Application Security Engineer

Basebiz

Chennai District

On-site

INR 1,200,000 - 1,800,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Basebiz in Chennai is seeking an experienced security engineer to lead large-scale application security programs across DevSecOps, SAST, DAST and API security. You will drive shift-left practices and mentor teams to ensure secure code delivery.

The role requires 3+ years of hands-on experience, strong scripting, familiarity with OWASP Top 10, and the ability to communicate risks to executives in a large agile environment. BE/B.Tech/MCA and solid CI/CD background are essential.

Qualifications

  • Experience performing manual and automated SAST/DAST assessments.
  • Scripting skills (Python, PowerShell, Java, Perl) and up-to-date with exploits.
  • Familiar with web vulnerability scanners and static analysis tools.
  • Experience building a DevSecOps CI/CD pipeline with open-source tools.
  • Experience with SCM tools and CI/CD integration via webhook/actions.
  • Knowledge of CI/CD phases: SAST, SCA, DAST, IAC, compliance, vulnerability mgmt.
  • Maturity planning for a DevSecOps program and pipeline optimization.
  • Understanding of OWASP Top 10 web vulnerabilities.

Responsibilities

  • Lead large-scale application security programs and shift-left security in DevOps.
  • Translate complex security concepts to technical and non-technical audiences.
  • Provide technical leadership and mentor junior team members.
  • Develop automated security solutions across the organization.
  • Support vulnerability analysis using SAST, DAST, SCA, IAST, and API security.
  • Ensure tools deliver value for security and developers and drive remediation.
  • Collaborate with Security and IT to deliver secure projects on time.

Skills

Security assessments
DevSecOps
SAST
DAST
Source Code Review
Threat Modelling
Windows/Linux/UNIX
Excel and PowerPoint

Education

BE/B.Tech/MCA

Tools

Acunetix
HP WebInspect
HCL AppScan
BurpSuite
CheckMarx
Snyk
Fortify
Veracode
Coverity
IBM AppScan Source
GitHub
GitLab
Bitbucket

Job description

Qualifications
  • Experience with performing manual and automated SAST assessments.
  • Experience with scripting/programming skills (e.g., Python, PowerShell, Java, Perl) and staying up-to-date with latest exploits and security trends.
  • Familiarity with dynamic web application vulnerability scanning tools and services (Acunetix, HP WebInspect, HCL AppScan, BurpSuite).
  • Familiarity with static code analysis tools and services (CheckMarx, Snyk, Fortify Static Code Analysis tool, Veracode, Coverity, IBM AppScan Source).
  • Experience in developing a DevSecOps CI/CD pipeline completely using open‑source tools.
  • Experience with SCM tools like Github, Gitlab, Bitbucket and their ability to integrate with CI/CD pipelines via webhooks, actions, etc.
  • Experience with implementing different phases of CI/CD such as secret scanning, SAST, SCA, DAST, infrastructure as code, compliance as code, and vulnerability management.
  • Optimizing the pipeline to produce the best results and planning a maturity model for the DevSecOps program.
  • Understanding of web‑based application vulnerabilities (OWASP Top 10).
Mandatory keyskill (To qualify for the role, you must have)
  • AppSec, DevSecOps, SAST, DAST, Source Code Review and Threat Modelling.
  • BE/B.Tech/MCA.
  • Minimum of 3 years of full‑time work experience in SAST, SCA, DAST, and DevSecOps.
  • Knowledge of Windows, Linux, UNIX, and other major operating systems.
  • Strong Excel and PowerPoint skills.
Ideally, you will also have
  • Familiarity with programming languages such as Java, JavaScript, Python, and Angular.
  • Strong knowledge of relevant security standards (OWASP) and how to apply them to the software development lifecycle in a large agile environment.
  • Experience performing security analysis on web applications and APIs.
  • Experience working in an Agile environment.
Key Responsibilities
  • Expertise in executing large‑scale application security programs.
  • Expertise in shift‑left security concepts and security in DevOps.
  • Understanding of agile software development principles and security practices.
  • Convey complex technical security concepts to technical and non‑technical audiences, including executives.
  • Strong knowledge of software supply chain vulnerabilities and effective communication of mitigation techniques with development teams.
  • Provide technical leadership and advise junior team members on application security engagements.
  • Develop automated solutions that mitigate risks throughout the organization.
  • Support policies and vulnerability analysis using application security testing infrastructure (SAST, DAST, SCA, IAST, and API Security).
  • Ensure these tools deliver maximum value for both security and developer stakeholders.
  • Support integration and automation efforts to make security testing an integral and painless part of code development.
  • Partner with and train developers in delivering secure code.
  • Track, prioritize, and drive remediation of code vulnerabilities.
  • Develop and foster effective working relationships within both Security and IT teams to ensure projects are delivered securely and on‑time.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

Basebiz • Bengaluru

On-site
INR 1,800,000 - 2,800,000
Application Security Engineer
Application Security Engineer

Basebiz • Pune District

On-site
INR 1,800,000 - 3,000,000
Application Testing Engineer
Application Testing Engineer

Quess • Chennai District, Bengaluru, Pune District

Hybrid
INR 700,000 - 1,500,000
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2coms • Bengaluru

On-site
INR 2,500,000 - 4,000,000
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
Application Security Manager
Application Security Manager

Coventine Digital • Chennai District, Bengaluru, Pune District

On-site
INR 3,000,000 - 6,000,000
Application Security Engineer
Application Security Engineer

Whitefield Careers • Bengaluru

On-site
INR 800,000 - 1,200,000
Application Security Lead | Offshore
Application Security Lead | Offshore

Photon • Hyderabad

On-site
INR 850,000 - 1,800,000
Application Security Testing Engineer
Application Security Testing Engineer

Infosys • Bengaluru

On-site
INR 900,000 - 1,200,000
Application Security
Application Security

Airtel • India

On-site
INR 1,200,000 - 2,400,000
Security-focused culture