Application Security Engineer

Greenlight Planet Inc.

India

On-site

USD 12,000 - 19,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Sun King is seeking an Application Security Engineer to own the end-to-end security posture of our product platform, including mobile apps, APIs, microservices, and cloud infrastructure. The role emphasizes secure design decisions early in the development lifecycle and rigorous validation.

Remote work is offered for this India-based position, with responsibilities spanning threat modeling, pentesting, vulnerability management, and security automation to protect our AI-enabled products and

Qualifications

  • Bachelor's degree in Computer Science, Cyber Security, or related field.
  • 2+ years of hands-on application security experience in product-based or SaaS environments.
  • Strong knowledge of OWASP Top 10, API Security Top 10, and common authorization flaws.
  • Experience testing web apps, APIs, and Android apps manually.
  • Familiarity with OAuth2, OIDC, JWT and misconfigurations in Keycloak/Firebase.
  • Experience integrating and tuning SAST/DAST (and optionally SCA/IAST) in CI/CD.
  • Exposure to cloud-native security: Kubernetes, IAM, and service mesh concepts.
  • Experience with AI/LLM security risks and guardrails for AI features.
  • Ability to script/automate in Python or Bash.

Responsibilities

  • Own application security for assigned functions via threat modeling, reviews, pentests and vulnerability management.
  • Perform manual penetration testing on web apps, APIs and Android applications.
  • Review security for AI-native products, models, pipelines and inference services.
  • Onboard applications into the SSDLC program and act as security contact for the product.
  • Own security incident response, define remediation and track fixes to closure.
  • Integrate and tune SAST/DAST/IAST/SCA tools in CI/CD and triage false positives.
  • Review and harden cloud infrastructure: Kubernetes RBAC, pod security, network policies, Istio, IAM.
  • Communicate vulnerabilities clearly to developers, PMs and leadership.
  • Conduct application security training for engineers and product managers.

Skills

Threat modeling
Architecture reviews
Penetration testing
Secure coding
Vulnerability mgmt
OAuth2/OIDC
CI/CD security
Kubernetes security
Cloud security
AI/LLM security

Education

Bachelor's degree in Computer Science or related

Tools

SAST tools
DAST tools
IAST tools
CI/CD tooling

Job description

Application Security Engineer

Department: Global Analytics and Technology

Employment Type: Permanent - Full Time

Location: India

Description

Job location: Remote

About the role:
We are looking for an Application Security Engineer to own the end-to-end security posture of our
product platform — spanning mobile applications, REST APIs, microservices, cloud infrastructure, and
third-party integrations. In this role, the Application Security Engineer will be involved into the
product and engineering lifecycle early, shaping secure design decisions before code is written, and
validating them through rigorous assessment.

What you will be expected to do
  • Own application security responsibility for assigned business functions by performing threat
    modeling, architecture reviews, penetration testing, secure coding programs, and vulnerability
    management.
  • Perform manual penetration testing and vulnerability assessments on web applications, APIs,
    and android mobile applications.
  • Perform security reviews for AI‑native products, models, pipelines, and inference services.
  • Onboard applications into the SSDLC program and be a security point of contact for the
    application product.
  • Own security incident response for product-layer issues, define remediation plans, and track
    fixes through to closure.
  • Integrate and tune SAST/DAST/IAST/SCA tools in CI/CD, create custom rules where needed and
    actively triage false positives.
  • Review and harden cloud infrastructure — Kubernetes RBAC, pod security, network policies,
    Istio service mesh, Keycloak/OIDC configurations, and IAM across AWS, DigitalOcean, GCP, and
    Firebase.
  • Communicate vulnerabilities and risk clearly to developers, product managers, and leadership
    — in language that drives actionable results.
  • Conduct application security training for engineers, product managers etc.
You might be a strong candidate if you have/are
  • Bachelor's degree in Computer Science, Cyber Security, or any related fields.
  • At least 2 years of hands‑on application security experience, ideally in product‑based or SaaS
    companies working directly with engineering teams.
  • Good understanding of OWASP Top 10, API Security Top 10, and common authorization flaws
    including BOLA, BFLA, and privilege escalation.
  • Experience in manually testing web apps, APIs, and Android apps, manual code reviews
    (beyond just running tools).
  • Familiarity with OAuth2, OIDC, JWT, and typical misconfigurations in providers such as Keycloak
    and Firebase.
  • Experience integrating and tuning SAST/DAST (and optionally SCA/IAST) tools within CI/CD
    pipelines.
  • Exposure to cloud‑native security: Kubernetes, containers, service mesh (Istio mTLS and
    policies), and IAM concepts across at least one major cloud provider.
  • Experience with Cloudflare WAF, perimeter security scanning, and/or red‑team testing is a
    plus.
  • Familiarity with AI/LLM security risks (e.g., OWASP LLM Top 10).
  • Practical experience implementing guardrails, prompt validation, output filtering, or other
    safety controls in production AI features, or assessing insecure use of third‑party AI APIs.
  • Ability to script/automate (e.g., Python, Bash) to streamline testing, data collection, and
    reporting.
  • Interest in or experience with building AI based security tools that improve coverage or reduce
    manual toil.
What Sun King offers
  • Professional growth in a dynamic, rapidly expanding, high-social-impact industry
  • An open-minded, collaborative culture made up of enthusiastic colleagues who are driven by the challenge of innovation towards profound impact on people and the planet.
  • A truly multicultural experience: you will have the chance to work with and learn from people from different geographies, nationalities, and backgrounds.
  • Structured, tailored learning and development programs that help you become a better leader, manager, and professional through the Sun King Center for Leadership.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Application Security Engineer
Senior Application Security Engineer

Hyland • Hyderabad

Hybrid
INR 2,500,000 - 4,200,000
Application Security Engineer
Application Security Engineer

US Software Group Inc • Bengaluru

On-site
INR 9,033,424 - 11,743,451
Application security
Application security

Codincity Digital Technologies • Chennai District

On-site
INR 3,500,000 - 5,500,000
Senior Cybersecurity Engineer - India
Senior Cybersecurity Engineer - India

Cornerstone OnDemand • Mumbai

Hybrid
INR 400,000 - 700,000
Senior Engineer, Product Security Testing
Senior Engineer, Product Security Testing

News Corp • Bengaluru

On-site
INR 2,500,000 - 4,500,000
Application Security Engineer
Application Security Engineer

5Exceptions Software Solutions Pvt Ltd • Indore District

On-site
INR 1,500,000 - 2,200,000
AI Security Engineer
AI Security Engineer

Five Exceptions Software Solutions • Indore District

On-site
INR 900,000 - 1,300,000
Application Security Engineer
Application Security Engineer

Ola • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

Cornerstone • Mumbai, Pune District

On-site
INR 2,000,000 - 4,000,000
Application Security Engineer
Application Security Engineer

Omnissa • Bengaluru

On-site
INR 2,800,000 - 4,600,000