Application Security Engineer

DigiCert

Bengaluru

On-site

INR 1,400,000 - 2,100,000

Full time

2 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Generous time off policies
Education, wellness and lifestyle支port

Job summary

DigiCert is seeking an Application Security Engineer to safeguard our web applications and services by embedding security into the Software Development Life Cycle. You will work with development, DevOps, and security teams to identify, assess, and remediate vulnerabilities while promoting secure coding practices and DevSecOps tooling.

The role offers collaboration across CI/CD pipelines, vulnerability triage, and security automation, with opportunities to grow in product and application security

Qualifications

  • Bachelor's degree in computer science, cybersecurity, or related technical field.
  • Experience in cybersecurity, software engineering, or DevOps with focus on application or product security.
  • Solid understanding of common web application vulnerabilities and remediation strategies.

Responsibilities

  • Integrate security controls across phases of the SDLC.
  • Assist in security assessments including static/dynamic analysis, dependency checks, and limited pentesting.
  • Perform manual and automated code reviews to identify vulnerabilities and flaws.
  • Promote secure development with CI/CD tooling and secure testing practices.
  • Evaluate, deploy, and tune DevSecOps tools (SAST/DAST/SCA).
  • Maintain secure deployment workflows and security automation.
  • Lead cross-functional security reviews under senior guidance.
  • Stay updated on threats and best practices in application security.
  • Triage vulnerabilities from scans, bug bounties, or external assessments.
  • Document processes and playbooks to enable scalable security.
  • Contribute to security standards and reference architectures.
  • Support remediation with engineering teams and foster security-first culture.
  • Other duties as assigned.

Skills

Security engineering
OWASP Top 10
DevSecOps tooling
CI/CD
Communication
Threat modeling

Education

Bachelor's degree in computer science, cybersecurity, or related field

Tools

SAST
DAST
SCA
CI/CD tools

Job description

DigiCert is a global leader in intelligent trust. We protect the digital world by ensuring the security, privacy, and authenticity of every interaction. Our AI-powered DigiCert ONE platform unifies PKI, DNS, and certificate lifecycle management, to secure infrastructure, software, devices, messages, AI content and agents. Learn why more than 100,000 organizations, including 90% of the Fortune 500, choose DigiCert to stop today’s threats and prepare for a quantum-safe future atwww.digicert.com

Job summary

As an Application Security Engineer within our cybersecurity team, you will help safeguard the company’s web applications and services by supporting the integration of security practices into the Software Development Life Cycle (SDLC). You will collaborate with development, DevOps, and security teams to identify, assess, and remediate vulnerabilities, contribute to secure coding practices, and assist in implementing DevSecOps tooling and processes. This role is ideal for someone with a strong technical foundation who is eager to grow within the product/application security space.

What you will do
  • Support the integration of security controls and best practices across various phases of the SDLC.
  • Assist in security assessments, including static and dynamic code analysis, open-source dependency analysis, and limited penetration testing.
  • Participate in manual and automated code reviews to identify potential vulnerabilities and coding flaws.
  • Collaborate with software engineers to promote secure development practices, including the use of security testing tools in CI/CD pipelines.
  • Contribute to the evaluation, deployment, and tuning of DevSecOps tools such as SAST, DAST, and SCA platforms.
  • Help maintain secure deployment workflows and support security automation efforts.
  • Participate in cross-functional security reviews of new features and systems with guidance from senior engineers.
  • Stay up to date on current security threats, vulnerabilities, and best practices in application security.
  • Assist with triaging vulnerabilities from internal scans, bug bounty submissions, or external assessments.
  • Document processes and playbooks to support consistent and scalable security practices.
  • Provide input to the development of internal security standards and reference architectures.
  • Support remediation efforts in collaboration with engineering teams.
  • Participate in promoting a security-first culture across the organization.
  • Other duties and responsibilities as assigned.
What you will have
  • Bachelor’s degree in computer science, cybersecurity, or a related technical field.
  • 2+ years of experience in cybersecurity, software engineering, or DevOps, with at least 1+ years focused on application or product security
  • Solid understanding of common web application vulnerabilities (e.g., OWASP Top 10, CWE) and remediation strategies.
  • Familiarity with DevSecOps tools (SAST, DAST, SCA) and secure SDLC methodologies. - nice to have if they have a solid understanding of common web application vulnerabilities (e.g., OWASP Top 10, CWE).
  • Ability to analyze code and spot security issues with guidance.
  • Strong communication and collaboration skills.
  • Strong attention to detail and willingness to learn new technologies.
Nice to have
  • Hands-on experience with CI/CD pipelines (e.g., GitHub Actions, GitLab CI, Jenkins).
  • Familiarity with security standards and frameworks such as NIST, OWASP SAMM, ISO 27001, or PCI DSS.
  • Experience working in a regulated environment (e.g., financial services, healthcare, or government).
  • Professional certifications such as Security+, CEH, eJPT, or equivalent (OSCP or similar preferred but not required).
  • Exposure to cloud platforms such as AWS, Azure, or GCP.
  • Experience contributing to or managing a bug bounty triage process.
  • Generous time off policies
  • Education, wellness and lifestyle support
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

Hire Today • Bengaluru

On-site
INR 1,500,000 - 2,300,000
Application Security Engineer
Application Security Engineer

GCS Recruitment Specialists • Pune District

On-site
INR 1,800,000 - 2,800,000
Application Security Engineer
Application Security Engineer

Ola • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
Application Security Engineer
Application Security Engineer

ESDS Software Solution Limited • Nashik District

On-site
INR 1,200,000 - 1,800,000
Senior Application Security Engineer
Senior Application Security Engineer

Tenarai • Bengaluru

On-site
INR 2,500,000 - 4,200,000
Staff Engineer - Application Security
Staff Engineer - Application Security

UST • Bengaluru

On-site
INR 2,400,000 - 4,200,000
Application Security Engineer
Application Security Engineer

5Exceptions Software Solutions Pvt Ltd • Mumbai

On-site
INR 1,500,000 - 2,300,000
Senior Product Security Engineer
Senior Product Security Engineer

Pocket FM Corp. • Bengaluru

On-site
INR 2,000,000 - 3,200,000
Senior Application Security Specialist
Senior Application Security Specialist

IntouchCX • Hyderabad

On-site
INR 3,200,000 - 4,200,000