Application Security Engineer

Basebiz

Bengaluru

On-site

INR 1,800,000 - 2,800,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Basebiz is seeking an experienced security professional to lead application security programs, focusing on SAST/DAST/SCA, threat modelling, and DevSecOps integration. The role requires strong scripting skills and familiarity with major security tools, driving secure coding practices across Agile teams.

The candidate will collaborate with developers to embed security into the SDLC, orchestrate remediation of vulnerabilities, and communicate risk to stakeholders while promoting secure design and

Qualifications

  • Minimum 3 years of full-time work experience in SAST, SCA, DAST, and DevSecOps.
  • Experience with performing manual and automated security assessments (SAST/DAST).
  • Familiarity with static and dynamic code analysis tools (e.g., CheckMarx, Snyk, Fortify, Veracode, Coverity, IBM AppScan Source).
  • Experience with scripting/programming languages (Python, PowerShell, Java, Perl) and staying up-to-date with exploits and security trends.
  • Knowledge of Windows, Linux, UNIX, and other operating systems; strong Excel and PowerPoint skills.

Responsibilities

  • Operate large-scale application security programs with a focus on shift-left security within DevOps.
  • Convey complex security concepts to technical and non-technical audiences, including executives.
  • Lead remediation efforts for code vulnerabilities and track progress with development teams.
  • Develop automated security solutions to mitigate risks across the organization.
  • Support policies and vulnerability analysis using SAST, DAST, SCA, IAST, and API security tooling.
  • Collaborate with Security and IT teams to ensure secure and timely project delivery.

Skills

AppSec
DevSecOps
SAST
DAST
Source Code Review
Threat Modelling
Python
PowerShell
Java
Automation scripting
CI/CD
Web security

Education

BE/B.Tech/MCA

Tools

Github
Gitlab
Bitbucket
BurpSuite
Acunetix
HP WebInspect
HCL AppScan
BurpSuite
CheckMarx
Snyk
Fortify Static Code Analysis
Veracode
Coverity
IBM AppScan Source

Job description

Qualifications
  • Experience with performing manual and automated SAST assessments.
  • Experience with scripting/programming skills (e.g., Python, PowerShell, Java, Perl) and staying up-to-date with latest exploits and security trends.
  • Familiarity with dynamic web application vulnerability scanning tools and services (Acunetix, HP WebInspect, HCL AppScan, BurpSuite).
  • Familiarity with static code analysis tools and services (CheckMarx, Snyk, Fortify Static Code Analysis tool, Veracode, Coverity, IBM AppScan Source).
  • Experience in developing a DevSecOps CI/CD pipeline completely using open‑source tools.
  • Experience with SCM tools like Github, Gitlab, Bitbucket and their ability to integrate with CI/CD pipelines via webhooks, actions, etc.
  • Experience with implementing different phases of CI/CD such as secret scanning, SAST, SCA, DAST, infrastructure as code, compliance as code, and vulnerability management.
  • Optimizing the pipeline to produce the best results and planning a maturity model for the DevSecOps program.
  • Understanding of web‑based application vulnerabilities (OWASP Top 10).
Mandatory keyskill (To qualify for the role, you must have)
  • AppSec, DevSecOps, SAST, DAST, Source Code Review and Threat Modelling.
  • BE/B.Tech/MCA.
  • Minimum of 3 years of full‑time work experience in SAST, SCA, DAST, and DevSecOps.
  • Knowledge of Windows, Linux, UNIX, and other major operating systems.
  • Strong Excel and PowerPoint skills.
Ideally, you will also have
  • Familiarity with programming languages such as Java, JavaScript, Python, and Angular.
  • Strong knowledge of relevant security standards (OWASP) and how to apply them to the software development lifecycle in a large agile environment.
  • Experience performing security analysis on web applications and APIs.
  • Experience working in an Agile environment.
Key Responsibilities
  • Expertise in executing large‑scale application security programs.
  • Expertise in shift‑left security concepts and security in DevOps.
  • Understanding of agile software development principles and security practices.
  • Convey complex technical security concepts to technical and non‑technical audiences, including executives.
  • Strong knowledge of software supply chain vulnerabilities and effective communication of mitigation techniques with development teams.
  • Provide technical leadership and advise junior team members on application security engagements.
  • Develop automated solutions that mitigate risks throughout the organization.
  • Support policies and vulnerability analysis using application security testing infrastructure (SAST, DAST, SCA, IAST, and API Security).
  • Ensure these tools deliver maximum value for both security and developer stakeholders.
  • Support integration and automation efforts to make security testing an integral and painless part of code development.
  • Partner with and train developers in delivering secure code.
  • Track, prioritize, and drive remediation of code vulnerabilities.
  • Develop and foster effective working relationships within both Security and IT teams to ensure projects are delivered securely and on‑time.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

Basebiz • Chennai District

On-site
INR 1,200,000 - 1,800,000
Application Security Engineer
Application Security Engineer

Basebiz • Pune District

On-site
INR 1,800,000 - 3,000,000
Application Testing Engineer
Application Testing Engineer

Quess • Chennai District, Bengaluru, Pune District

Hybrid
INR 700,000 - 1,500,000
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2coms • Bengaluru

On-site
INR 2,500,000 - 4,000,000
Application Security Manager
Application Security Manager

Coventine Digital • Chennai District, Bengaluru, Pune District

On-site
INR 3,000,000 - 6,000,000
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
Application Security Engineer
Application Security Engineer

Whitefield Careers • Bengaluru

On-site
INR 800,000 - 1,200,000
Application Security Lead | Offshore
Application Security Lead | Offshore

Photon • Hyderabad

On-site
INR 850,000 - 1,800,000
Application Security Testing Engineer
Application Security Testing Engineer

Infosys • Bengaluru

On-site
INR 900,000 - 1,200,000
Application Security
Application Security

Airtel • India

On-site
INR 1,200,000 - 2,400,000
Security-focused culture