Application Security Engineer

India Fan Corporation

Hyderabad

On-site

INR 1,800,000 - 2,700,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

India Fan Corporation seeks an experienced Application Security Engineer specializing in Software Composition Analysis (SCA) to secure our software supply chain and mitigate risks from open-source components used in internal applications.

The role involves integrating scanning tools into CI/CD pipelines, collaborating with developers and engineering teams to triage vulnerabilities, and embedding security controls across the software development lifecycle for scalable secure coding practices.

Qualifications

  • 5–7 years of experience in various AppSec domains.
  • Experience with integrating SCA and security tooling into CI/CD.
  • Experience with open-source governance and license compliance.
  • Knowledge of OWASP Top 10 and SSDLC.

Responsibilities

  • Lead the implementation and optimization of SCA solutions across enterprise applications.
  • Integrate and automate SCA and security tools within CI/CD pipelines.
  • Triage vulnerabilities, assess exploitability, and embed security controls in the SDLC.
  • Provide technical guidance on secure coding practices to development teams.

Job description

Summary

We are seeking an experienced Application Security Engineer with deep expertise in Software Composition Analysis (SCA) to strengthen the security of our software supply chain and reduce risks associated with open-source and third-party software components in internally developed applications.

This role will help integrate scanning tools into CI/CD pipelines and partner with developers and engineering teams to triage vulnerabilities to embed security controls throughout the software development lifecycle.

The ideal candidate will have extensive experience integrating SCA and application security tooling into CI/CD pipelines, evaluating vulnerability exploitability, managing open-source license compliance, and enabling developers to build secure applications at scale.

Experience with AI/LLM-focused security scanning tools and emerging application security technologies is highly desirable.

Key Responsibilities
  • 5 - 7 years of experience in various AppSec domains.
  • Lead the implementation and optimization of Software Composition Analysis (SCA) solutions to identify vulnerabilities, license compliance issues, and software supply chain risks across enterprise applications.
  • Establish and maintain processes for managing risks associated with open-source and third-party software dependencies.
  • Integrate and automate SCA and application security tools within CI/CD pipelines to provide continuous security validation throughout the software development lifecycle.
  • Deploy and manage security platforms such as Black Duck, Mend, Veracode, Checkmarx, and experience with any emerging AI/LLM-based security scanning solutions would be desirable.
  • Experience embedding security guardrails into build pipelines using tools like Jenkins, GitHub Actions, or GitLab CI.
  • Artifactory integration experience in the pipeline and developer workflows would be desirable.
  • Analyze identified vulnerabilities to determine exploitability, reachability, and potential business impact.
  • Perform risk-based prioritization of findings, focusing remediation efforts on vulnerabilities that pose the greatest threat to the organization.
  • Validate findings to reduce false positives and improve overall vulnerability management effectiveness.
  • Develop, maintain, and enforce open-source software governance policies.
  • Provide technical guidance, security coding, and best practices to development teams.
  • Strong proficiency in multiple programming languages, including Java, Python, C++, and Ruby.
  • Strong understanding of how third-party packages are integrated through external public repos (e.g., npm for JavaScript, pip for Python, Maven/Gradle for Java).
  • Knowledge of application security best practices and industry standards, including OWASP Top 10, Secure Software Development Lifecycle (SSDLC), Software Supply Chain Security principles, and Vulnerability Management frameworks.
Professional Skills
  • Excellent communication, strong analytical thinking, and problem-solving capabilities.
  • Self-motivated with a commitment to continuous learning and staying current with evolving security threats and technologies.
Education
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related technical discipline.

(ref:hirist.tech)

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Security Engineer
Lead Security Engineer

Rwindia • Bengaluru

On-site
INR 3,500,000 - 6,000,000
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
DevSecOps (Security test lead) Engineer
DevSecOps (Security test lead) Engineer

D-techworks • Mumbai, Bengaluru

On-site
INR 2,500,000 - 4,000,000
Application Security Engineer
Application Security Engineer

DigiCert • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Generous time off policies
Top shelf benefits
Education, wellness, and lifestyle support
Application Security Specialist
Application Security Specialist

Pearson India Education Services Pvt Ltd • Bengaluru

On-site
INR 1,800,000 - 3,200,000
Infosec Engineer IV
Infosec Engineer IV

7-Eleven Global Solution Center – India • Bengaluru

On-site
INR 800,000 - 1,200,000
Application Testing Engineer
Application Testing Engineer

Quess • Chennai District, Bengaluru, Pune District

Hybrid
INR 700,000 - 1,500,000
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2coms • Bengaluru

On-site
INR 2,500,000 - 4,000,000
Information Security Analyst
Information Security Analyst

S&P Global Market Intelligence • Gurugram District, Dadri

On-site
INR 600,000 - 900,000
Application Security Engineer
Application Security Engineer

Basebiz • Bengaluru

On-site
INR 1,800,000 - 2,800,000