Application Security Engineer – SAST/DAST & Security Tooling Outage Support

Alignity

Hyderabad

Hybrid

INR 1,200,000 - 2,000,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Alignity is hiring an Application Security Engineer to support SAST/DAST testing and triage, providing remediation guidance and incident response. The role covers onboarding, vulnerability tracking, and outage support across AppScan, Checkmarx, Cycode, and GCP Model Armor in a hybrid, multi‑city setup (Hyderabad, Bengaluru, Pune, Chennai).

You will participate in scheduled patching, ensure security tooling reliability, and collaborate with DevOps and development teams to secure software

Qualifications

  • Hands‑on experience with SAST and DAST tools and processes (e.g., Checkmarx, HCL AppScan, or equivalent), including scan triage and false‑positive analysis.
  • Basic Windows Server support knowledge, with experience using RDP for remote troubleshooting.
  • Working knowledge of IIS Manager and Windows Services, including starting/stopping services and application pools.
  • Basic knowledge of Cycode or similar secret‑scanning tools, Azure DevOps, pull request workflows, webhooks/service hooks, and branch policies.
  • Basic knowledge of Google Cloud Platform (GCP), Terraform, Git repositories, pull request processes, pipeline deployments, and HCP Terraform workspace approvals.
  • Experience with incident handling, vendor coordination, and SOP‑based outage support procedures.
  • Strong written and verbal communication skills, including the ability to escalated unresolved issues via email and Microsoft Teams.
  • Willingness to support scheduled patching windows and off‑business‑hours / on‑call activities as needed.

Responsibilities

  • Perform and support Static (SAST) and Dynamic (DAST) application security testing across in‑scope applications.
  • Triage scan findings across SAST, DAST, SaaS, Secrets, and API security scan results, distinguishing false positives from confirmed vulnerabilities.
  • Provide developers with clear, actionable remediation guidance for validated vulnerabilities.
  • Support application onboarding into scan tooling and manage Penalty‑Box exception handling and unblock decisions.
  • Provide security support during production release ACAB reviews and Breakglass approvals.
  • Create, validate, and drive Vulnerability Information Tracker (VIT) and defect records through to closure.
  • Provide support during scheduled monthly Windows Server patching windows to ensure AppScan and Checkmarx remain available and operational after server restarts.
  • Validate application access for AppScan and Checkmarx following patching.
  • Use RDP to connect to in‑scope management servers for troubleshooting.
  • Check IIS Manager to confirm required application pools are in Started status; verify all required HCL AppScan and Cx services are in Running status.
  • Start any stopped services or application pools; reboot the AppScan management server when required for database‑related errors.
  • Revalidate application login pages after restart and escalated unresolved issues via email or Microsoft Teams.
  • Support Cycode‑related issues, primarily stuck or delayed pull requests during the secret‑scanning process.
  • Review incident details and validate pull request scan history in Cycode; check for missing or delayed pull requests.
  • Coordinate with the E3 team to verify Azure DevOps webhooks and recent ADO changes, and confirm branch policy settings.
  • Validate whether an actual secret is blocking the pull request and raise a vendor support ticket with Cycode when required.

Skills

SAST & DAST tools
Windows Server
IIS Manager
Cycode
Azure DevOps
GCP
Terraform
Git workflows
Incident handling
SOP procedures
Communication skills

Tools

Checkmarx
HCL AppScan
Cycode
Azure DevOps
GCP Model Armor
Terraform
IIS Manager

Job description

Do you love a career where you Experience, Grow & Contribute at the same time, while earning at least 10% above the market? If so, we are excited to have bumped onto you. Learn how we are redefining the meaning of work, and be a part of the team raved by Clients, Job-seekers and Employees. Jobseeker Video Testimonials Employee Glassdoor Reviews If you are a Application Security Engineer looking for excitement, challenge and stability in your work, then you would be glad to come across this page. We are an IT Solutions Integrator/Consulting Firm helping our clients hire the right professional for an exciting long-term project. Here are a few details. Check if you are up for maximizing your earning/growth potential, leveraging our Disruptive Talent Solution.

Role:Application Security Engineer Experience:5-8Years Location:Hyderabad | Bengaluru | Pune | Chennai Work Mode:Hybrid Type:Contract to Hire Notice Period: 0-30 days

Role Summary

We are looking for an Application Security Engineer to support Static and Dynamic Application Security Testing (SAST/DAST) scan and triage activities, while also providing hands‑on outage support for the security tooling ecosystem — including AppScan, Checkmarx, Cycode, and GCP Model Armor. This role combines day‑to‑day vulnerability triage and remediation guidance with structured, SOP‑driven incident response when scanning tools are degraded or unavailable, including support during scheduled patching windows and off‑business‑hours coverage.

Key Responsibilities
SAST & DAST Testing and Triage
  • Perform and support Static (SAST) and Dynamic (DAST) application security testing across in‑scope applications.
  • Triage scan findings across SAST, DAST, SaaS, Secrets, and API security scan results, distinguishing false positives from confirmed vulnerabilities.
  • Provide developers with clear, actionable remediation guidance for validated vulnerabilities.
  • Support application onboarding into scan tooling and manage Penalty‑Box exception handling and unblock decisions.
  • Provide security support during production release ACAB reviews and Breakglass approvals.
  • Create, validate, and drive Vulnerability Information Tracker (VIT) and defect records through to closure.
AppScan & Checkmarx Windows Server Patching Outage Support
  • Provide support during scheduled monthly Windows Server patching windows to ensure AppScan and Checkmarx remain available and operational after server restarts.
  • Validate application access for AppScan and Checkmarx following patching.
  • Use RDP to connect to in‑scope management servers for troubleshooting.
  • Check IIS Manager to confirm required application pools are in Started status; verify all required HCL AppScan and Cx services are in Running status.
  • Start any stopped services or application pools; reboot the AppScan management server when required for database‑related errors.
  • Revalidate application login pages after restart and escalated unresolved issues via email or Microsoft Teams.
Cycode Tool Outage Support
  • Support Cycode‑related issues, primarily stuck or delayed pull requests during the secret‑scanning process.
  • Review incident details and validate pull request scan history in Cycode; check for missing or delayed pull requests.
  • Coordinate with the E3 team to verify Azure DevOps webhooks and recent ADO changes, and confirm branch policy settings.
  • Validate whether an actual secret is blocking the pull request and raise a vendor support ticket with Cycode when required.
  • Coordinate unresolved issues with the appropriate internal teams and Cycode Support until resolution.
GCP Model Armor Support
  • Provide off‑business‑hours support for managing Google Cloud Model Armor configurations.
  • Enable or disable Model Armor for required projects and switch configurations between Inspect Only mode and Inspect and Block mode.
  • Update the necessary Terraform configuration, create pull requests, coordinate approvals, and trigger pipeline deployments.
  • Approve Terraform runs in accordance with the SOP, coordinating with reviewers and approvers as needed.
Required Skills & Experience
  • Hands‑on experience with SAST and DAST tools and processes (e.g., Checkmarx, HCL AppScan, or equivalent), including scan triage and false‑positive analysis.
  • Basic Windows Server support knowledge, with experience using RDP for remote troubleshooting.
  • Working knowledge of IIS Manager and Windows Services, including starting/stopping services and application pools.
  • Basic knowledge of Cycode or similar secret‑scanning tools, Azure DevOps, pull request workflows, webhooks/service hooks, and branch policies.
  • Basic knowledge of Google Cloud Platform (GCP), Terraform, Git repositories, pull request processes, pipeline deployments, and HCP Terraform workspace approvals.
  • Experience with incident handling, vendor coordination, and SOP‑based outage support procedures.
  • Strong written and verbal communication skills, including the ability to escalated unresolved issues via email and Microsoft Teams.
  • Willingness to support scheduled patching windows and off‑business‑hours / on‑call activities as needed.
Preferred Qualifications
  • Prior experience in an Application Security Testing (AST), DevSecOps, or security operations support role.
  • Familiarity with vulnerability management workflows (VIT/defect lifecycle: creation, validation, closure).
  • Exposure to CI/CD pipelines and infrastructure‑as‑code approval workflows.
  • Relevant certifications (e.g., Security+, GCP Associate/Professional, or vendor‑specific tool certifications) are a plus.
Soft Skills
  • Strong attention to detail when following SOP‑based procedures under time pressure.
  • Clear, calm communication during live outage or incident scenarios.
  • Ability to work independently during off‑hours support windows while knowing when to elevate.
  • Collaborative mindset for coordinating across internal teams (E3, DevOps, application teams) and external.

Benefits Visit us at http://alignity.io/careers. Alignity Solutions is an Equal Opportunity Employer, M/F/V/D.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Consultant (SAST & DAST)
Application Security Consultant (SAST & DAST)

Alignity • Hyderabad

Hybrid
INR 1,500,000 - 2,500,000
VAPT Security Engineer
VAPT Security Engineer

Alignity • Hyderabad

Hybrid
INR 2,500,000 - 4,000,000
DevSecOps Engineer (SAST/DAST) 3 - 8 Yrs
DevSecOps Engineer (SAST/DAST) 3 - 8 Yrs

Alignity • Hyderabad

Hybrid
INR 1,200,000 - 1,800,000
Equal Opportunity Employer
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2COMS Consulting Pvt. Ltd. • Bengaluru Urban

On-site
INR 1,500,000 - 2,100,000
DevSecOps-AI SSDLC Security Engineer
DevSecOps-AI SSDLC Security Engineer

Alignity • Hyderabad

Hybrid
INR 1,800,000 - 3,200,000
Hybrid work model
Equal Opportunity Employer
Staff Engineer - Application Security
Staff Engineer - Application Security

UST • Bengaluru

On-site
INR 2,400,000 - 4,200,000
SAST/DAST Application Security Consultant (Pen Testing)
SAST/DAST Application Security Consultant (Pen Testing)

Alignity Solutions • Hyderabad

Hybrid
INR 1,200,000 - 1,800,000
Dynamic application security Engineer
Dynamic application security Engineer

Cloudxtreme • Hyderabad, Chennai District, Bengaluru

Hybrid
INR 1,200,000 - 2,400,000
Hybrid work model
Application Security Testing Consultant with SAST and DAST
Application Security Testing Consultant with SAST and DAST

Cloudxtreme • Hyderabad, Pune District, Bengaluru

On-site
INR 1,200,000 - 1,800,000
Application Security Engineer
Application Security Engineer

Kyndryl Inc. • Uttar Pradesh

On-site
INR 2,500,000 - 4,500,000