Application Security Engineer - SSDLC

Reserve Bank Information Technology

Bengaluru

On-site

INR 1,200,000 - 1,800,000

Full time

10 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Reserve Bank Information Technology is seeking an Application Security Engineer with 3–8 years of experience to strengthen our software security lifecycle across cloud and microservices. The role involves conducting SAST/DAST/SCA reviews, secure SDLC governance, and collaboration with development teams and stakeholders to proactively identify and remediate vulnerabilities.

Candidates should have strong English communication, familiarity with OWASP/NIST, and knowledge of VMware cloud platforms.

Qualifications

  • Experience in Secure SDLC for Waterfall or Agile development.
  • Knowledge of OWASP and NIST security guidelines.
  • Experience reviewing security of microservices and APIs.
  • Hands-on with Source Code reviews (SAST).
  • Hands-on with DAST and SCA tooling.
  • Experience in Tech Stack Review.
  • Familiarity with Cloud platforms/VMware and agile collaboration.
  • Ability to identify vulnerabilities and communicate with stakeholders.
  • Threat modelling knowledge (PASTA/STRIDE) is a plus.

Responsibilities

  • Perform security best practices review with development team.
  • Perform SCA and report vulnerabilities and recommendations.
  • Perform Tech Stack review and report findings with recommendations.
  • Perform code review with SAST and remove false positives, report issues.
  • Perform DAST and report issues to development team.
  • Contribute to RFP process and SSDLC tools implementation.
  • Escalate issues and risks and take ownership for resolution.
  • Track milestones and provide status updates to stakeholders.

Skills

Secure SDLC
OWASP
NIST guidelines
API security
SAST
DAST
SCA
Tech stack review
Cloud platforms/VMware
Threat modelling
Stakeholder communication

Education

B.E./B.Tech in Engineering
M.E./M.Tech in Engineering
CS/IT/IT Security specialization
BSc/MSc/MCA (IT/Computer)

Tools

SAST Tool
DAST Tool
SCA Tool
Cloud/VMware tooling

Job description

Role: Application Security Engineer

Experience range: 3 years - 8 years

Reporting Structure

Reports to the Platform Software Security Services Lead/ Manager

Education

Bachelors Degree in Engineering/Master Degree in Engineering in CSE/CS/IT/IT Security or Cyber Security Specialization/B.Sc/M.Sc/MCA (IT/Computer) preferred

Experience/ Qualifications

1. Experience in the following process areas:

  • Secure SDLC Methodologies for Waterfall/ Agile software development
  • Should be well-versed with Security best practices like OWASP and NIST guidelines
  • Ability to perform security review of microservices architecture, API Security
  • Hands on experience on Source Code reviews - SAST solution
  • Hands on experience on Dynamic Application Security Testing - DAST
  • Hands on experience in Software Composition Analysis - SCA
  • Hands on experience in performing Tech Stack Review
  • Comfortable working in an environment that practices Agile development, engaging Product Owner and other stakeholders
  • Good knowledge of Cloud platform/VMware
  • Ability to identify vulnerabilities & threat actors in the application cycle and communicate effectively to the stake holders.
  • Threat Modelling PASTA, STRIDE etc (Good to Have)

2. Possesses ability to quickly understand the technical and functional aspects of the project to be able to communicate effectively with different stakeholders.

3. Excellent written and verbal communication skills in English, high integrity, strong work ethic and ability to empathize with the customer.

4. Ability to work effectively in a fast-paced, project-oriented environment

5. Ability to prioritize and execute tasks

6. Ability to handle sensitive and confidential information

7. Strong analytical and problem-solving skills

Responsibilities
  1. Perform security best practices review followed by Development team
  2. Perform SCA and report vulnerabilities and recommendations
  3. Perform Tech Stack review and report findings along with recommendations.
  4. Perform code review (supporting SAST Tool) and remove false positives if any, and report valid security issues to development team
  5. Perform DAST on the various applications and remove false positives if any, and report valid security issues to development team
  6. Contribution to RFP process and assist in Implementing SSDLC Tools.

7. Escalate issues and risks and proactively takes ownership for resolution

8. Track milestones and deliverables and provide regular status reporting to respective stakeholders

Certifications

CSSLP/CISSP/SSCP or equivalent certification are desirable (Good to Have).

Application/API Security Threat Modelling/API Security product Implementations, Specialization or OWASP certifications or Agile Certifications are a plus

Employment Type

All positions are on fixed term contract on a full-time basis exclusively for ReBIT, initially for a period of five years, extendable by mutual consent

Location

Navi Mumbai, Bangalore

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer - SSDLC
Application Security Engineer - SSDLC

Reserve Bank Information Technology • Navi Mumbai

On-site
INR 1,400,000 - 2,400,000
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2coms • Bengaluru

On-site
INR 2,500,000 - 4,000,000
Application Security Manager
Application Security Manager

Coventine Digital • Chennai District, Bengaluru, Pune District

On-site
INR 3,000,000 - 6,000,000
SENIOR SOFTWARE ENGINEER - Application Security
SENIOR SOFTWARE ENGINEER - Application Security

Happiest Minds Technologies • Bengaluru

On-site
INR 1,700,000 - 2,100,000
Application Security Engineer
Application Security Engineer

Basebiz • Pune District

On-site
INR 1,800,000 - 3,000,000
Application Security Engineer
Application Security Engineer

Cynosure Corporate Solutions • Chennai District

On-site
INR 1,500,000 - 2,500,000
Application Security - Web/Mobile API - Assistant Manager
Application Security - Web/Mobile API - Assistant Manager

Embark • Mumbai

On-site
INR 1,200,000 - 1,800,000
Security Engineer (Application Security / Secure Coding)
Security Engineer (Application Security / Secure Coding)

Estaff Tech Private Limited • Bengaluru Urban

On-site
INR 1,400,000 - 2,200,000
Application Testing Engineer
Application Testing Engineer

Quess • Chennai District, Bengaluru, Pune District

Hybrid
INR 700,000 - 1,500,000
Application Security Engineer
Application Security Engineer

US Software Group Inc • Bengaluru

Hybrid
INR 9,033,000 - 11,744,000