Lead SAST

Daimler Trucks Innovation Center

Bengaluru

On-site

INR 3,000,000 - 6,000,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Daimler Trucks Innovation Center in Bengaluru is seeking an experienced Application Security Engineer to lead secure software development practices, define Secure SDLC, and drive security across CI/CD pipelines.

You will manage SAST/SCA platforms like Snyk Code and Black Duck, design scalable tooling, and mentor teams on vulnerability remediation, enabling secure cloud-native architectures.

Qualifications

  • 8+ years of Application Security, DevSecOps, or secure software engineering experience.
  • Hands-on experience with Snyk, Black Duck, and enterprise SAST/SCA platforms.
  • Proven ability to integrate security tools into CI/CD pipelines and design scalable tooling.

Responsibilities

  • Lead implementation and enhancement of enterprise Application Security programs.
  • Design secure-by-default architecture for Application Security tooling.
  • Define and maintain Secure SDLC practices across development teams.
  • Establish security governance and standards for assessments.
  • Drive security improvements across modern software development environments.

Skills

Snyk
Black Duck
SAST
SCA
CI/CD
DevSecOps
Threat modeling

Education

Bachelors/Masters in CS/InfoSec

Tools

Snyk
Black Duck

Job description

Application Security Engineering
  • Lead the implementation and enhancement of enterprise Application Security programs.
  • Design secure-by-default architecture for Application Security tooling.
  • Define and maintain Secure SDLC practices across development teams.
  • Establish security governance and technical standards for application security assessments.
  • Drive security improvements across modern software development environments.
SAST & SCA/FOSS Program Management
  • Own and manage enterprise Static Application Security Testing (SAST) platforms including Snyk Code.
  • Manage Software Composition Analysis (SCA) and Open Source Software (FOSS) security using Black Duck and similar platforms.
  • Define, review, and continuously improve SAST scanning policies, quality gates, and security baselines.
  • Review scan results, validate vulnerabilities, and perform false positive analysis.
  • Support onboarding of new repositories and applications into security scanning platforms.
  • Drive continuous improvements and product enhancements for SAST/SCA solutions.
DevSecOps & CI/CD Security
  • Integrate cybersecurity tooling into CI/CD pipelines (GitHub, GitLab, Azure DevOps, Jenkins).
  • Design automated security scanning workflows across development pipelines.
  • Build scalable DevSecOps security controls using automation.
  • Collaborate with Platform Engineering teams to embed security into development workflows.
  • Improve developer experience while maintaining security compliance.
Security Tool Integration & Automation
  • Design and implement integrations between cybersecurity platforms and enterprise tools.
  • Develop automation scripts and APIs to improve security operations.
  • Integrate Application Security tools with: Source Code Management
  • Build Pipelines
  • Issue Tracking
  • Reporting Dashboards
  • Vulnerability Management Platforms
  • Drive end-to-end security automation initiatives.
Security Architecture
  • Design scalable architecture for Application Security tooling ecosystem.
  • Evaluate new security technologies and recommend enterprise adoption.
  • Define architecture patterns for secure development.
  • Participate in application architecture reviews from a security perspective.
  • Support cloud-native and container security initiatives.
Application Security Testing
  • Lead and perform technical security assessments including:
  • Web Application Security Testing
  • REST API Security Testing
  • Thick Client Security Testing
  • Secure Code Review
  • Authentication & Authorization Testing
  • Business Logic Testing
  • OWASP Top 10 Validation
  • API Abuse Testing
Developer Enablement
  • Conduct developer security awareness sessions.
  • Train Security Champions across development organizations.
  • Create Secure Development Learning Paths.
  • Develop secure coding guidelines and technical documentation.
  • Mentor engineering teams on vulnerability remediation.
  • Promote secure coding culture across global teams.
Stakeholder Management
  • Work closely with: Software Development Teams
  • DevOps Teams
  • Enterprise Architects
  • Product Owners
  • Cybersecurity Teams
  • Global Business Units
  • Drive adoption of cybersecurity tooling and security best practices.
  • Present technical recommendations to senior leadership.
Qualifications
  • Bachelor's or Master's degree in Computer Science, Information Security, Engineering, or related field.
  • 8+ years of experience in Application Security, DevSecOps, or Secure Software Engineering.
  • Strong hands‑on experience with Snyk, Black Duck, and enterprise SAST/SCA platforms.
  • Proven experience integrating security tools into enterprise CI/CD pipelines.
  • Experience designing scalable security tooling architecture.
  • Hands‑on experience performing Web, API, and Thick Client security assessments.
  • Experience reviewing and validating vulnerabilities, including false positive analysis.
  • Strong understanding of modern software development practices.
  • Excellent stakeholder communication and technical leadership skills.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Security Engineer
Lead Security Engineer

Rwindia • Bengaluru

On-site
INR 3,500,000 - 6,000,000
DevSecOps (Security test lead) Engineer
DevSecOps (Security test lead) Engineer

D-techworks • Mumbai, Bengaluru

On-site
INR 2,500,000 - 4,000,000
Application Security Engineer
Application Security Engineer

Basebiz • Bengaluru

On-site
INR 1,800,000 - 2,800,000
Application Security Engineer
Application Security Engineer

Basebiz • Chennai District

On-site
INR 1,200,000 - 1,800,000
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2coms • Bengaluru

On-site
INR 2,500,000 - 4,000,000
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
Application Security Lead | Offshore
Application Security Lead | Offshore

Photon • Hyderabad

On-site
INR 850,000 - 1,800,000
Application Security Testing Engineer
Application Security Testing Engineer

Infosys • Bengaluru

On-site
INR 900,000 - 1,200,000
Application Testing Engineer
Application Testing Engineer

Quess • Chennai District, Bengaluru, Pune District

Hybrid
INR 700,000 - 1,500,000
Application Security Engineer
Application Security Engineer

Basebiz • Pune District

On-site
INR 1,800,000 - 3,000,000