Manager - AppSec/DevSecOps Security Engineer

Ex

Dadri

On-site

INR 2,500,000 - 5,000,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Ex seeks a seasoned security leader to own and evolve the application security program across strategy, testing, and governance. You will mentor a team of AppSec engineers, lead penetration testing efforts, and drive risk decisions with engineering and product leadership.

The role covers AI security, secure code reviews, and DevSecOps integration, with a focus on OWASP ASVS/NIST/ISO standards. Collaborate with clients and vendors to strengthen security posture and compliance.

Qualifications

  • Experience leading an AppSec team and mentoring engineers.
  • Strong knowledge of OWASP, NIST 800-53, ISO 27001, PCI-DSS, and SOC 2.
  • Experience conducting web/mobile security assessments.

Responsibilities

  • Own and evolve the application security strategy, testing roadmap, and service catalogue aligned to business and regulatory requirements.
  • Lead, and mentor a team of AppSec engineers and penetration testers; manage workload, quality, and career development.
  • Act as the primary escalation point for application security risk decisions across engineering and product leadership.
  • Drive continuous improvement in AppSec tooling, methodologies, and coverage metrics.
  • Represent the AppSec function in client discussions, audits, risk committees, and vendor assessments.

Skills

Leadership
Team mentoring
AppSec strategy
Penetration testing
OWASP
DevSecOps
Cloud security

Tools

Semgrep
Checkmarx
Veracode
SonarQube
Frida
Objection
Drozer
Jenkins
GitHub Actions
Terraform
CloudFormation
SAST
DAST
SCA

Job description

Leadership & Programme Management
  • Own and evolve the application security strategy, testing roadmap, and service catalogue aligned to business and regulatory requirements.
  • Lead, and mentor a team of AppSec engineers and penetration testers; manage workload, quality, and career development.
  • Act as the primary escalation point for application security risk decisions across engineering and product leadership.
  • Drive continuous improvement in AppSec tooling, methodologies, and coverage metrics.
  • Represent the AppSec function in client discussions, audits, risk committees, and vendor assessments.
Web Application Penetration Testing
  • Oversee and conduct advanced web application penetration testing including complex business logic, authentication/authorisation flaws, API abuse, and chained attack scenarios.
  • Define and maintain testing methodology aligned to OWASP Testing Guide, PTES, and client-specific requirements.
  • Review and quality-assure penetration test reports produced by the team before delivery to clients or stakeholders.
  • Drive responsible disclosure and coordinated vulnerability management for critical findings.
Mobile Application Security
  • Lead mobile security assessments for Android and iOS—static/dynamic analysis, reverse engineering, and runtime manipulation (Frida, objection, Drozer).
  • Establish and maintain mobile security standards aligned to OWASP MASVS and MSTG across product teams.
  • Guide development teams on secure mobile architecture: certificate pinning, secure storage, and inter-process communication security.
Source Code Review
  • Conduct and oversee manual source code security reviews across multiple languages (Java, Python, JavaScript/TypeScript, Go, C#, and others).
  • Define code review standards and integrate SAST tooling (Semgrep, Checkmarx, Veracode, SonarQube) into development workflows.
  • Provide actionable, developer-centric findings with clear severity ratings and remediation guidance.
  • Track remediation SLAs and report on code security posture trends over time.
DevSecOps Integration
  • Lead integration of security tooling (SAST, DAST, SCA, container scanning, API security) into CI/CD pipelines (Jenkins, GitHub Actions, and similar).
  • Define pipeline security gates, policy-as-code standards, and developer feedback loops to shift security left.
  • Oversee IaC security (Terraform, CloudFormation), secrets management, and supply-chain security controls.
  • Collaborate with platform and cloud engineering on secure architecture, baseline hardening, and runtime protection.
Governance, Risk & Compliance
  • Own the application security risk register; track, prioritise, and report on vulnerability posture to senior leadership.
  • Ensure AppSec activities align with OWASP ASVS, NIST 800-53, ISO 27001, PCI-DSS, and SOC 2.
  • Define and track AppSec KPIs: mean time to remediation, critical findings per release, and coverage rates.
  • Translate regulatory and client security requirements into testable engineering controls.
AI / GenAI Security
  • Assess and mitigate risks in AI/GenAI applications: LLM-based apps, RAG pipelines, agentic workflows (OWASP LLM Top 10, prompt injection, data leakage).

Incorporate AI security testing into standard AppSec assessment methodologies.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
Application Security
Application Security

Airtel • India

On-site
INR 1,200,000 - 2,400,000
Security-focused culture
Application Security Engineer
Application Security Engineer

Kyndryl Inc. • Uttar Pradesh

On-site
INR 2,500,000 - 4,500,000
Security Engineer
Security Engineer

Promaynov Advisory Services Pvt. Ltd • Bengaluru

On-site
INR 1,000,000 - 1,500,000
Application Security Specialist (AppSec + AI Security)
Application Security Specialist (AppSec + AI Security)

Qualizeal India • Hyderabad

On-site
INR 3,000,000 - 6,000,000
Staff Engineer - Application Security
Staff Engineer - Application Security

UST • Bengaluru

On-site
INR 2,400,000 - 4,200,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Nextwebi • Bengaluru

On-site
INR 1,500,000 - 3,000,000
Security Engineering Manager
Security Engineering Manager

Smartstream Limited • Bengaluru

On-site
INR 4,000,000 - 7,000,000
Application Security Engineer
Application Security Engineer

Ola • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Security Engineering Manager
Security Engineering Manager

SmartStream • India

On-site
INR 4,000,000 - 6,000,000