Application Security Engineer (AppSec Engineer) - Bengaluru

Omnissa

Bengaluru

Hybrid

INR 1,800,000 - 2,800,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Hybrid work model
Office in Bengaluru
Security-focused environment

Job summary

Omnissa seeks an Application Security Engineer to strengthen the security of Web, Mobile, and Thick Client products. This IC role partners with product and engineering to embed secure development practices and drive security initiatives.

The candidate will lead threat modelling, secure code reviews, and automation (Semgrep) across CI/CD pipelines, ensuring high-impact vulnerabilities are remediated with long-term fixes. Hybrid work from Bengaluru office with travel as needed.

Qualifications

  • 5–8 years in security, focused on application/product security.
  • Web/Mobile/Thick Client security testing expertise.
  • Threat modelling and secure design reviews.
  • Manual security reviews across multiple languages/frameworks.
  • Semgrep and SAST/DAST tooling and scripting.
  • Languages: Java, Kotlin, Swift, JS, Python, C#/ .NET.
  • Strong security fundamentals and cryptographic practices.
  • Excellent communication to explain findings.

Responsibilities

  • Conduct in-depth manual and automated security testing of Web, Mobile, and Thick Client apps.
  • Perform secure code reviews, with Semgrep, integrated into CI/CD pipelines.
  • Review features early in the lifecycle and provide risk-based recommendations.
  • Facilitate threat modelling and architecture reviews with product/engineering teams.
  • Lead initiatives to improve overall security posture and guardrails.
  • Collaborate with Incident Response and bug bounty teams to triage issues.

Skills

5-8 years security
Web/Mobile/Thick Client security
Threat modelling
Manual code review
Security tooling Semgrep
Languages: Java/Kotlin/Swift/JS/Python
Security fundamentals
Communication skills
CI/CD security automation

Education

OSWE/OSCP/OSEP/GWAPT/GMOB certifications

Tools

Semgrep
SAST/DAST tools
Custom scripts
Cloud platforms AWS/GCP/Azure
Bug bounty programs

Job description

Job Description:
We are Omnissa!

The world is evolving fast, and organizations everywhere—from corporations to schools—are under immense pressure to provide flexible, work-from-anywhere solutions. They need IT infrastructure that empowers employees and customers to access applications from any device, on any cloud, all while maintaining top-tier security. That’s where Omnissa comes in.

The Omnissa Platform is the first AI-driven digital work platform that enables smart, seamless and secure work experiences from anywhere. It uniquely integrates multiple industry-leading solutions including Unified Endpoint Management, Virtual Apps and Desktops, Digital Employee Experience, and Security & Compliance through common data, identity, administration, and automation services. Built on the vision of autonomous workspaces - self configuring, self‑healing, and self‑securing - Omnissa continuously adapts to the way people work; delivering personalized and engaging employee experiences, while optimizing security, IT operations and costs. we’re experiencing rapid growth—and this is just the beginning of our journey!

At Omnissa, we’re driven by a shared mission to maximize value for our customers. Our five Core Values guide us: Act in Alignment, Build Trust, Foster Inclusiveness, Drive Efficiency, and Maximize Customer Value —all with the aim of achieving shared success for our clients and our team.

As a global private company with over 4,000 employees, we’re always looking for passionate, talented individuals to join us. If you’re ready to make an impact and help shape the future of work, we’d love to hear from you!

What is the opportunity?

Application Security Engineer plays a critical role in improving the overall security posture of our products and platforms. This role focuses on end-to-end security testing across Web, Mobile, and Thick Client applications, and partners closely with product and engineering teams to implement secure development practices. The candidate will lead initiatives related to threat modelling, secure code reviews, feature assessments, automation (e.g., Semgrep), and root cause analysis for high-impact vulnerabilities. This is an Individual contributor role that requires deep technical expertise, leadership in security initiatives, and a proactive mindset for process improvement.

Must have Skills : -
  • 5 to 8 years of experience in the security domain, specifically in Application/Product Security.
  • Demonstrated expertise in: Web, Mobile, and Thick Client security testing.
  • Threat modelling and secure design review.
  • Manual code reviews across multiple languages and frameworks.
  • Use and automation of security tools such as Semgrep, SAST/DAST tools, and custom scripts.
  • Proficiency with languages such as Java, Kotlin, Swift, JavaScript, Python, C#/.NET.
  • Strong understanding of security principles including authentication, authorization, secure storage, and cryptographic best practices.
  • Excellent communication skills, including the ability to present security issues and recommendations to technical and non-technical stakeholders.
Good to have skills : -
  • Hands‑on experience with CI/CD security automation , container security, and cloud environments (AWS/GCP/Azure).
  • Certifications such as OSWE, OSCP, OSEP, GWAPT, GMOB , or equivalent.
  • Experience working with bug bounty programs , VDPs, or vulnerability triage.
  • Track record of contributions to the security community (e.g., blogs, talks, open‑source tools, CVEs).
Key Responsibilities:-
Security Testing & Reviews

Conduct in‑depth manual and automated security testing of Web, Mobile (Android/iOS), and Thick Client applications.

Perform secure code reviews using both manual techniques and tools like Semgrep, integrated into CI/CD pipelines.

Review product features for potential security issues early in the development lifecycle and provide risk-based recommendations.

Security Architecture & Threat Modelling

Facilitate threat modelling and architecture reviews with product and engineering teams.

Provide guidance on secure design patterns, attack surface reduction, and defense‑in‑depth strategies.

Process & Posture Improvement

Lead and drive initiatives to improve the overall security posture of products and development practices.

Define and implement scalable security controls and development guardrails.

Security Issue & Incident Collaboration

Work with Incident Response and Bug Bounty teams to evaluate researcher‑submitted and customer‑reported issues.

Conduct variant and root‑cause analysis for high‑severity (P0/P1) bugs and provide long-term remediation guidance.

Stakeholder Management

Collaborate with Product BU leaders and engineering stakeholders to align on security goals and assist in their execution.

Act as a trusted security advisor to cross‑functional teams across the organization.

What will you bring to Omnissa?
  • Work closely with teams to create, update and maintain threat models
  • Perform secure code reviews and manual application security testing across all our products
  • Triage and validate externally reported issues against our products
  • Provide guidance and education to developers
  • Develop ways to help identify and prevent systematic issues

Location: Bengaluru

Location Type: HYBRID. NO REMOTE. This role offers a balanced arrangement, with the expectation of working 3 days a week in our local office and the flexibility to work from home for the remaining days. It is essential that you reside within a reasonable commuting distance of the office location for the in‑office workdays.

Travel Expectations: 5% of travel Domestic/International only if business demands.

What is the leadership like for this role? What is the structure and culture of the team like?

Report to the Manager / Sr. Manager. Work closely with a committed team of security engineers, product managers, and developers focused on innovation and getting things done. Build trust among team members and stakeholders, committing to customer success. Operate in a transparent, communicative environment that emphasizes work-life balance and having fun at work.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Member of Technical Staff
Member of Technical Staff

Omnissa • Bengaluru

Hybrid
INR 3,500,000 - 7,000,000
Member of Technical Staff
Member of Technical Staff

Omnissa India Private Limited • Bengaluru

Hybrid
INR 1,800,000 - 2,400,000
Senior Software Engineer (C#, Distributed systems)- Bengaluru
Senior Software Engineer (C#, Distributed systems)- Bengaluru

Omnissa • Bengaluru

Hybrid
INR 1,800,000 - 2,400,000
QE Professional - Automation Python
QE Professional - Automation Python

Omnissa • Bengaluru

On-site
INR 2,400,000 - 4,200,000
Senior Automation QA Engineer - Networking - Bengaluru
Senior Automation QA Engineer - Networking - Bengaluru

Omnissa India Private Limited • Bengaluru

On-site
INR 700,000 - 1,100,000
Software/Sr.Software Engineer - C#.net
Software/Sr.Software Engineer - C#.net

Omnissa • Chennai District

On-site
INR 1,200,000 - 1,800,000
Senior MTS/Staff Engineer C#.net (9+Years)
Senior MTS/Staff Engineer C#.net (9+Years)

Omnissa • Bengaluru

Hybrid
INR 4,000,000 - 7,000,000
Hybrid work (3 days in office)
Senior Automation QA Engineer - Networking - Bengaluru
Senior Automation QA Engineer - Networking - Bengaluru

Omnissa • Bengaluru

On-site
INR 3,500,000 - 6,000,000
Application Security Engineer
Application Security Engineer

Omnissa • Bengaluru

On-site
INR 2,800,000 - 4,600,000
Software Engineer (C#, Distributed systems)
Software Engineer (C#, Distributed systems)

Omnissa • Bengaluru

On-site
INR 800,000 - 1,200,000