Application Security Lead | Offshore

Visa Hunt

India

On-site

INR 1,200,000 - 1,800,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Visa Hunt is seeking an experienced Application Security Engineer to join our security program. You will drive secure development practices across cloud and containerized environments and collaborate with cross-functional teams to embed security into the product lifecycle.

The ideal candidate has 3+ years of hands-on security experience, strong knowledge of CI/CD pipelines, OWASP Top 10, and hands-on with SAST/DAST/SCA tools. Experience with AWS/Azure and Docker/Kubernetes is preferred.

Qualifications

  • 3+ years of hands-on application security experience.
  • Experience securing cloud-based and containerized environments.
  • Experience performing secure code reviews and interpreting SAST/DAST/SCA results.
  • Strong knowledge of CI/CD workflows (Azure Pipelines, GitHub Actions).
  • Familiarity with OWASP Top 10 for web apps and APIs.
  • Hands-on with security tools like Snyk, Veracode, Burp Suite.
  • Knowledge of AWS and Azure; Docker and Kubernetes.
  • Programming in Python, Java, or C# preferred.
  • Ability to translate security concepts into actionable guidance.

Responsibilities

  • Shift left security to embed secure SDLC practices.
  • Conduct secure design reviews and threat modeling to identify risks, attack surfaces, and vulnerabilities.
  • Deploy and operationalize SAST, DAST, SCA and secrets scanning.
  • Collaborate with Platform DevOps to embed inline security checks into CI/CD pipelines.
  • Partner with Platform DevOps to design secure-by-default architectures and workflows.
  • Assist with application security code reviews and advise on remediations.
  • Establish and track SLA governance to identify, prioritize, and remediate findings.
  • Maintain application asset inventory.
  • Lead the Security Champions Program to build security-minded culture among developers and IT Ops teams.
  • Act as a trusted advisor for development and cross-functional teams.
  • Help with training on secure coding practices.
  • Evaluate and implement security tools and automation solutions to enhance security posture.

Skills

Application security
CI/CD pipelines
OWASP Top 10
SAST tools
DAST/SCA
Cloud platforms
Containerization
Docker/Kubernetes
Python/Java/C#

Education

Bachelor's in CS/InfoSec

Tools

Snyk
Veracode
Burp Suite

Job description

Responsibilities
  • Shift left” security efforts to build security into the software development lifecycle:
  • Conduct secure design reviews and threat modeling to identify and prioritize risks, attack surfaces, and vulnerabilities
  • Deploy and operationalize static (SAST), dynamic (DAST), dependency (SCA) and secrets scanning
  • Work with Platform DevOps team to build and maintain security automation tools to seamlessly embed inline security checks into CI/CD pipelines
  • Partner with Platform DevOps to help design secure‑by‑default architectures and workflows
  • Assist with application security code reviews of source code changes and advise developers on remediating vulnerabilities following secure coding practices
  • Establish and track SLA governance to ensure security findings are identified, prioritized, and remediated.
  • Maintain application asset inventory.
  • Lead the Security Champions Program to build security‑minded culture amongst developers and IT Operations teams.
  • Act as a trusted advisor and partner for development and cross‑functional project teams, providing actionable guidance to address security.
  • Help with training on secure coding practices, empowering teams to proactively prevent vulnerabilities.
  • Evaluate and implement security tools and automation solutions to enhance the security posture of applications and streamline security processes.
PROFILE
  • Bachelor's degree in Computer Science, Information Security, or related professional experience.
  • Have 3+ years of hands‑on experience in application security, including securing cloud‑based and containerized environments.
  • Experience performing secure code reviews and interpreting SAST/SCA/DAST results.
  • Strong experience with modern development workflows, including CI/CD pipelines, using Azure Pipelines and GitHub Actions.
  • Working knowledge of the OWASP Top 10 for web applications and APIs and how to apply the standard to minimize security risk.
  • In‑depth understanding of vulnerabilities and secure coding practices.
  • Hands‑on experience with security tools like Snyk, Veracode, Burpsuite or similar.
  • Familiarity with cloud platforms (AWS, Azure) and containerization (Docker, Kubernetes).
  • Proficiency in programming languages like Python, Java, or C# is preferred.
  • Have empathy, collaboration skills, and a learning mindset to work cross‑functionally with engineers of all levels to build security into the product life cycle.
  • Possess broad security knowledge to connect the dots across domains and identify holistic ways to lower the overall threat surface.
  • Have the ability to distill complex security concepts into clear actions and drive consensus with minimum supervision.
  • Demonstrated success in partnering with developers to integrate security.

Originally posted on Himalayas

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2coms • Bengaluru

On-site
INR 2,500,000 - 4,000,000
Application Security
Application Security

Airtel • India

On-site
INR 1,200,000 - 2,400,000
Security-focused culture
Application security
Application security

Codincity Digital Technologies • Chennai District

On-site
INR 3,500,000 - 5,500,000
Lead Engineer - Cyber Security
Lead Engineer - Cyber Security

Mphasis • Bengaluru

On-site
INR 3,500,000 - 7,000,000
Lead- Product Security
Lead- Product Security

42 Gears Mobility Systems • Bengaluru

On-site
INR 4,000,000 - 6,400,000
Application Security Engineer
Application Security Engineer

US Software Group Inc • Bengaluru

Hybrid
INR 9,033,000 - 11,744,000
Senior Engineer - Cyber Security
Senior Engineer - Cyber Security

Adani Group • Mumbai

On-site
INR 1,200,000 - 2,000,000
Application Security Engineer
Application Security Engineer

Ola • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2COMS Consulting Pvt. Ltd. • Bengaluru Urban

On-site
INR 1,500,000 - 2,100,000