are certified in revenue cycle best practices and are supporting end-to-end RCM operations. We are at the forefront of innovation using cutting-edge technology to drive meaningful impact in the Revenue Cycle Management landscape. As a leading player in the industry, we offer an environment that fosters growth, creativity, and collaboration, where your expertise will be valued, and your contributions will make a difference.

Job Title

Application Security Architect

Experience

12+ Years

Job Location

Hyderabad (Hybrid)

Position Summary

We are looking for a hands-on Application Security Architect who combines strong software engineering skills with deep application security expertise. This is a generalist role - you should be comfortable reading and writing production-quality code across multiple languages, and equally comfortable designing and running an AppSec program that spans SAST, DAST, and SCA tooling, secure architecture reviews, and developer enablement. This position will require occasional after-hours and weekend work. The selected candidate will be expected to attend work on a regular and predictable schedule in accordance with agency leave policy and perform other duties as assigned.

Key Responsibilities

Design and drive the application security strategy across the SDLC - from design reviews through CI/CD to production. Own and continuously tune SAST (e.g., Checkmarx, Fortify, Semgrep, CodeQL), DAST (e.g., Burp Suite Enterprise, OWASP ZAP, Invicti), and SCA (e.g., Snyk, Black Duck, Mend, Dependency-Track) tooling - integration, rule tuning, false-positive reduction, and coverage. Perform secure architecture and design reviews for new features, services, and major system changes. Read, write, and refactor code (not just review it) to build internal tooling, PoCs for vulnerabilities, custom scanners, and secure-by-default libraries/frameworks. Conduct manual code reviews and threat modeling for high-risk services, complementing automated tooling. Partner with engineering teams to remediate vulnerabilities, and act as a technical escalation point for security findings. Build and maintain CI/CD security gates (pre-commit hooks, pipeline scanning, break-the-build policies). Define and evangelize secure coding standards, guardrails, and reusable security patterns/libraries. Run or support penetration tests and coordinate remediation with engineering. Mentor developers and security champions; deliver secure coding training. Track and report AppSec metrics (vulnerability density, MTTR, tool coverage, false-positive rates) to leadership. Stay current on emerging threats (OWASP Top 10, CWE/SANS Top 25, supply chain attacks) and evolve the program accordingly.

Required Skills:
  • Engineering foundation (must-have - this is a generalist coding role, not a pure GRC/tooling role)
  • Strong hands-on software development experience in at least one backend language (e.g., Java, Python, Go, Node.js, C#) and working familiarity with others. Comfortable reading and writing code across the stack - APIs, web front ends, mobile, or infrastructure-as-code, as relevant to your environment. Solid understanding of software design patterns, frameworks, and modern CI/CD pipelines.
  • Application security expertise
  • Deep, practical experience with SAST, DAST, and SCA tools - selection, deployment, tuning, and interpreting results (not just running scans).
  • Strong grasp of OWASP Top 10, OWASP ASVS, CWE/SANS Top 25, and secure design principles (authN/authZ, cryptography, input validation, session management).
  • Experience with threat modeling methodologies (STRIDE, PASTA, or similar).
  • Familiarity with container/cloud security (Docker, Kubernetes, AWS/Azure/GCP security services) is a plus.
  • Understanding of software supply chain security (SBOM, dependency risk, artifact signing).
  • Experience building custom security tooling or writing SAST/DAST rules.
  • Exposure to regulated industries (BFSI, healthcare) or compliance frameworks (PCI-DSS, ISO 27001, SOC 2).
Why Choose Ensemble India?

People First, Last + Always We believe in putting people at the heart of everything. Our culture is rooted in collaboration, growth and innovation - where your contributions are valued, your voice is heard and your potential is nurtured.

A Place to Thrive Whether you're just starting out or looking to grow your career, Ensemble India is a place where you can do your best work and be your best self. We offer structured career paths, paid professional certifications, tuition reimbursement and mentorship opportunities to help you advance.

Comprehensive Total Rewards

We support the physical, emotional and financial well-being of you and your family. Our Total Rewards package include:

  • Healthcare coverage for associates and their immediate families including parents
  • Paid time off plans
  • Retirement benefits
  • Recognition and wellness programs
  • Market competitive pay rates
Inclusive Culture

Our organization is deeply committed to fostering a positive environment and culture where we celebrate and reward merit and contribution and where every associate feels valued, included, and empowered to succeed.

Purpose-Driven Impact

We proudly partner with local communities through philanthropic initiatives - from school supply drives to health awareness campaigns - because giving back is part of who we are.

Equal Employment Opportunity

Ensemble Health Partners is an equal employment opportunity employer. It is our policy not to discriminate against any applicant or employee based on race, color, sex, sexual orientation, gender, gender identity, religion, national origin, age, disability, military or veteran status, genetic information or any other basis protected by applicable federal, state, or local laws. Ensemble Health Partners also prohibits harassment of applicants or employees based on any of these protected categories.

Ensemble Health Partners is a leading provider of technology-enabled revenue cycle management solutions for health systems, including hospitals and affiliated physician groups. They offer end-to-end revenue cycle solutions as well as a comprehensive suite of point solutions to clients across the country. Our India Office is an extension of Ensemble's team and culture designed to augment and enhance our talent and skill base in Revenue Cycle Management in addition to our long-standing presence in technology. Leveraging our platform of services, technology, business intelligence and analytics, our teams are creating and maintaining innovative products and systems to help our revenue cycle operators achieve the most efficient, ideal outcomes for our clients. Our teams are certified in revenue cycle best practices and are supporting end-to-end RCM operations. We are at the forefront of innovation using cutting-edge technology to drive meaningful impact in the Revenue Cycle Management landscape. As a leading player in the industry, we offer an environment that fosters growth, creativity, and collaboration, where your expertise will be valued, and your contributions will make a difference.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr. Cybersecurity Engineer
Sr. Cybersecurity Engineer

Ensemble Health Partners • Hyderabad

Hybrid
INR 2,500,000 - 4,500,000
Healthcare coverage
Paid time off
Retirement benefits
+1
Senior Engineer, Software
Senior Engineer, Software

Ensemble Health Partners • Hyderabad

Hybrid
INR 1,500,000 - 2,500,000
Sr Network Engineer
Sr Network Engineer

Ensemble Health Partners • Hyderabad

Hybrid
INR 2,500,000 - 4,500,000
Healthcare benefits
Paid time off
Retirement benefits
+1
Engineer II, Business Intelligence
Engineer II, Business Intelligence

Ensemble Health Partners • Hyderabad

Hybrid
INR 1,800,000 - 2,800,000
Healthcare coverage for associates and
Immediate family coverage
Paid time off
+3
Senior Engineer, BI
Senior Engineer, BI

Ensemble Health Partners • Hyderabad

Hybrid
INR 2,500,000 - 3,500,000
Healthcare coverage
Paid time off
Retirement benefits
+1
Specialist, Denials
Specialist, Denials

Ensemble Health Partners • Hyderabad

On-site
INR 500,000 - 700,000
Senior Manager, Software Engineering
Senior Manager, Software Engineering

Ensemble Health Partners, India • Hyderabad

Hybrid
INR 3,500,000 - 6,000,000
Health insurance
Professional development programs
Labor law compliant benefits
Lead Software Engineer
Lead Software Engineer

Ensemble Global • Hyderabad

On-site
INR 1,000,000 - 1,500,000
Comprehensive health insurance coverage
Accidental insurance coverage
Professional development programs
+2
Manager - Cybersecurity (SOC, GRC & Security Engineering)
Manager - Cybersecurity (SOC, GRC & Security Engineering)

Ensemble Health Partners, India • Hyderabad

Hybrid
INR 2,800,000 - 4,600,000
Comprehensive health insurance
Professional development programs
Labor law compliant benefits
+1
Director, Software Engineering
Director, Software Engineering

Ensemble Health Partners, India • Hyderabad

Hybrid
INR 2,500,000 - 3,500,000
Comprehensive health insurance
Accidental insurance
Professional development programs
+2