Application Security Engineer III

Phenom

Hyderabad

On-site

INR 1,800,000 - 3,800,000

Full time

12 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Health and wellness benefits
Flexible hours
Parental leave
Career development opportunities

Job summary

Phenom ITX Platform security role seeks an engineer to triage vulnerabilities, collaborate with engineering, and deploy SAST/DAST tools to keep the platform secure. You will drive remediation, report findings to leadership, and help embed secure-by-default practices across product development.

The role emphasizes threat modeling, vulnerability management, and building scalable security controls within an Agile SaaS environment in Hyderabad, India.

Qualifications

  • Experience securing cloud environments and related controls.
  • Experience building and maintaining a vulnerability management program.
  • Knowledge of threat modeling methodologies and remediation.
  • Hands-on with SAST/DAST and security testing tools.
  • Familiarity with CI/CD security integration and automation.

Responsibilities

  • Research, identify and triage vulnerabilities affecting Phenom ITX Platform and its infrastructure, reporting severity and remediation.
  • Collaborate with engineering to evolve security processes and shift-left practices.
  • Implement fixes to remediate vulnerabilities in collaboration with the engineering team.
  • Deploy and utilize SAST/DAST/SCA and other security tools and communicate findings to production teams.
  • Maintain progress on vulnerabilities and close issues in line with Phenom standards.
  • Develop remediation plans with business/support teams and guide on development strategies.
  • Prepare vulnerability assessment reports for all audiences and leadership.

Skills

Cloud Security
Vulnerability Mgmt
Threat Modeling
SAST/DAST
CI/CD Security
Python
Automation
Security Controls

Tools

Terraform
SIEM
XDR
OWASP ZAP

Job description

Job Description:

Job Requirements
Phenom Intro

Our purpose is to help a billion people find the right job! Phenom is an AI-Powered talent experience platform that is redefining the HR tech space. We have grown into a global organization with offices in 6 countries and over 2,000 employees. As an HR tech unicorn organization, innovation and creativity is within our DNA. Come help us make every talent moment Phenomenal!

What You’ll Do
  • Research, identify and analyze and triage vulnerabilities that could affect Phenom ITX Platform and its supporting infrastructure, and determine its severity, exploitability and corrective action recommendations, summarizing and reporting results.
  • Collaborate with engineering/development teams to evolve software assurance processes to address security risks, and help teams learn and adopt shift-security-to-left practices.
  • Work on implementing the required fixes to remediate the vulnerabilities in collaboration with the engineering team
  • Deploy, improve and utilize SAST/DAST/SCA and other cybersecurity solutions to identify and communicate security vulnerabilities to Phenom production teams
  • Maintain and report progress on the state of application vulnerabilities and elevate as necessary to ensure vulnerability issues are closed and handled in a manner consistent with Phenom standards
  • Work closely with the business, support and production teams to provide input and guidance on development of planned remediation plans and strategies to solve identified vulnerabilities
  • Use technical writing and effective communications to prepare and deliver vulnerability assessment result reports to all levels of audiences (peers and or leadership).
  • Drive compliance support and improvements over time through the management, analysis and tracking of vulnerabilities discovered through audits, products or collaborations.
  • Perform research and analytics and stay apprised on new security vulnerability, threats, risks, attack tools and techniques to contribute and improve Phenom’s Threat model and collaborate with senior engineering and product management staff to incorporate effective security standards and controls into product design.
  • Help in the deployment of Phenom Secure Architecture & Software Development program to support the best cybersecurity development practice, and ensure Phenom ITX Platform is highly secure, resilient and aligned with business and product development strategy.
  • Continuously review and identify security improvement opportunities in existing processes, services, and workflows to ensure Phenom ITX platform is robust against current and future cybersecurity threats.
  • Support cybersecurity process activities including security requirements definition, threat modelling, code reviews and cyber risk assessment.
  • Support on development and maintenance of a "security by default" standard to be used in the development, infrastructure, or any other technology project.
  • Deliver training on Security Development Lifecycle to engineering/development teams
  • Contribute to the review of internal processes and activities and assist in identifying potential opportunities for improvement and automation.
  • Drive continuous improvement activities to define, measure, visualize and improve key cyber security metrics related to Application Security.
  • Provide analytic support to answer questions about vulnerabilities, and general threat intelligence trends
Work Experience
  • Experience with Amazon Web Services cloud environments and its security controls and their corresponding challenges.
  • Experience with microservices architectures & distributed Platforms especially in the SaaS businesses
  • Experience using Agile software development
  • Coding Experience in Scripting & programming languages (such as Terraform, Java, Python, Ruby, etc.)
  • Knowledge of information security principles (Confidentiality, Integrity, Availability Authentication & Public Key Infrastructure (PKI), Data Security or Cryptography), and understanding of common exploitation techniques and mitigation.
  • Experience implementing, managing, and supporting a vulnerability management program (process and technology).
  • Experience and well-known understanding of Dynamic and Static Application Security Testing (DAST & SAST) and infrastructure automation/development utilizing APIs.
  • Understanding of the main cybersecurity tools (SIEM, IPS, XDR, etc.) and how they help to protect an application.
  • Experience working with Threat modeling (e.g., STRIDE, PASTA, FAIR, Security Cards) and vulnerability frameworks standards (e.g., OWASP, CVSS, CWE) with a good understanding of the Cyber Kill Chain and pervasive threat attack methods and remediation.
  • Thought leadership, critical thinking, strong organizational skills, report writing skills to senior level, ability to prioritize and multitask
Benefits
  • Health and wellness benefits/programs to support holistic employee health.
  • Flexible hours and working schedules, as well as parental leave for new parents.
  • Growing organization with career pathing and development opportunities.
  • Tons of perks and extras in every location for all Phenoms!
Diversity, Equity, & Inclusion

Our commitment to diversity runs deep! Diversity is essential to building phenomenal teams, products, and customer experiences. Phenom is proud to be an equal opportunity employer taking collective action to build a more inclusive environment where every candidate and employee feels welcomed.

We recognize there is more to be done. Our teams are committed to continuous improvement until these powerful ideas are ingrained in our culture for Phenom and employers everywhere!

Requirements:

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer II
Application Security Engineer II

Phenom • Hyderabad

On-site
INR 1,500,000 - 3,000,000
Application Security Engineer II
Application Security Engineer II

Phenom People • Hyderabad

On-site
INR 1,500,000 - 2,100,000
Cloud Security Engineer II
Cloud Security Engineer II

Phenom • Hyderabad

On-site
INR 1,000,000 - 1,500,000
Health and wellness benefits
Flexible hours and working schedules
Career pathing and development opportunities
Cyber Security Engineer II
Cyber Security Engineer II

Phenom • Hyderabad

On-site
INR 2,400,000 - 4,200,000
Incident Manager III
Incident Manager III

Phenom • Hyderabad

On-site
INR 2,800,000 - 4,200,000
Health and wellness benefits
Flexible hours
Parental leave
+2
Product Development Engineer III
Product Development Engineer III

Phenom • Hyderabad

On-site
INR 1,500,000 - 2,500,000
Health and wellness benefits
Flexible hours
Career pathing opportunities
+1
Incident Manager II
Incident Manager II

Phenom • Hyderabad

On-site
INR 650,000 - 850,000
Health and wellness benefits
Flexible hours
Parental leave
+1
Solutions Architect
Solutions Architect

Phenom • Hyderabad

On-site
INR 2,000,000 - 2,800,000
Health and wellness programs
Flexible hours
Parental leave
+2
Product Quality Assurance Engineer
Product Quality Assurance Engineer

Phenom People • Hyderabad

On-site
INR 1,000,000 - 1,800,000
Benefits/programs to support holistic-
Career development opportunities
Product Quality Engineer I
Product Quality Engineer I

Phenom • Hyderabad

On-site
INR 900,000 - 1,500,000
Holistic health benefits
Career development opportunities