Principle Engineer - Application Security

UST

Bengaluru

On-site

INR 2,500,000 - 4,800,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

UST is seeking an experienced Application Security professional in Bengaluru to conduct comprehensive security testing, coordinate findings, and guide developers on secure coding practices.

You will collaborate with cross-functional teams, work with DevOps to optimize SAST/DAST/SCA tools, and drive secure software delivery within an enterprise environment.

Qualifications

  • Strong security fundamentals with hands-on execution in AppSec (SAST/DAST/SCA).
  • Experience in threat modeling, penetration testing, and secure coding practices.
  • Knowledge of DevSecOps processes and cloud security integration.
  • Ability to leverage automation and AI to improve security workflows.

Responsibilities

  • Conduct thorough application security penetration tests
  • Coordinate findings with cross-functional teams and communicate results
  • Help developers fix code security issues and adopt best practices
  • Partner with DevOps to ensure security tools perform well and accurate results
  • Adapt to changing priorities and manage conflicting demands

Skills

SAST
DAST
SCA
Threat Modeling
Penetration Testing
DevSecOps
Cloud Security
Automation
AI Security
AWS Security

Education

Bachelor's degree in CS/IT
GWAPT/GWEB/GPEN/OSCP/CSSLP

Tools

SAST tools
DAST tools
SCA tools

Job description

Role Description

Conduct application security testing in order to comply with corporate policies, and regulatory requirements. Coordinate and execute application security tests, communicate the results to relevant stakeholders, and help application developers understand how to fix code security issues.

Role Description

Conduct application security testing in order to comply with corporate policies, and regulatory requirements. Coordinate and execute application security tests, communicate the results to relevant stakeholders, and help application developers understand how to fix code security issues.

Responsibilities
  • Conduct thorough application security penetration tests
  • Work effectively with a cross-functional team to plan, execute, and communicate findings from application security testing
  • Work with application owners to improve their knowledge and practical application of information security best practices, including but not limited to threat assessment, vulnerability prevention and secure coding practices.
  • Partner with DevOps team to ensure application security tools such as SAST and DAST are performing well and generating accurate testing results.
  • Flexibility to change direction and manage conflicting demands.
Experience
  • 10 -12 years progressive Information Technology experience or equivalent specialized skills with 5+ years of application security experience.
  • Experience in running & administrating static analysis (SAST), dynamic analysis (DAST), and Software Composition Analysis (SCA) tools and processes
  • Experience in conducting and training application penetration testing
  • Experience in Cloud Security.
  • Experience and strong understanding of DevSecOps processes, tools, and integrations.
Qualifications
  • Strong knowledge and ability to work with DevOps teams on the processes and integrations.
  • Strong web application security knowledge with thorough understanding of web, mobile, and API testing Knowledge of application security architecture and ability to perform threat modeling and risk assessments on identified applications.
  • Knowledge of DevSecOps processes and ability to work with the stakeholders to deliver the results for security integrations in DevOps.
  • Development background in .Net, Java, and/or Python a plus Strong knowledge of Security Standards, frameworks and groups (OWASP, WASC, OSSTMM)
  • Knowledge of the software development lifecycle under agile environment in a large enterprise Knowledge of database, application and Web server design
  • Knowledge of current and emerging security technologies, threats and techniques for exploiting security vulnerabilities
  • Knowledge of public cloud services
Education
  • Bachelor's degree in Computer Science, Information Technology or equivalent Advanced degree preferred
  • Certifications including GWAPT, GWEB, GPEN, OSCP, CSSLP, CASE, or similar preferred

The priority is not tool-specific expertise but strong security fundamentals combined with hands-on execution: Application Security (SAST, DAST, SCA, secrets management) Threat Modelling Penetration Testing DevSecOps and Cloud Security Ability to leverage AI/LLMs and automation in security processes

Strong coding and integration capabilities to build or automate workflows Strong Emphasis on Automation and AI Highlighted that the primary need is for engineers who can: Evaluate and implement security automation solutions.

Use AI tools and agents to improve: Threat modelling SAST analysis Penetration testing Security workflow automation

Skills
  • SAST, Threat Modeling, AI Security, Application Security, DAST, Vulnerability Assessment and Penetration Testing, Workflow Automation, Application Security, AWS Security, Cloud Security, LLMs
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Engineer - Application Security
Staff Engineer - Application Security

UST • Bengaluru

On-site
INR 2,400,000 - 4,200,000
Application Security Engineer
Application Security Engineer

Ola • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Application Security Engineer
Application Security Engineer

Whitefield Careers • Bengaluru

On-site
INR 800,000 - 1,200,000
Application Security Engineer
Application Security Engineer

Kyndryl • Dadri, Greater Noida

On-site
INR 2,500,000 - 4,500,000
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
Application Security Engineer (SAST / DAST / DevSecOps / SCA)
Application Security Engineer (SAST / DAST / DevSecOps / SCA)

Qualizeal India • Hyderabad

On-site
INR 1,200,000 - 1,800,000
Application Security
Application Security

Airtel • India

On-site
INR 1,200,000 - 2,400,000
Security-focused culture
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2coms • Bengaluru

On-site
INR 2,500,000 - 4,000,000
Senior Engineer - Cyber Security
Senior Engineer - Cyber Security

Adani Group • Mumbai

On-site
INR 1,200,000 - 2,000,000
Security Engineer
Security Engineer

Cloudxtreme • Hyderabad

On-site
INR 1,200,000 - 1,800,000