Application Security Engineer

Kyndryl

Dadri, Greater Noida

On-site

INR 2,500,000 - 4,500,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Kyndryl is seeking a seasoned Application Security SME with 7+ years of experience across SAST, DAST, DevSecOps integration, and threat modeling. You will lead threat modeling workshops, perform manual security testing, validate findings from Fortify, Burp Suite, and others, and mentor junior analysts while ensuring testing quality and SLA adherence.

You will collaborate with DevOps, product teams, and stakeholders to embed AppSec controls in CI/CD pipelines and guide secure design decisions for

Qualifications

  • 7+ years of experience in Application Security and secure SDLC.
  • Proven expertise in threat modeling and risk assessments.
  • Hands-on experience with SAST/DAST tools and manual testing.
  • Ability to lead security testing, triage, and remediation discussions.

Responsibilities

  • Lead threat modeling workshops for critical applications and services.
  • Perform manual security testing to assess business logic and advanced attack scenarios.
  • Validate high-risk findings from DAST/SAST tools and reduce false positives.

Skills

Threat modeling
Manual security testing
DevSecOps integration
SAST
DAST
Vulnerability triage
Security leadership

Education

Bachelor's degree in Computer Science/IT

Tools

Fortify SCA
Checkmarx
SonarQube
Veracode
Fortify WebInspect
Burp Suite Pro
OWASP ZAP
AppScan
Netsparker
Microsoft Threat Modeling Tool
OWASP Threat Dragon
Jenkins
GitLab CI
GitHub Actions
Azure DevOps
Postman
Charles Proxy
MobSF
Splunk/Power BI

Job description

Role & responsibilities

We are seeking a seasonedApplication Security Subject Matter Expert (SME) with 7+ years of experience across multiple facets of application security including SAST, DAST, DevSecOps integration, and threat modeling. The SME will provide leadership in manual security testing, vulnerability validation, secure design reviews, and mentoring, while ensuring testing quality, SLA adherence, and alignment with business risk priorities.

Key Responsibilities
Threat Modeling & Advanced Testing
  • Lead threat modeling workshops for critical applications and services.
  • Perform manual security testing to assess business logic, abuse cases, and advanced attack scenarios.
  • Validate and exploit high-risk findings from DAST tools such as Fortify WebInspect to confirm impact and reduce false positives.
Vulnerability Triage & Remediation
  • Provide second-level triage of critical and high-severity vulnerabilities identified across SAST and DAST.
  • Conduct in-depth discussions with application stakeholders to review critical findings, false positives, and exception requests.
  • Guide application teams in remediation planning, secure design alternatives, and architecture-level mitigations.
DAST & SAST Governance
  • Conduct DAST tool coverage reviews and evaluate feature utilization to maximize effectiveness.
  • Ensure SAST and DAST testing, reporting, and remediation SLAs are consistently met.
  • Track security metrics (coverage, SLA compliance, MTTR) and present insights to AppSec leadership.
Collaboration & Mentorship
  • Collaborate with development, DevOps, and product teams to embed AppSec controls in CI/CD pipelines.
  • Mentor and guide junior analysts (L1/L2) in vulnerability triage, secure coding, and manual testing techniques.
  • Contribute to security automation opportunities, improving efficiency of AppSec processes and tooling.
Stakeholder Engagement
  • Act as a trusted advisor and escalation point for application security issues.
  • Lead second-level report discussions with business and technical stakeholders for critical vulnerabilities.
  • Support secure design and architecture discussions for new initiatives and high-risk projects.
Tools & Technologies
  • SAST: Fortify SCA, Checkmarx, SonarQube, Veracode
  • DAST: Fortify WebInspect, Burp Suite Pro, OWASP ZAP, AppScan, Netsparker
  • Threat Modeling: Microsoft Threat Modeling Tool, OWASP Threat Dragon, custom frameworks
  • DevSecOps: Jenkins, GitLab CI, GitHub Actions, Azure DevOps integration for security scanning
  • Supporting Tools: Postman, Charles Proxy, MobSF (mobile), Splunk/Power BI for reporting
Qualifications
  • Bachelor's degree in Computer Science, Information Technology, or related field.
  • 7+ years of experience in Application Security spanning SAST, DAST, manual testing, and secure SDLC.
  • Proven experience in threat modeling, risk assessments, and secure design reviews.
  • Strong knowledge of OWASP Top 10, API Security Top 10, SANS Top 25, CWE, and emerging threat vectors.
  • Hands-on expertise in integrating security tools within DevSecOps pipelines.
  • Excellent stakeholder communication and leadership skills.
Certifications (Preferred)
  • OSWE / OSCP / OSEP (advanced exploit and web testing)
  • CISSP / CSSLP (for security leadership & secure SDLC expertise)
  • GWAPT / GWEB (web application security)
  • Cloud security certs (CCSP, AWS Security Specialty, Azure SC-100) must have one cloud security certification
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
Application Security
Application Security

Airtel • India

On-site
INR 1,200,000 - 2,400,000
Security-focused culture
Appsec Specialist - Lead
Appsec Specialist - Lead

Adani Group • Ahmedabad District

On-site
INR 2,800,000 - 4,200,000
Cybersecurity Subject Matter Expert
Cybersecurity Subject Matter Expert

Sunovaa Tech • Pune District, Bengaluru

Hybrid
INR 2,500,000 - 4,000,000
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2coms • Bengaluru

On-site
INR 2,500,000 - 4,000,000
Application Security Consultant
Application Security Consultant

SecurityBoat Cybersecurity Solutions Private Limited • Mumbai

On-site
INR 1,200,000 - 2,200,000
Competitive compensation
Specialized cybersecurity team
Professional development
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2COMS Consulting Pvt. Ltd. • Bengaluru Urban

On-site
INR 1,500,000 - 2,100,000
Application Security Engineer
Application Security Engineer

Cynosure Corporate Solutions • Chennai District

On-site
INR 1,500,000 - 2,500,000
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2coms • Bengaluru Urban

On-site
INR 2,600,000 - 3,800,000
SAST/DAST Application Security Consultant (Pen Testing)
SAST/DAST Application Security Consultant (Pen Testing)

Alignity Solutions • Hyderabad

Hybrid
INR 1,200,000 - 1,800,000