Application Security Engineer

GCS Recruitment Specialists

Pune District

Presencial

INR 1 800 000 - 2 800 000

Tempo integral

há 38 horas
Torna-te num dos primeiros candidatos
Gerador de candidaturas

Uma candidatura feita para esta oferta — um currículo e uma carta de apresentação personalizados que vão ao encontro do anúncio.

Ultrapassa os filtros ATS

Resumo da oferta

GCS Recruitment Specialists is seeking a hands-on Application Security Engineer to strengthen the security of software products, platforms, APIs, cloud services, and supporting development practices across the SDLC.

The role partners with product, architecture, engineering, and platform teams to prevent, identify, and remediate vulnerabilities early, coaching developers and enabling secure-by-design practices across cloud-native apps and software supply chains.

Qualificações

  • Bachelor's degree in Computer Science, Software Engineering, Cybersecurity, or related field or equivalent practical experience.
  • Several years of hands-on experience in software engineering, application security, product security, or DevSecOps.
  • Strong programming and scripting skills in at least one language used in modern software development.
  • Demonstrated experience with threat modeling, secure code reviews, and security testing of web apps and APIs.
  • Knowledge of common vulnerability classes including OWASP Top 10, auth/authorization flaws, injection, insecure design, and software supply chain risks.
  • Experience integrating and tuning SAST, DAST, SCA, and secrets scanning tools within CI/CD pipelines.
  • Understanding of cloud-native architectures, containers, identity, encryption, logging, and secure configuration.
  • Excellent collaboration and communication skills; able to influence teams without authority.
  • Strong written and verbal English communication.

Responsabilidades

  • Embed application security requirements across requirements, architecture, design, development, testing, release, and operations.
  • Facilitate threat modeling and security design reviews for applications, APIs, cloud-native services, and AI-enabled capabilities.
  • Perform secure code reviews and targeted security testing; reproduce vulnerabilities and provide remediation guidance.
  • Engineer and improve SAST, DAST, SCA, secrets detection, and related controls in CI/CD workflows.
  • Define and maintain secure coding standards, patterns, and developer guidance.
  • Partner with architects and platform teams on authentication, authorization, data protection, cryptography, logging, and secure configuration.
  • Triage complex findings, assess exploitability, and advise on remediation options.
  • Support development teams in fixing vulnerabilities and verify fixes address root causes.
  • Coordinate application penetration tests and security assessments; translate findings into improvements.
  • Contribute security evidence to product risk reviews, audits, and regulatory readiness including Cyber Resilience Act.

Conhecimentos

Programming skills
Threat modeling
English communication
Collaboration/coaching
CI/CD security

Formação académica

Bachelor's degree in CS/SE/Cybersecurity

Ferramentas

Burp Suite
OWASP ZAP
Semgrep
SonarQube
Snyk
Checkmarx
GitHub Advanced Security

Descrição da oferta de emprego

Application Security Engineer

Reports to

Business Information Security Officer (BISO)

Role Summary

We are seeking a hands-on Application Security Engineer to strengthen the security of software products, platforms, APIs, cloud services, and supporting development practices. The role embeds security throughout the software development lifecycle by partnering with product, architecture, engineering, and platform teams to prevent, identify, and remediate vulnerabilities early.

The successful candidate combines strong software engineering capability with practical application security expertise and enables development teams through automation, reusable patterns, coaching, and risk-based guidance rather than acting as a late-stage approval gate. The role supports a secure-by-design approach in which software producers take ownership of customer security outcomes.

Responsibilities

  • Embed application security requirements and activities across requirements, architecture, design, development, testing, release, and operations.
  • Facilitate threat modeling and security design reviews for applications, APIs, integrations, cloud-native services, and AI-enabled capabilities.
  • Perform secure code reviews and targeted manual security testing; reproduce vulnerabilities and provide actionable remediation guidance.
  • Engineer, integrate, and continuously improve SAST, DAST, software composition analysis, secrets detection, and related controls in CI/CD workflows.
  • Define and maintain secure coding standards, reusable security patterns, reference implementations, and developer guidance.
  • Partner with Solution Architects, Security Architects, and platform teams to address authentication, authorization, data protection, cryptography, logging, and secure configuration.
  • Triage technically complex application and dependency findings, validate exploitability, and advise on severity, business impact, and remediation options.
  • Support development teams in correcting vulnerabilities and verify that fixes address root causes without introducing regressions.
  • Coordinate application penetration tests and security assessments; translate findings into sustainable engineering improvements.
  • Contribute application security evidence to product risk reviews, audits, and regulatory readiness, including expectations arising from the Cyber Resilience Act.
  • Engineer security for desktop clients and hybrid desktop-to-cloud products, including secure update mechanisms, code signing, release integrity, and artifact provenance.
  • Implement SBOM generation and dependency governance workflows that support software component visibility, vulnerability response, and regulatory readiness.
  • Define and verify security requirements for engineering calculation, configuration, and specification workflows, protecting the integrity and correctness of customer outcomes and project data.
  • Support security incident analysis where application behavior, source code, APIs, or software dependencies are involved.
  • Support coordinated vulnerability disclosure and product security response by validating reported issues and helping define sustainable corrective actions.
  • Establish and coach a network of security champions; deliver practical training and improve developer self-service capabilities.
  • Track application security coverage, recurring weakness patterns, remediation performance, and effectiveness of preventive controls.
  • Collaborate with cybersecurity, application security, architecture, DevSecOps, product teams, and enterprise security functions.

Required Qualifications

  • Bachelor's degree in Computer Science, Software Engineering, Cybersecurity, or a related field, or equivalent practical experience.
  • Several years of hands-on experience in software engineering, application security, product security, or DevSecOps.
  • Strong programming and scripting skills in at least one language commonly used in modern software development.
  • Demonstrated experience with threat modeling, secure code review, and security testing of web applications and APIs.
  • Practical knowledge of common vulnerability classes, including the OWASP Top 10, authentication and authorization flaws, injection, insecure design, and software supply chain risks.
  • Experience integrating and tuning SAST, DAST, SCA, and secrets scanning tools within CI/CD pipelines.
  • Understanding of cloud-native architectures, containers, identity, encryption, logging, and secure configuration.
  • Ability to investigate findings, assess exploitability, and communicate technically precise remediation guidance.
  • Strong collaboration and coaching skills, with the ability to influence engineering teams without direct authority.
  • Strong written and verbal communication skills in English.
  • High level of integrity, ownership, and commitment to protecting customers and software assets.
  • Experience working with global teams.
  • Ability to travel internationally when required for key workshops, assessments, or team collaboration.
  • Ability to collaborate effectively across global time zones with teams distributed across multiple continents.

Preferred Qualifications

  • Experience securing AWS-based, SaaS, microservices, mobile, or desktop applications.
  • Knowledge of NIST Secure Software Development Framework, secure-by-design principles, and risk-driven software assurance using OWASP ASVS and SAMM.
  • Experience applying OWASP ASVS at a risk-appropriate assurance level rather than treating every control as universally mandatory.
  • Experience with tools such as Burp Suite, OWASP ZAP, Semgrep, SonarQube, Snyk, Checkmarx, GitHub Advanced Security, or equivalent.
  • Knowledge of API security, OAuth 2.0, OpenID Connect, JWT, secrets management, and software bill of materials practices.
  • Experience applying security to AI-enabled applications and modern software supply chains.
  • Relevant certifications such as CSSLP, GIAC GWEB/GWAPT, OSWE, or equivalent.
  • Familiarity with engineering or technical software environments is advantageous.

GCS is acting as an Employment Agency in relation to this vacancy.

Obtém a tua avaliação gratuita e confidencial do currículo.

ou arrasta e larga o ficheiro aqui.

Similar jobs

Ofertas semelhantes que vale a pena comparar

Staff Engineer - Application Security
Staff Engineer - Application Security

UST • Bengaluru

Presencial
INR 2 400 000 - 4 200 000
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

Presencial
INR 1 800 000 - 2 500 000
Application Security Engineer
Application Security Engineer

Ola • Bengaluru

Presencial
INR 1 200 000 - 2 000 000
Application Security Engineer
Application Security Engineer

DigiCert • Bengaluru

Presencial
INR 1 400 000 - 2 100 000
Generous time off policies
Education, wellness and lifestyle支port
Senior Application Security Engineer
Senior Application Security Engineer

Tenarai • Bengaluru

Presencial
INR 2 500 000 - 4 200 000
Principle Engineer - Application Security
Principle Engineer - Application Security

UST • Bengaluru

Presencial
INR 2 500 000 - 4 800 000
Product Security Analyst - Vulnerability Management
Product Security Analyst - Vulnerability Management

GCS Recruitment Specialists • Pune District

Presencial
INR 1 200 000 - 2 000 000
Application Security Engineer
Application Security Engineer

ESDS Software Solution Limited • Nashik District

Presencial
INR 1 200 000 - 1 800 000
Application Security Engineer
Application Security Engineer

5Exceptions Software Solutions Pvt Ltd • Mumbai

Presencial
INR 1 500 000 - 2 300 000
Senior Product Security Engineer
Senior Product Security Engineer

Dun & Bradstreet • Hyderabad

Presencial
INR 4 000 000 - 7 000 000