Application Security Engineer (SAST & DAST, DevSecOps)

2coms

Bengaluru Urban

On-site

INR 1,800,000 - 2,400,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

2coms is seeking an experienced Application Security Engineer to strengthen enterprise security across the SDLC. You will lead testing using SAST, DAST, and SCA tools, embed security into CI/CD, and manage SBOMs and vulnerability metrics.

Collaboration with DevSecOps and platform teams is essential to drive remediation and secure development practices. The role requires 7–12 years of hands-on security experience, deep knowledge of OWASP Top 10, and the ability to translate security findings into

Qualifications

  • 7–12 years of professional experience in Application Security, Secure SDLC, or DevSecOps environments.
  • Experience managing enterprise AppSec scanning platforms and vulnerability lifecycles.
  • Proven ability to integrate security testing into CI/CD pipelines and cloud-native infra.
  • Strong understanding of OWASP Top 10, secure coding, and software supply chain security.

Responsibilities

  • Execute ongoing and targeted security assessments using SAST, SCA, Secrets Detection, and DAST technologies.
  • Analyze security alerts to verify accuracy, filter false positives, and assist Dev teams in remediation.
  • Embed automated security scanning into CI/CD pipelines to enforce secure development gates.
  • Oversee SBOM creation, monitor open-source dependency risks, track CVEs, and report on vulnerabilities.
  • Monitor and manage remediation SLAs, TTD, and TTR metrics with key security KPIs.
  • Collaborate with development, DevSecOps, and platform engineering to enable remediation and security hardening.

Skills

Security testing
CI/CD integration
OWASP Top 10
SBOM management
Vulnerability remediation
Vulnerability analysis
DevSecOps collaboration

Tools

Checkmarx
Veracode
Fortify
SonarQube
GitHub Advanced Security
Snyk
Black Duck
Burp Suite
Invicti
Acunetix
GitGuardian
GitHub Secrets Scanning
Azure DevOps
GitHub Actions
Jenkins
GitLab CI/CD
Prisma Cloud
Wiz
Aqua Security
Microsoft Defender for Cloud
ServiceNow
Power BI
Grafana

Job description

Application Security Engineer (SAST & DAST, DevSecOps)

Bangalore North, India | Posted on 08/17/2026

  • Dial in Extension to connect with Recruiter 410
Job Description

Experience: 7-12 years

Summary

This pivotal role focuses on strengthening enterprise application security by leveraging a comprehensive suite of testing methodologies, including Static Application Security Testing (SAST), Software Composition Analysis (SCA), Secrets Detection, and Dynamic Application Security Testing (DAST). The successful candidate will act as a catalyst for embedding security into the Software Development Life Cycle (SDLC), ensuring seamless integration within CI/CD workflows. By overseeing vulnerability validation, managing Software Bill of Materials (SBOM), and driving risk-based remediation strategies, this position is essential for maintaining robust security postures and delivering actionable security metrics to stakeholders.

Responsibilities
  • Execute ongoing and targeted security assessments utilizing advanced SAST, SCA, Secrets Detection, and DAST technologies.
  • Analyze security alerts to verify accuracy, filter out false positives, and assist development teams in resolving identified vulnerabilities.
  • Embed automated security scanning mechanisms directly into CI/CD pipelines to enforce strict secure development gates.
  • Oversee the creation of SBOMs, monitor open-source dependency risks, track Common Vulnerabilities and Exposures (CVEs), and generate reports on vulnerability exposure.
  • Monitor and manage remediation Service Level Agreements (SLAs), Turnaround Time (TTD), and Time to Remediate (TTR) metrics alongside key application security performance indicators.
  • Collaborate closely with development, DevSecOps, and platform engineering units to facilitate effective remediation and foster a culture of continuous security enhancement.
  • Contribute to security evaluation efforts, optimize scanning tools, produce executive reports, and lead initiatives to empower developers with security best practices.
Requirements
  • Possess between 2-6 years of professional experience within Application Security, Secure SDLC frameworks, or DevSecOps environments.
  • Demonstrate practical expertise in managing enterprise-level AppSec scanning platforms and executing vulnerability management lifecycles.
  • Show proven ability to integrate security testing protocols into CI/CD pipelines and cloud-native infrastructure.
  • Maintain a deep understanding of the OWASP Top 10, secure coding standards, and the principles of software supply chain security.
Technical Skills & Tool Experience
  • SAST: Proficiency with Checkmarx, Veracode, Fortify, SonarQube, or GitHub Advanced Security.
  • SCA & SBOM: Experience utilizing Fortify, Checkmarx, Snyk, or Black Duck for dependency analysis.
  • DAST & API Security: Hands-on knowledge of Fortify, Checkmarx, Burp Suite, Invicti, or Acunetix.
  • Secrets Detection: Familiarity with GitGuardian or GitHub Secret Scanning capabilities.
  • DevSecOps: Competence in Azure DevOps, GitHub Actions, Jenkins, or GitLab CI/CD.
  • Container & Cloud Security: Knowledge of Prisma Cloud, Wiz, Aqua, or Microsoft Defender for Cloud.
  • Reporting & ITSM: Skills in ServiceNow, Power BI, and Grafana for data visualization and ticket management.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2COMS Consulting Pvt. Ltd. • Bengaluru Urban

On-site
INR 1,500,000 - 2,100,000
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2coms • Bengaluru

On-site
INR 2,500,000 - 4,000,000
DevSecOps Engineer (SAST/DAST)
DevSecOps Engineer (SAST/DAST)

Alignity Solutions • Hyderabad

Hybrid
INR 1,200,000 - 1,800,000
Hybrid work model
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
SAST/DAST Application Security Consultant (Pen Testing)
SAST/DAST Application Security Consultant (Pen Testing)

Alignity Solutions • Hyderabad

Hybrid
INR 1,200,000 - 1,800,000
Application Security Testing Consultant with SAST and DAST
Application Security Testing Consultant with SAST and DAST

Cloudxtreme • Hyderabad, Pune District, Bengaluru

On-site
INR 1,200,000 - 1,800,000
Application Security Engineer
Application Security Engineer

Kyndryl • Dadri, Greater Noida

On-site
INR 2,500,000 - 4,500,000
Application Security Manager
Application Security Manager

Coventine Digital • Chennai District, Bengaluru, Pune District

On-site
INR 3,000,000 - 6,000,000
Application Security Engineer (SAST / DAST / DevSecOps / SCA)
Application Security Engineer (SAST / DAST / DevSecOps / SCA)

Qualizeal India • Hyderabad

On-site
INR 1,200,000 - 1,800,000
Application Security Engineer
Application Security Engineer

US Software Group Inc • Bengaluru

Hybrid
INR 9,033,000 - 11,744,000