Stand out for this role — generate a tailored resume and cover letter in about a minute.
Omnissa Bengaluru is seeking an Application Security Engineer to strengthen product security through end-to-end testing of Web, Mobile, and Thick Client apps.
You will perform manual and automated security testing, lead threat modelling, review secure design, and drive CI/CD security automation with Semgrep and SAST/DAST tools.
Application Security Engineer plays a critical role in improving the overall security posture of our products and platforms. This role focuses on end-to-end security testing across Web, Mobile, and Thick Client applications, and partners closely with product and engineering teams to implement secure development practices. The candidate will lead initiatives related to threat modelling, secure code reviews, feature assessments, automation (e.g., Semgrep), and root cause analysis for high-impact vulnerabilities. is an Individual contributor role that requires deep technical expertise, leadership in security initiatives, and a proactive mindset for process improvement.
Must have Skills : -
Good to have skills : -
Conduct in-depth manual and automated security testing of Web, Mobile (Android/iOS), and Thick Client applications.
Perform secure code reviews using both manual techniques and tools like Semgrep, integrated into CI/CD pipelines.
Review product features for potential security issues early in the development lifecycle and provide risk-based recommendations.
Facilitate threat modelling and architecture reviews with product and engineering teams.
Provide guidance on secure design patterns, attack surface reduction, and defense-in-depth strategies.
Lead and drive initiatives to improve the overall security posture of products and development practices.
Define and implement scalable security controls and development guardrails.
Work with Incident Response and Bug Bounty teams to evaluate researcher-submitted and customer-reported issues.
Conduct variant and root cause analysis for high-severity (P0/P1) bugs and provide long-term remediation guidance.
Collaborate with Product BU leaders and engineering stakeholders to align on security goals and assist in their execution.
Act as a trusted security advisor to cross-functional teams across the organization.