Application Security with DevSecOps

Kyndryl

Dadri

Hybrid

INR 4,000,000 - 6,000,000

Full time

8 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Be Well programme
Hybrid-friendly culture

Job summary

Kyndryl in India is seeking a seasoned Application Security SME with 8+ years of experience across SAST, DAST, SCA, container security, and DevSecOps integration to lead manual testing, threat modelling, and secure design reviews for mission-critical apps.

You will mentor junior analysts, drive vulnerability triage and remediation, ensure SLA compliance, and collaborate with Dev, Sec and product teams to embed AppSec controls in CI/CD pipelines.

Qualifications

  • 8+ years in Application Security spanning SAST, DAST, manual testing, and secure SDLC.
  • Threat modelling, risk assessments, and secure design reviews.
  • Strong knowledge of OWASP Top 10, API Security Top 10, SANS Top 25, CWE and emerging threats.

Responsibilities

  • Lead threat modelling workshops for critical applications and services.
  • Perform manual security testing to assess business logic and advanced attack scenarios.
  • Validate and triage high-risk findings across SAST/DAST.
  • Guide remediation planning and secure design alternatives with stakeholders.
  • Embed AppSec controls in CI/CD pipelines and mentor L1/L2 analysts.

Skills

Threat modelling
Manual testing
SAST/DAST
DevSecOps
Container security
Cloud security
Mentoring
Security governance

Education

Bachelor's degree in Computer Science/IT or related field

Tools

Fortify
Checkmarx
SonarQube
Veracode
Burp Suite Pro
OWASP ZAP
Microsoft Threat Modeling Tool

Job description

Who We Are

At Kyndryl, we run and reimagine the mission‑critical technology systems that drive advantage for the world’s leading businesses. We are at the heart of progress; with proven expertise and a continuous flow of AI‑powered insight, enabling smarter decisions, faster innovation, and a lasting competitive edge. For our people—Kyndryls—that means doing purposeful work that powers human progress. Join us and experience a flexible, supportive environment where your well‑being is prioritised and your potential can thrive.

The Role

We are seeking a seasoned Application Security Subject Matter Expert (SME) with 8+ years of experience across multiple facets of application security including SAST, DAST, SCA, Container security, DevSecOps integration, and threat modelling. The SME will provide leadership in manual security testing, vulnerability validation, secure design reviews, and mentoring, while ensuring testing quality, SLA adherence, and alignment with business risk priorities.

Roles & Responsibilities
  • Threat Modelling & Advanced Testing Lead threat modelling workshops for critical applications and services.
  • Perform manual security testing to assess business logic, abuse cases, and advanced attack scenarios.
  • Validate and exploit high‑risk findings from DAST tools such as Fortify WebInspect to confirm impact and reduce false positives.
  • Strong understanding of security integration for application and infra level security assessments in DevSecops pipeline.
  • Understanding of Containers, Microservices based applications security considerations.
  • Container security assessment knowledge.
  • Knowledge of cloud security aspects is also preferred.
  • Vulnerability Triage & Remediation Provide second‑level triage of critical and high‑severity vulnerabilities identified across SAST and DAST.
  • Conduct in‑depth discussions with application stakeholders to review critical findings, false positives, and exception requests.
  • Guide application teams in remediation planning, secure design alternatives, and architecture‑level mitigations.
  • DAST & SAST Governance Conduct DAST tool coverage reviews and evaluate feature utilisation to maximise effectiveness.
  • Ensure SAST and DAST testing, reporting, and remediation SLAs are consistently met.
  • Track security metrics (coverage, SLA compliance, MTTR) and present insights to AppSec leadership.
  • Collaboration & Mentorship Collaborate with development, DevOps, and product teams to embed AppSec controls in CI/CD pipelines.
  • Mentor and guide junior analysts (L1/L2) in vulnerability triage, secure coding, and manual testing techniques.
  • Contribute to security automation opportunities, improving efficiency of AppSec processes and tooling.
  • Stakeholder Engagement Act as a trusted adviser and escalation point for application security issues.
  • Lead second‑level report discussions with business and technical stakeholders for critical vulnerabilities.
  • Support secure design and architecture discussions for new initiatives and high‑risk projects.
Tools & Technologies
  • SAST: Fortify SCA, Checkmarx, SonarQube, Veracode
  • DAST: Fortify WebInspect, Burp Suite Pro, OWASP ZAP, AppScan, Netsparker
  • Threat Modeling: Microsoft Threat Modeling Tool, OWASP Threat Dragon, custom frameworks
  • DevSecOps: Jenkins, GitLab CI, GitHub Actions, Azure DevOps integration for security scanning
  • Container security: assessments using Palo Alto Prisma Cloud, Trivy, Wiz etc
  • Supporting Tools: Postman, Charles Proxy, MobSF (mobile), Splunk/Power BI for reporting
Required Professional Experience
  • 8+ years of experience in Application Security spanning SAST, DAST, manual testing, and secure SDLC.
  • Proven experience in threat modelling, risk assessments, and secure design reviews.
  • Strong knowledge of OWASP Top 10, API Security Top 10, SANS Top 25, CWE, and emerging threat vectors.
  • Hands‑on expertise in integrating security tools within DevSecOps pipelines.
  • Excellent stakeholder communication and leadership skills.
Preferred Professional Experience
  • OSWE / OSCP / OSEP (advanced exploit and web testing)
  • CISSP / CSSLP (for security leadership & secure SDLC expertise)
  • GWAPT / GWEB (web application security)
  • Cloud security certs (CCSP, AWS Security Specialty, Azure SC-100) – must have one cloud security certification
Education

Bachelor's degree in Computer Science, Information Technology, or related field.

Who You Are

You’re good at what you do and possess the required experience to prove it. However, equally as important – you have a growth mindset; keen to drive your own personal and professional development. You are customer‑focused – someone who prioritises customer success in their work. And finally, you’re open and borderless – naturally inclusive in how you work with others.

Being You

The “Kyn” in Kyndryl means kinship, which represents the strong bonds we have with each other, our customers and our communities. We focus on ensuring all Kyndryls feel included and we welcome people of all cultures, backgrounds, and experiences. Even if you don’t meet every requirement, we encourage you to apply. We believe in growth, and we’re excited to see what you can bring. At Kyndryl, employee feedback has told us that our number one driver of employee engagement is belonging. That sense of belonging — being a valued, respected, trusted member of the team — is fundamental to our culture and fueling great experiences for our customers. This dedication to welcoming everyone into our company means that Kyndryl gives you the ability to thrive and contribute to our culture of empathy and shared success. That’s The Kyndryl Way.

What You Can Expect

Your career with us isn’t just a job—it’s an adventure with purpose. We offer a dynamic, hybrid‑friendly culture that supports your well‑being and empowers you to grow. Our Be Well programmes are thoughtfully designed to support your financial, mental, physical, and social health—because we know that when you feel your best, you do your best. From your very first day, you’ll dive into impactful work that powers the systems our customers rely on every day. You won’t just contribute—you’ll make a difference, tackling meaningful projects that sharpen your skills and fuel your growth. We’re here to champion your journey. With powerful tools to chart your career path, personalised development goals aligned with your ambitions, and continuous feedback to keep you inspired and on track, you’ll have everything you need to thrive and evolve. You’ll develop in‑demand skills to grow your career and achieve your ambitions with access to cutting‑edge learning opportunities—from certifications with Microsoft, Google, and Amazon to coaching and hands‑on experiences. And through it all, you’ll be part of a culture that values empathy, restless learning, and a devotion to shared success. We want you to thrive here—and we’re committed to helping you do just that.

Ready to Make an Impact?

Join us and help shape what’s next. At Kyndryl, we achieve progress the world depends on, with purpose. Beginning with the purpose that matters to you. Because here, you will be part of a culture designed with purpose. One that is restless, empathetic and devoted. Where we are committed to sustainable progress for our customers and supporting the communities where we work and live. All of you is what we want. And what we need. Join us, and together, we can advance the vital systems that power human progress.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Engineer - Network Security Consulting
Engineer - Network Security Consulting

Kyndryl Inc. • Mumbai

Hybrid
INR 1,400,000 - 2,600,000
Be Well program
Learning & development opportunities
EDR SME
EDR SME

Kyndryl Inc. • India

Hybrid
INR 1,800,000 - 3,000,000
Be Well program
Hybrid-friendly culture
ApplSec DevSecOps L3
ApplSec DevSecOps L3

Kyndryl Inc. • India

On-site
INR 1,400,000 - 1,900,000
Security Operations & SIEM Lead (SOC)
Security Operations & SIEM Lead (SOC)

Kyndryl Inc. • India

Hybrid
INR 1,500,000 - 2,800,000
SOC Lead
SOC Lead

Kyndryl Inc. • India

Hybrid
INR 1,400,000 - 2,800,000
Cybersecurity- CTI SME (Cyber Threat Intelligence)
Cybersecurity- CTI SME (Cyber Threat Intelligence)

Kyndryl Inc. • India

Hybrid
INR 2,500,000 - 4,000,000
SOC Senior Analyst
SOC Senior Analyst

Kyndryl Inc. • India

Hybrid
INR 1,400,000 - 2,400,000
Security Operations & SIEM Lead (SOC)
Security Operations & SIEM Lead (SOC)

Kyndryl • Dadri

On-site
INR 1,200,000 - 1,800,000
Be Well program
Hybrid-friendly culture
SOC Senior Analyst
SOC Senior Analyst

5100 Kyndryl Solutions Private Limited • Dadri

Hybrid
INR 1,500,000 - 2,200,000
Lead - Network Security
Lead - Network Security

Kyndryl Inc. • Mumbai

Hybrid
INR 1,800,000 - 3,200,000
Be Well program