Consultant - Application Security Job

YASH Technologies, Inc.

Bengaluru

On-site

INR 1,800,000 - 3,200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

YASH Technologies, Inc. is seeking a seasoned security-focused software engineer to partner with software teams on defect analysis and remediation while guiding secure feature implementation. The role emphasizes leveraging automated tools and collaborating with developers and leaders to elevate security maturity.

The candidate will work across architectures, APIs, and web apps, applying best practices from OWASP ASVS/Top 10 and CWE to ensure robust security postures in cloud environments.

Qualifications

  • 5+ years as a software engineer or software engineering manager.
  • 5+ years as a software development cybersecurity professional.
  • 5+ years on a major cloud platform (AWS, Azure, GCP, or Salesforce) as engineer/DevOps/security architect.

Responsibilities

  • Analyze, validate, communicate, and consult on security defects from automated/manual sources.
  • Serve as a trusted advisor to software engineers, architects, product owners on secure implementations.
  • Enable and monitor automated defect-detection tooling at repository or application level.
  • Collect and communicate required scope/access for penetration testing and security assessments.
  • Advise on practices to improve security maturity using Cat Digital scorecards/models.
  • Collaborate with engineers to correct error reports to prevent recurrence.

Skills

Security defect mgmt
Cloud platforms
Secure coding guidance
Programming languages

Tools

SAST/DAST tools

Job description

Responsibilities
  • Security Defect Management – Analyzing, validating, communicating, and consulting on security defects identified by both automated and manual sources such as CodeQL, Rapid7 Web Application Security, penetration testing, bug bounty, etc. In other words, our security engineers are partners to software engineers who require accurate information on why a vulnerability exists and what they can do about it.
  • Engineering Consulting – Serving as a “best friend” to software engineers, architects, product owners, and leaders, provide contextually‑aware guidance to help these groups make good decisions when implementing new features and remediating existing issues.
  • Tool Enablement – Enabling and monitoring automated defect detection tooling (CodeQL, Rapid7, etc.) at the repository or application level according to established process.
  • Security Test Onboarding & Management – Collecting and communicating required scope and access information for penetration testing and security assurance assessments, as well as handling the output of these assessments via our Defect Management Process.
  • Maturity Measurement – Consulting with software engineers on practices which will improve their application’s security maturity according to scorecards and maturity models established by Cat Digital.
  • Correction of Error – Authoring, in close partnership with software engineers, correction of error reports which help engineers and architects across Cat Digital avoid similar mistakes in their own applications.
Basic Qualifications

Two of three:

  • 5+ years of experience as a software engineer (in any language or framework) or software engineering manager
  • 5+ years of experience as a software development‑focused cybersecurity professional
  • 5+ years of experience working on a major cloud platform (AWS, Azure, GCP, or Salesforce) as a software engineer, cloud/DevOps engineer, security engineer, or architect.
As well as:
  • Experience analyzing and remediating security findings from automated and manual sources such as Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), penetration testing, Software Composition Analysis (SCA), etc.
  • Experience leveraging one or more of the following resources to support secure coding and decision‑making:
  • OWASP Top 10
  • MITRE Common Weakness Enumeration (CWE) Top 25
  • OWASP Application Security Verification Standard (ASVS)
  • Other industry‑standard best practice guides or frameworks
  • Experience building or supporting web applications and APIs including Single Page Applications (SPA) and RESTful APIs.
  • Proficiency in one or more programming languages.
Candidate Attributes
  • Decision‑Making Ability – Our engineers make sound, justifiable, customer‑first decisions to determine which security issues to raise to software engineers/leaders and support work prioritization decisions.
  • Strong Communication – Our engineers relate complex technical concepts to non‑technical audiences and technical audiences without a security background. Additionally, the Cat Digital team spans the globe, and our engineers must collaborate effectively with engineers from a number of locations and cultural backgrounds.
  • Active Participation – Software engineering is not a “spectator sport”. The input and experience our engineers bring to the table are valued and should be shared freely. Similarly, engineers are relied upon to complete complex assignments at a high level of quality with limited supervision.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Consultant - Application Security Job
Consultant - Application Security Job

YASH Technologies • Bengaluru

On-site
INR 1,800,000 - 3,200,000
Application Security Engineer
Application Security Engineer

DigiCert • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Generous time off policies
Top shelf benefits
Education, wellness, and lifestyle support
Application Security Engineer
Application Security Engineer

Basebiz • Chennai District

On-site
INR 1,200,000 - 1,800,000
Application Security Engineer
Application Security Engineer

Basebiz • Bengaluru

On-site
INR 1,800,000 - 2,800,000
Senior Manager - Application Security & AI Security
Senior Manager - Application Security & AI Security

Pine Labs • Dadri

On-site
INR 4,500,000 - 7,500,000
Application Security Lead | Offshore
Application Security Lead | Offshore

Photon • Hyderabad

On-site
INR 850,000 - 1,800,000
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
Application Security Engineer
Application Security Engineer

Ola • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Application Security Engineer
Application Security Engineer

Cynosure Corporate Solutions • Chennai District

On-site
INR 1,500,000 - 2,500,000
Lead SAST
Lead SAST

Daimler Trucks Innovation Center • Bengaluru

Hybrid
INR 3,000,000 - 6,000,000