Application Security Specialist

Ramboll Group

Chennai District

On-site

INR 1,800,000 - 3,200,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Flexible work from home

Job summary

Ramboll India invites applications for an Application Security Specialist to join our Information Security and Data Compliance team. You will embed security across the SDLC, collaborate with DevOps and engineering, and drive secure coding practices while aligning with ISO/IEC standards and CIS controls.

You will work with RAMTECH and global security teams to translate policies into technical controls, perform threat modeling, and report risk posture to leadership.

Qualifications

  • Hands-on experience with OWASP Top 10 risks.
  • Ability to translate security policy into technical controls.
  • Experience in Agile/DevOps environments and secure coding.
  • Knowledge of cloud security (AWS/Azure/GCP) is a plus.

Responsibilities

  • Translate security policies into actionable technical controls for development teams.
  • Embed application security controls into CI/CD pipelines.
  • Perform risk-based vulnerability assessments and prioritize remediation.
  • Lead secure coding guidance and targeted training sessions.
  • Develop reusable secure design patterns and reference architectures.

Skills

AppSec
Cyber Security
DevSecOps
Secure Coding
Vulnerability Management
Threat Modeling

Education

CSSLP
OSCP
CISSP
GWAPT

Tools

Docker
Kubernetes
IaC Security Tools

Job description

Ramboll is a global leader in sustainable architecture, engineering, and consultancy. At Ramboll Tech, we drive digital transformation across Ramboll, setting the pace for how technology transforms the built environment. Our mission is to become the leading tech-enabled partner for sustainable change.

If you are passionate about shaping high-impact digital products and want to connect product strategy with engineering execution, cloud platforms, data, integration and AI-enabled capabilities, this is your opportunity.

Ramboll globally

Ramboll is a leading engineering, architecture and consultancy company. Working at one of our offices in 35 countries you will join 16,000 fellow bright minds in creating innovative and sustainable solutions within Buildings, Transport, Energy, Environment & Health, Architecture, Landscape & Urbanism, Water and Management Consulting. Combining local experience with global knowledge, we help shape the society of tomorrow.

Do you want to push the boundaries of your profession and develop your excellence in an open, collaborative, and empowering culture? We work to create a sustainable future and our inspiring projects and innovative solutions aim to set the standard among our peers. You will join a global company that has been growing successfully since its founding in 1945. Together, we lead and leave a positive impact on societies, companies, and people around the world.

Application Security Specialist India

Are you motivated by turning complex security and compliance risks into clear, decision‑ready insights? Do you want to work at the intersection of information security, data compliance and governance in a global organisation? Are you looking to make a tangible impact on how a leading consultancy manages cyber and data‑related risks?

If this sounds like you, or you’re curious to learn more, then this role could be the perfect opportunity. Join our Information Security and Data Compliance department

Your new role

The Application Security Specialist operates at the intersection of Information Security and Assurance (ISA) and DevSecOps, ensuring that application security is embedded, measurable, and compliant across Ramboll’s global digital landscape and application development.

This role focuses on integrating security into engineering workflows while aligning with enterprise security frameworks such as ISO 12207 /ISO/IEC 27001 / CIS 18 and industry best practices like OWASP.

The Application Security specialist is responsible for identifying, analyzing, and mitigating security vulnerabilities in applications throughout the software development lifecycle (SDLC). This role works closely with development, DevOps, and security teams to ensure secure coding practices and compliance with organizational and industry standards. You will work closely with RAMTECH, data compliance, regulatory and business teams.

Your key responsibilities will be:

Alignment & Assurance
  • Translate security policies into actionable technical controls for development teams
  • Ensure alignment with:
    • ISO/IEC 27001
    • CIS Critical Security Controls
    • OWASP Top 10
  • Support internal/external audits by providing application security evidence and metrics
  • Contribute to risk registers, control effectiveness reviews, and exception handling
DevSecOps Enablement
  • Embed application security controls into CI/CD pipelines across business units
  • Drive adoption of security-by-design and shift-left security practices
  • Integrate and manage tools for:
    • SAST
    • DAST
    • SCA
    • Secrets Scanning
  • Partner with DevOps teams to standardize secure pipelines globally

Confidential.

  • Perform risk-based vulnerability assessments and prioritize remediation
  • Align risk ratings aligned with Cyber and Information security risk methodology
  • Track remediation SLAs and report on risk posture to CISO office.
  • Conduct threat modeling for critical applications and digital solutions
Security Testing & Validation
  • Oversee and/or perform:
    • Secure code reviews
    • Penetration testing (manual & automated)
  • Validate vulnerability fixes and ensure closure meets compliance requirements
  • Establish baseline security requirements for all applications
Developer Security Advisory
  • Act as a security champion enabler across distributed engineering teams
  • Provide secure coding guidance and conduct targeted training sessions
  • Develop reusable secure design patterns and reference architectures.
  • Define and track KPIs such as:
    • Vulnerability density
    • Mean Time to Remediate (MTTR)
    • % of applications onboarded to DevSecOps pipelines
  • Build dashboards for leadership visibility and regulatory reporting
  • Drive continuous improvement initiatives across global teams
Security Knowledge
  • Hands-on experience with OWASP Top 10 risks
  • Understanding of threat modeling methodologies
  • Experience in bridging policy-to-technical implementation gaps
  • Knowledge of cloud security (AWS, Azure, GCP) is a plus
About you
  • 5+ years in Application Security, Cyber Security, or Software Development
  • Experience working in Agile/DevOps environments
  • Prior experience in secure coding or vulnerability management preferred
Certifications (Preferred)
  • Certified Secure Software Lifecycle Professional (CSSLP)
  • Offensive Security Certified Professional (OSCP)
  • Certified Information Systems Security Professional (CISSP)
  • GIAC Web Application Penetration Tester (GWAPT)
Nice to Have
  • Experience with bug bounty programs
  • Knowledge of container security (Docker, Kubernetes)
  • Experience with Infrastructure as Code (IaC) security tools
What we can offer you
  • Flexible work environment with the possibility of working from home.
  • Commitment to your professional and personal development.
  • Leaders guided by Ramboll’s Leadership Principles.
  • A culture that welcomes you as the unique person you are.
  • The long‑term thinking of a foundation‑owned company.

We invite diversity in all its forms and encourage applicants from all groups to apply.

Buildings, Transport, Energy, Environment & Health, Water and Management Consulting

I’m an early career talent

Early career talents are individuals who are currently studying at university, have recently graduated or who have a couple of years of PG work experience.

I’m an experienced professional

Experienced professionals are those who have anywhere from a few years to many decades of workexperience.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Specialist
Application Security Specialist

Ramboll • Chennai District

Hybrid
INR 1,200,000 - 1,800,000
Flexible work environment
Professional development
Lead Automation – Power Systems - Energy - Chennai
Lead Automation – Power Systems - Energy - Chennai

Ramboll Group A/S • Chennai District

On-site
INR 3,000,000 - 4,200,000
Senior Project Accounting Analyst'
Senior Project Accounting Analyst'

Ramboll • Gurugram District

On-site
INR 800,000 - 1,200,000
Investment in development
Leadership support
Inclusive work environment
Consultant – Environmental Impact Assessment (EIA)
Consultant – Environmental Impact Assessment (EIA)

Ramboll Group A/S • Bengaluru

On-site
INR 900,000 - 1,300,000
Senior Project Accounting Analyst - PMO
Senior Project Accounting Analyst - PMO

Ramboll Group • Gurugram District

On-site
INR 900,000 - 1,800,000
Development investment
Leadership guidance
Value individuality
+2
Principal Engineer, Geotech, REC
Principal Engineer, Geotech, REC

Ramboll Group A/S • India

On-site
INR 4,000,000 - 7,000,000
Senior HR Coordinator - German language expert
Senior HR Coordinator - German language expert

Ramboll Group A/S • India

Hybrid
INR 900,000 - 1,500,000
Hybrid work culture
Learning and development (LinkedIn)
Mental health support
+1
Global Workplace Project Manager
Global Workplace Project Manager

Ramboll • Gurugram District

Hybrid
INR 1,400,000 - 2,200,000
Competitive salary
Flexible benefits
Development opportunities
+5
Senior Designer - BIM, Civil Structures, REC
Senior Designer - BIM, Civil Structures, REC

Ramboll • Gurugram District

On-site
INR 1,500,000 - 2,800,000
Senior Engineer Pavement Desing - Aviation
Senior Engineer Pavement Desing - Aviation

Ramboll Group A/S • Gurgaon

On-site
INR 1,800,000 - 3,200,000