Application Security Engineer

Omnissa

Bengaluru

On-site

INR 2,800,000 - 4,600,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Omnissa Bengaluru is seeking an Application Security Engineer to strengthen product security through end-to-end testing of Web, Mobile, and Thick Client apps.

You will perform manual and automated security testing, lead threat modelling, review secure design, and drive CI/CD security automation with Semgrep and SAST/DAST tools.

Qualifications

  • 5 to 9 years of experience in the security domain, specifically in Application/Product Security.
  • Demonstrated expertise in Web, Mobile, and Thick Client security testing.
  • Threat modelling and secure design review.
  • Manual code reviews across multiple languages and frameworks.
  • Use and automation of security tools such as Semgrep, SAST/DAST tools, and custom scripts.

Responsibilities

  • Conduct in-depth manual and automated security testing of Web, Mobile, and Thick Client applications.
  • Perform secure code reviews using both manual techniques and tools like Semgrep, integrated into CI/CD pipelines.
  • Review product features for potential security issues early in the development lifecycle and provide risk-based recommendations.
  • Facilitate threat modelling and architecture reviews with product and engineering teams.
  • Lead and drive initiatives to improve the overall security posture of products and development practices.

Skills

Security testing
Threat modelling
Secure code reviews
CI/CD security
Semgrep

Tools

Semgrep
SAST/DAST
Custom scripts

Job description

Application Security Engineer plays a critical role in improving the overall security posture of our products and platforms. This role focuses on end-to-end security testing across Web, Mobile, and Thick Client applications, and partners closely with product and engineering teams to implement secure development practices. The candidate will lead initiatives related to threat modelling, secure code reviews, feature assessments, automation (e.g., Semgrep), and root cause analysis for high-impact vulnerabilities. is an Individual contributor role that requires deep technical expertise, leadership in security initiatives, and a proactive mindset for process improvement.

Must have Skills : -

  • 5 to 9 years of experience in the security domain, specifically in Application/Product Security.
  • Demonstrated expertise in: Web, Mobile, and Thick Client security testing.
  • Threat modelling and secure design review.
  • Manual code reviews across multiple languages and frameworks.
  • Use and automation of security tools such as Semgrep, SAST/DAST tools, and custom scripts.
  • Strong understanding of security principles including authentication, authorization, secure storage, and cryptographic best practices.
  • Excellent communication skills, including the ability to present security issues and recommendations to technical and non-technical stakeholders.

Good to have skills : -

  • Hands-on experience with CI/CD security automation, container security, and cloud environments (AWS/GCP/Azure).
  • Certifications such as OSWE, OSCP, OSEP, GWAPT, GMOB, or equivalent.
  • Experience working with bug bounty programs, VDPs, or vulnerability triage.
  • Track record of contributions to the security community (e.g., blogs, talks, open-source tools, CVEs).
Key Responsibilities:-
Security Testing & Reviews

Conduct in-depth manual and automated security testing of Web, Mobile (Android/iOS), and Thick Client applications.

Perform secure code reviews using both manual techniques and tools like Semgrep, integrated into CI/CD pipelines.

Review product features for potential security issues early in the development lifecycle and provide risk-based recommendations.

Security Architecture & Threat Modelling

Facilitate threat modelling and architecture reviews with product and engineering teams.

Provide guidance on secure design patterns, attack surface reduction, and defense-in-depth strategies.

Process & Posture Improvement

Lead and drive initiatives to improve the overall security posture of products and development practices.

Define and implement scalable security controls and development guardrails.

Security Issue & Incident Collaboration

Work with Incident Response and Bug Bounty teams to evaluate researcher-submitted and customer-reported issues.

Conduct variant and root cause analysis for high-severity (P0/P1) bugs and provide long-term remediation guidance.

Stakeholder Management

Collaborate with Product BU leaders and engineering stakeholders to align on security goals and assist in their execution.

Act as a trusted security advisor to cross-functional teams across the organization.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

Ola • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Application Security Engineer
Application Security Engineer

Kyndryl • Dadri, Greater Noida

On-site
INR 2,500,000 - 4,500,000
Application Security
Application Security

Airtel • India

On-site
INR 1,200,000 - 2,400,000
Security-focused culture
Staff Engineer - Application Security
Staff Engineer - Application Security

UST • Bengaluru

On-site
INR 2,400,000 - 4,200,000
Security Engineer
Security Engineer

Recro • Bengaluru

On-site
INR 1,800,000 - 2,600,000
Application security
Application security

Codincity Digital Technologies • Chennai District

On-site
INR 3,500,000 - 5,500,000
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2coms • Bengaluru

On-site
INR 2,500,000 - 4,000,000
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2COMS Consulting Pvt. Ltd. • Bengaluru Urban

On-site
INR 1,500,000 - 2,100,000
Application Security Lead | Offshore
Application Security Lead | Offshore

Visa Hunt • India

On-site
INR 1,200,000 - 1,800,000
Application Security Analyst
Application Security Analyst

Zs Associates • Mumbai

Hybrid
INR 900,000 - 1,500,000