Lead Security Engineer

Rwindia

Bengaluru

On-site

INR 3,500,000 - 6,000,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Rwindia in Bengaluru seeks an experienced Lead Security Engineer to strengthen and continuously improve an enterprise Application Security program. You will drive SAST and SCA/FOSS initiatives, implement DevSecOps controls, and integrate security tooling into CI/CD pipelines across global teams.

You will lead security assessments, mentor engineers, and enable developers with secure coding practices, OWASP Top 10 validation, and API security testing.

Qualifications

  • 8+ years in Application Security or DevSecOps.
  • Hands-on with Snyk and Black Duck; integrat es into CI/CD.
  • Experience securing Web Applications, REST APIs, and Thick Clients.
  • Strong leadership and stakeholder communication skills.

Responsibilities

  • Lead implementation and enhancement of enterprise Application Security programs.
  • Design secure-by-default architecture for Application Security tooling.
  • Define and maintain Secure SDLC practices and governance standards.
  • Own and manage enterprise SAST platforms, including Snyk Code.
  • Manage SCA/FOSS security platforms such as Black Duck.
  • Define and continuously improve SAST scanning policies and baselines.
  • Review scan results, validate vulnerabilities, and perform false-positive analysis.
  • Integrate cybersecurity tools into CI/CD pipelines.

Skills

Application Security
DevSecOps
Secure SDLC
CI/CD
Vulnerability analysis
Leadership
Stakeholder communication
Web security
Cloud security

Education

Bachelor’s/Master’s degree

Tools

Snyk
Black Duck
SAST platforms

Job description

Job Summary

The Lead Security Engineer – Application Security & DevSecOps is responsible for strengthening and continuously improving an enterprise Application Security program. The role focuses on integrating cybersecurity throughout the Software Development Lifecycle (SDLC), leading SAST and SCA/FOSS programs, implementing DevSecOps security controls, integrating security tooling into CI/CD pipelines, performing application security assessments, and driving developer security enablement across global development teams.

Key Responsibilities
  • Lead the implementation and enhancement of enterprise Application Security programs.
  • Design secure-by-default architecture for Application Security tooling.
  • Define and maintain Secure SDLC practices and application security governance standards.
  • Own and manage enterprise SAST platforms, including Snyk Code.
  • Manage SCA/FOSS security platforms such as Black Duck.
  • Define and continuously improve SAST scanning policies, quality gates, and security baselines.
  • Review scan results, validate vulnerabilities, and perform false-positive analysis.
  • Support onboarding of repositories and applications into security scanning platforms.
  • Integrate cybersecurity tools into CI/CD pipelines using GitHub, GitLab, Azure DevOps, and Jenkins.
  • Design automated security scanning workflows and scalable DevSecOps controls.
  • Develop integrations between cybersecurity platforms and source code management, build pipelines, issue tracking, reporting dashboards, and vulnerability management platforms.
  • Develop automation scripts and APIs to improve security operations.
  • Design scalable architecture for the Application Security tooling ecosystem.
  • Evaluate new security technologies and recommend enterprise adoption.
  • Participate in application architecture reviews from a security perspective.
  • Support cloud-native and container security initiatives.
  • Lead Web Application, REST API, and Thick Client security assessments.
  • Perform secure code review, authentication and authorization testing, business logic testing, OWASP Top 10 validation, and API abuse testing.
  • Conduct developer security awareness sessions and train Security Champions.
  • Create secure development learning paths, coding guidelines, and technical documentation.
  • Mentor engineering teams on vulnerability remediation.
  • Drive adoption of security tooling and secure development practices across global teams.
  • Present technical recommendations to senior leadership.
Required Skills & Experience
  • 8+ years of experience in Application Security, DevSecOps, or Secure Software Engineering.
  • Strong hands-on experience with Snyk, Black Duck, and enterprise SAST/SCA platforms.
  • Proven experience integrating security tools into enterprise CI/CD pipelines.
  • Experience designing scalable security tooling architecture.
  • Hands-on experience performing Web Application, REST API, and Thick Client security assessments.
  • Strong experience with vulnerability validation and false-positive analysis.
  • Strong understanding of modern software development practices and Secure SDLC.
  • Experience with application security testing methodologies.
  • Strong technical leadership and stakeholder communication skills.
  • Bachelor's or Master's degree in Computer Science, Information Security, Engineering, or a related field.
Preferred Qualifications
  • Experience in the Automotive or Manufacturing industry.
  • Knowledge of cloud-native application security.
  • Experience implementing enterprise-wide DevSecOps transformation programs.
  • Exposure to AI-assisted secure coding and security automation.
  • Relevant certifications such as OSCP, CISSP, CSSLP, GWAPT, GWEB, GCSA, or Snyk Certified Professional.
Other Requirements
  • Ability to work with global Software Development, DevOps, Enterprise Architecture, Product, Cybersecurity, and Business teams.
  • Strong developer enablement and mentoring capabilities.
  • Ability to drive adoption of security tooling and secure development practices.
  • Strong presentation and communication skills for senior leadership engagement.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead SAST
Lead SAST

Daimler Trucks Innovation Center • Bengaluru

Hybrid
INR 3,000,000 - 6,000,000
DevSecOps (Security test lead) Engineer
DevSecOps (Security test lead) Engineer

D-techworks • Mumbai, Bengaluru

On-site
INR 2,500,000 - 4,000,000
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
Application Security Team Lead
Application Security Team Lead

Pearson India Education Services Pvt Ltd • Bengaluru

On-site
INR 6,000,000 - 9,000,000
Application Security Lead | Offshore
Application Security Lead | Offshore

Photon • Hyderabad

On-site
INR 850,000 - 1,800,000
Application Security Engineer
Application Security Engineer

India Fan Corporation • Hyderabad

On-site
INR 1,800,000 - 2,700,000
Application Security Engineer
Application Security Engineer

Cynosure Corporate Solutions • Chennai District

On-site
INR 1,500,000 - 2,500,000
Appsec Specialist - Lead
Appsec Specialist - Lead

Adani Group • Ahmedabad District

On-site
INR 2,800,000 - 4,200,000
Head of Application Security
Head of Application Security

Adani Enterprises Ltd • Ahmedabad District

On-site
INR 4,000,000 - 7,000,000
Application Security Engineer
Application Security Engineer

DigiCert • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Generous time off policies
Top shelf benefits
Education, wellness, and lifestyle support