Consultant - Application Security Job

YASH Technologies

Bengaluru

On-site

INR 1,800,000 - 3,200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

YASH Technologies seeks a security-focused software professional to manage defects and guide remediation across cloud-based apps and APIs. You will work with developers, architects, and product owners to communicate risks and prioritize fixes.

Responsibilities include enabling tools like CodeQL and Rapid7, onboarding security testing, and advising teams on reducing risk through mature security practices. This role emphasizes collaboration across geographies and disciplines.

Qualifications

  • Experience analyzing security findings from automated and manual sources.
  • Familiarity with OWASP Top 10 and ASVS.
  • Experience building web apps and APIs (SPA/REST).

Responsibilities

  • Analyze, validate, and communicate security defects from multiple sources.
  • Provide guidance to engineers to remediate vulnerabilities.
  • Enable and monitor automated defect detection tooling at repo or app level.
  • Coordinate security onboarding and management for tests and assessments.
  • Advise on practices to improve security maturity.

Skills

Software engineering
Cybersecurity
Cloud platforms
Communication

Tools

CodeQL
Rapid7
SAST
DAST
SCA

Job description

Responsibilities
  • Security Defect Management – Analyzing, validating, communicating, and consulting on security defects identified by both automated and manual sources such as CodeQL, Rapid7 Web Application Security, penetration testing, bug bounty, etc. Our security engineers partner with software engineers to explain why a vulnerability exists and what to do about it.
  • Engineering Consulting – Acting as a “best friend” to software engineers, architects, product owners, and leaders, providing context‑aware guidance to help these groups make good decisions when implementing new features and remediating existing issues.
  • Tool Enablement – Enabling and monitoring automated defect detection tooling (CodeQL, Rapid7, etc.) at the repository or application level according to established processes.
  • Security Test Onboarding & Management – Collecting and communicating required scope and access information for penetration testing and security assurance assessments, and handling the outputs of these assessments via our Defect Management Process.
  • Maturity Measurement – Consulting with software engineers on practices that improve their applications’ security maturity according to scorecards and maturity models established by Cat Digital.
  • Correction of Error – Authoring, in close partnership with software engineers, corrections of error reports that help engineers and architects across Cat Digital avoid similar mistakes in their own applications.
Basic Qualifications
  • 5+ years of experience as a software engineer (any language or framework) or software engineering manager, OR
  • 5+ years of experience as a software development‑focused cybersecurity professional, OR
  • 5+ years of experience working on a major cloud platform (AWS, Azure, GCP, or Salesforce) as a software engineer, cloud/DevOps engineer, security engineer, or architect.
Additional Qualifications
  • Experience analyzing and remediating security findings from automated and manual sources such as Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), penetration testing, Software Composition Analysis (SCA), etc.
  • Experience leveraging one or more of the following resources to support secure coding and decision‑making:
    • OWASP Top 10
    • MITRE Common Weakness Enumeration (CWE) Top 25
    • OWASP Application Security Verification Standard (ASVS)
    • Other industry‑standard best‑practice guides or frameworks
  • Experience building or supporting web applications and APIs including Single Page Applications (SPA) and RESTful APIs.
  • Proficiency in one or more programming languages.
Candidate Attributes
  • Decision‑Making Ability – Making sound, customer‑first decisions about which security issues to raise to software engineers/leaders and supporting work prioritization.
  • Strong Communication – Relating complex technical concepts to both technical and non‑technical audiences, and collaborating effectively with colleagues from diverse locations and cultures.
  • Active Participation – Contributing to the team and completing complex assignments at a high level of quality with limited supervision.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Consultant - Application Security Job
Consultant - Application Security Job

YASH Technologies, Inc. • Bengaluru

On-site
INR 1,800,000 - 3,200,000
Application Security Engineer
Application Security Engineer

DigiCert • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Generous time off policies
Top shelf benefits
Education, wellness, and lifestyle support
Application Security Lead | Offshore
Application Security Lead | Offshore

Photon • Hyderabad

On-site
INR 850,000 - 1,800,000
Application Security Engineer
Application Security Engineer

Basebiz • Chennai District

On-site
INR 1,200,000 - 1,800,000
Application Security Engineer
Application Security Engineer

Basebiz • Bengaluru

On-site
INR 1,800,000 - 2,800,000
Application Security
Application Security

Airtel • India

On-site
INR 1,200,000 - 2,400,000
Security-focused culture
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
Appsec Specialist - Lead
Appsec Specialist - Lead

Adani Enterprises Limited • Ahmedabad District

On-site
INR 2,600,000 - 3,800,000
Application Security Engineer
Application Security Engineer

Whitefield Careers • Bengaluru

On-site
INR 800,000 - 1,200,000
Application Security Engineer
Application Security Engineer

Ola • Bengaluru

On-site
INR 1,200,000 - 2,000,000