Lead Engineer - Cyber Security

Mphasis

Bengaluru

On-site

INR 3,500,000 - 7,000,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Mphasis is seeking a Senior Application Security Engineer plus Vulnerability Operations in India to drive large-scale AppSec controls across CI/CD pipelines and engineering teams. You will lead vulnerability governance, model threats, orchestrate remediation, and mentor AppSec specialists while partnering with champions to embed secure development practices.

Position located in India with emphasis on secure design, development, and deployment across the enterprise, enabling secure software

Qualifications

  • 7+ years of experience in Application Security engineering or secure development.
  • Experience leading CI/CD integrated security automation (SAST, DAST, SCA, secrets scanning).
  • Ability to interpret complex vulnerability trends, emerging threats, and remediation strategies.
  • Excellent communication and executive presentation skills to influence senior technical leaders.

Responsibilities

  • Lead enterprise-wide operationalization of AppSec controls across CI/CD pipelines.
  • Act as SME for advanced vulnerability classes and guide remediation efforts.
  • Architect scalable CI/CD security integrations (SAST, DAST, SCA, secrets scanning).
  • Design KPIs, scorecards and dashboards for risk reporting to executives.
  • Mentor AppSec Specialists and promote secure development practices.

Education

Bachelor's/Master's in CS/Cybersecurity

Tools

SAST tools
DAST tools
SCA tools
Secrets scanning tooling
IaC scanning

Job description

Senior Application Security Engineer plus Vulnerability Operations

Location: India

Role Summary

The Senior Application Security Engineer serves as a technical and operational leader within the Vulnerability Operations function. This role drives large scale adoption of application security controls, partnering closely with engineering teams and the Application Security Champion community to ensure secure design, development, and deployment across the enterprise. You will lead strategic control rollouts, guide vulnerability governance, address emerging threat classes, and provide expert escalation support for the most complex AppSec issues.

Key Responsibilities
  • Strategic Leadership and Program Enablement: Lead the enterprise wide operationalization of AppSec controls, ensuring scalable integration across CI/CD pipelines and diverse engineering environments. Partner with the Application Security Champion team to embed secure development practices, coordinate training, share emerging vulnerability insights, and drive decentralized security ownership. Own the tiered security control strategy (Tier 1 to 3), defining quarterly migration targets and ensuring cross portfolio alignment.

  • Advanced Vulnerability and Threat Management: Act as subject matter expert for advanced and emerging vulnerability classes (for example supply chain risks, AI and ML application threats, container and serverless misconfigurations, emerging OWASP categories). Lead complex vulnerability triage and remediation efforts; facilitate cross team deep dive sessions to drive prioritization and timely mitigation. Conduct proactive threat modeling and security design reviews for high risk or business critical applications.

  • Automation and CI/CD Security Architecture: Architect scalable CI/CD integrations for SAST, DAST, SCA, and secrets scanning using policy as code, automated gating, and risk based controls. Implement and optimize Tier 3 merge prevention and build failure gates, ensuring engineering teams meet strict compliance requirements. Develop reusable automation frameworks, scanning templates, and pipeline modules to accelerate secure software delivery.

  • Governance, Reporting and Stakeholder Engagement: Design and maintain KPIs, scorecards, and compliance dashboards using analytics platforms (Power BI, Grafana, or equivalent). Lead risk review forums, document mitigations, publish weekly risk register updates, and deliver executive level insights on trends, gaps, and emerging threats. Oversee quarterly migration planning, dependency tracking, and cross team alignment on AppSec program objectives. Mentor AppSec Specialists and upskill partner engineering teams on tools, governance workflows, and emerging security techniques.

  • Emerging Vulnerabilities and Continuous Improvement: Stay current with modern vulnerability trends (for example supply chain risks, API threats, cloud native issues). Evaluate tool outputs, identify false positives, and provide actionable remediation guidance. Recommend improvements to scanning processes, workflows, and onboarding procedures.

Required Qualifications And Skills
  • Bachelors or Masters in Computer Science, Cybersecurity, or related field.
  • 7 plus years of experience in Application Security engineering, vulnerability management, or secure development.
  • Expertise in advanced AppSec concepts: secure design patterns, threat modeling, exploit analysis, and remediation strategy for modern architectures (microservices, APIs, cloud native).
  • Proven experience leading CI/CD integrated security automation (SAST, DAST, SCA, secrets scanning, infrastructure as code scanning).
  • Strong track record of working with engineering organizations and AppSec Champions to drive program adoption.
  • Demonstrated ability to interpret complex vulnerability trends, emerging threats, and zero day risk scenarios.
  • Excellent communication and executive presentation skills, with ability to influence senior technical leaders.
Preferred Qualifications
  • Hands on experience with cloud native security tooling across AWS, Azure, or GCP.
  • Certifications: CISSP, CSSLP, OSWE, OSCP, GWAPT, or equivalent industry credentials.
  • Familiarity with policy and governance tools (OPA and Gatekeeper), software supply chain frameworks (SLSA, SBOM), and infrastructure as code security.
  • Experience designing or contributing to AppSec Champion programs or federated security enablement models.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

Byline Learning Solutions • Pune District

On-site
INR 1,200,000 - 1,800,000
Lead Engineer - Security Consultant
Lead Engineer - Security Consultant

Esyasoft Holding Ltd • Kolkata Metropolitan Area

On-site
INR 4,000,000 - 7,000,000
SENIOR SOFTWARE ENGINEER - Application Security
SENIOR SOFTWARE ENGINEER - Application Security

Happiest Minds Technologies • Bengaluru

On-site
INR 1,700,000 - 2,100,000
Application Security Engineer
Application Security Engineer

Basebiz • Pune District

On-site
INR 1,800,000 - 3,000,000
Application Security
Application Security

Airtel • India

On-site
INR 1,200,000 - 2,400,000
Security-focused culture
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
Senior Application Security Engineer
Senior Application Security Engineer

Hyland • Hyderabad

Hybrid
INR 2,500,000 - 4,200,000
Application Security Engineer
Application Security Engineer

DigiCert • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Generous time off policies
Top shelf benefits
Education, wellness, and lifestyle support
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2coms • Bengaluru

On-site
INR 2,500,000 - 4,000,000
Application Security Architect
Application Security Architect

Mettler-Toledo, Inc. • Bengaluru

Hybrid
INR 2,000,000 - 3,000,000
Hybrid working model
Family mediclaim benefits
Wide portfolio of training opportunities
+1