Security Engineer

Promaynov Advisory Services Pvt. Ltd

Bengaluru

On-site

INR 1,000,000 - 1,500,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Promaynov Advisory Services Pvt. Ltd in Bengaluru, India is seeking a Security Engineer focusing on AI, ML, DevSecOps, and Application Security. The ideal candidate will possess over 4 years of hands-on experience with security tools like SAST, SCA, and DAST, and will play a crucial role in integrating and optimizing security tools within CI/CD pipelines.

The role involves executing security assessments, providing clear remediation guidance, and ensuring the overall security of the software development lifecycle. Strong communication skills and a solid understanding of modern application security are essential.

Qualifications

  • 4+ years of hands-on experience in application security / DevSecOps.
  • Experience with leading AppSec tools.
  • Strong understanding of SSDLC and secure coding practices.

Responsibilities

  • Integrate SAST, SCA, and DAST tools within CI/CD pipelines.
  • Perform API security testing including authentication validation.
  • Analyze scan results and provide remediation guidance.

Skills

SAST
SCA
DAST
Python
API security testing
DevSecOps practices

Tools

Checkmarx
Veracode
Fortify
Burp Suite
OWASP ZAP

Job description

We are seeking a Security Engineer – AI/ML/DevSecOps / Application Security with strong hands‑on delivery experience in SAST, SCA, and DAST to embed security across the software development lifecycle. This role focuses on implementing and operating application security tooling in CI/CD pipelines, executing application security assessments (including API security), triaging and prioritizing findings, enabling remediation, and driving secure‑by‑design engineering practices across cloud‑native and enterprise applications. SAST, SCA, and DAST remain foundational AppSec capabilities, and the role is positioned accordingly with an emphasis on measurable delivery outcomes (tool onboarding, pipeline coverage, risk reduction, and remediation closure).

As a Security Engineer, You Will
  • Integrate, configure, and optimize SAST, SCA, and DAST tools within CI/CD pipelines to automate security testing across build, test, and release stages (including quality gates and exception workflows).
  • Perform static, dynamic, and open‑source dependency assessments to identify vulnerabilities including OWASP Top 10 risks, insecure libraries, exposed secrets, misconfigurations, and software supply‑chain weaknesses.
  • Execute API security testing (REST/GraphQL) including authentication/authorization validation (OAuth2/OIDC/JWT), input validation, rate limiting/abuse cases, and broken object/function level authorization (BOLA/BFLA), and translate results into developer‑ready fixes.
  • Analyze scan results, remove false positives, prioritize findings based on exploitability and business impact, and provide clear, actionable remediation guidance (secure coding patterns, compensating controls, and verification steps).
  • Work hands‑on with developers, DevOps engineers, architects, and client stakeholders to embed secure coding, secure design, and shift‑left security practices, including playbooks, office hours, and remediation sprints.
  • Support threat modeling and security design reviews; convert threats into actionable security requirements, test cases, and engineering backlog items aligned to delivery timelines.
  • Track vulnerabilities through closure, validate remediation (re‑scan, proof of fix, and regression checks), and ensure issues are managed in line with client policy, risk tolerance, and SLA expectations.
  • Implement additional DevSecOps controls such as IaC scanning, secrets detection, container image scanning, and Kubernetes security checks (where applicable), including policy‑as‑code to prevent insecure deployments.
  • Strengthen software supply‑chain security by supporting SBOM generation/consumption, dependency hygiene, and build/release integrity controls (e.g., artifact signing/verification and provenance where applicable).
  • Automate repeatable security tasks using scripting (e.g., Python/Bash) and integrations (APIs/webhooks) to improve scan reliability, reporting, and developer workflow adoption.
  • Design and build AI agents / agentic workflows for AppSec automation (e.g., triage, false‑positive suppression, secure code review assistance, threat‑model generation, remediation assistance), ensuring appropriate guardrails, logging, and human‑in‑the‑loop validation.
  • Perform current‑state assessments of client DevSecOps and emerging AISecOps practices against industry standards; provide prioritized recommendations and an implementation roadmap.
  • Perform security testing across modern application surfaces—code, APIs, cloud, containers/Kubernetes—and, where applicable, AI/ML pipelines (e.g., RAG data flows, model integration points, and tool/function calling) using a combination of automated and manual techniques.
  • Produce security assessment reports, dashboards, trend analysis, and root‑cause insights for technical and non‑technical stakeholders.
  • Contribute to secure SDLC standards aligned to recognized verification frameworks such as OWASP ASVS.
  • Stay current on emerging threats, AppSec tooling trends, software supply‑chain risks, and new attack surfaces introduced by AI‑enabled applications and agentic workflows.
Qualifications
  • Own end‑to‑end delivery for a workstream (or multiple applications): tool onboarding plan, scan strategy (SAST/SCA/DAST/API), coverage tracking, and closure metrics.
  • Design and implement CI/CD security patterns at scale (reusable templates, quality gates, exception workflows), including policy‑as‑code and integrations with vulnerability management/ticketing/reporting.
  • Design and build AI agents / agentic workflows for AppSec automation use cases (e.g., automated vulnerability triage, false‑positive suppression, secure code review assistance, threat‑model generation, and remediation assistance), with human validation and safe‑guardrails.
  • Lead security architecture reviews, threat modeling, and risk‑based prioritization with clients for modern applications, microservices, APIs, and AI/ML systems (including LLM‑based and agentic architectures); translate outcomes into engineering backlogs and acceptance criteria.
  • Apply AISecOps and AppSec frameworks as applicable (e.g., OWASP Top 10 for LLM Applications, MITRE ATLAS, NIST AI RMF, OWASP ASVS) to assess and harden AI/ML pipelines, RAG systems, and agentic platforms; guide controls such as guardrails, least‑privilege tool access, and secure data handling.
  • Mentor junior team members on engagements; contribute to proposals/solutioning and continuously improve reusable playbooks, points‑of‑view, and accelerators.
Must‑have Skills / Project Experience
  • 4+ years of hands‑on experience in application security / DevSecOps, with strong experience in SAST, SCA, and DAST (and ability to operate these in CI/CD).
  • Experience with leading AppSec tools such as Checkmarx, Veracode, Fortify, Burp Suite, OWASP ZAP, Snyk, Mend/WhiteSource, Black Duck, or similar.
  • Strong understanding of SSDLC, OWASP Top 10, secure coding practices, and common web/API vulnerabilities (authentication/authorization, injection, SSRF, deserialization, misconfiguration).
  • Experience integrating security controls into Jenkins, GitLab CI, GitHub Actions, Azure DevOps, or similar CI/CD platforms, including pipeline templates, quality gates, and exception processes.
  • Python proficiency for AppSec automation (e.g., pipeline integrations, parsing/enrichment, and custom checks); experience with scripting to operationalize security at scale.
  • Hands‑on experience designing/building AI agents or agentic workflows for security/engineering use cases, including tool/function calling and multi‑step orchestration (frameworks such as LangChain/LangGraph/CrewAI/AutoGen or equivalent).
  • Experience in vulnerability triage, remediation validation, developer enablement, and reporting.
  • Working knowledge of threat modeling, security architecture review, and secure design principles.
  • Hands‑on experience performing API security testing and guiding remediation for authorization and abuse‑case issues (e.g., BOLA/BFLA) in modern application architectures.
  • Familiarity with cloud‑native application security, containers/Kubernetes, IaC, and secrets management concepts in delivery pipelines.
  • Awareness of security risks in LLM‑enabled applications (prompt injection, sensitive data exposure, insecure tool/function calling) and ability to apply basic mitigating controls during delivery.
  • Strong verbal and written communication skills, including the ability to explain risk and remediation to both technical and business stakeholders.
Preferred / Good‑to‑have Skills
  • Experience conducting security architecture reviews and identifying design‑level weaknesses.
  • Experience using OWASP ASVS or equivalent control frameworks to define and validate AppSec requirements.
  • Experience with container/Kubernetes security, IaC scanning, secrets detection, and policy‑as‑code (e.g., OPA/Gatekeeper or similar concepts/tools).
  • Exposure to software supply‑chain security practices such as SBOM, artifact signing/verification, dependency pinning, and build provenance (concepts aligned to SLSA).
  • Knowledge of regulatory/compliance requirements impacting application security programs.
  • Familiarity with AISecOps frameworks and guidance (e.g., OWASP Top 10 for LLM Applications, OWASP Agentic Security, MITRE ATLAS, NIST AI RMF, Google SAIF).
  • Experience with LLM guardrails and safety controls (e.g., NeMo Guardrails, Llama Guard, or similar) and/or agent sandboxing patterns.
  • Exposure to AI/ML supply‑chain security (e.g., model registries, signed model artifacts, ML‑BOM concepts) and governance for model and data lineage.
  • Exposure to IAST, runtime application protection, or unified AppSec platforms.
AI / GenAI Capabilities (delivery‑focused)
  • Use AI‑assisted techniques responsibly for triage, summarization, and remediation suggestions with strong validation and secure handling of client data.
  • Create and execute GenAI/LLM security test cases (prompt injection/jailbreaks, data exfiltration paths, tool/function‑calling abuse) and recommend guardrails and monitoring.
  • Understand RAG risks (data poisoning, retrieval manipulation) and apply hardening controls (content filtering, grounding checks, least privilege for connectors).
  • Experience using AI‑assisted AppSec tooling for vulnerability triage, false‑positive reduction, exploitability context, and remediation recommendation—while validating outputs before use.
  • Ability to create GenAI/LLM application test cases (prompt injection, data exfiltration paths, jailbreak attempts, and abuse scenarios) and translate them into actionable engineering controls/guardrails.
  • Familiarity with securing RAG patterns and tool/function calling integrations (least privilege for connectors, allow‑listing tools, validation of model outputs, and protection against unsafe actions).
  • Familiarity with reviewing and governing AI‑generated code (secure coding patterns, secrets leakage checks, licensing considerations for generated snippets where applicable) within standard PR workflows.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Appsec & AI Security
Appsec & AI Security

Promaynov Advisory Services Pvt. Ltd • Bengaluru

On-site
INR 2,500,000 - 3,500,000
Lead Security Engineer – DevSecOps
Lead Security Engineer – DevSecOps

Jobtailor • India

On-site
INR 4,000,000 - 6,500,000
Application Security Engineer
Application Security Engineer

Millennium • Bengaluru

On-site
INR 1,500,000 - 2,500,000
AI Security Engineer
AI Security Engineer

India Fan Corporation • Hyderabad

On-site
INR 2,500,000 - 6,000,000
AI Security Engineer
AI Security Engineer

Agile Dna • Hyderabad

On-site
INR 2,400,000 - 4,200,000
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
Lead - AI and Application Security
Lead - AI and Application Security

LeadSquared • Bengaluru

On-site
INR 1,400,000 - 2,200,000
AI and Cloud Security Engineer
AI and Cloud Security Engineer

TD Synnex • Mumbai

On-site
INR 4,500,000 - 7,500,000
Senior AI Application Security Architect
Senior AI Application Security Architect

Radware • Chennai District

On-site
INR 4,000,000 - 7,000,000
Security Tester
Security Tester

Paramount Computer Systems LLC • Coimbatore District

On-site
INR 900,000 - 1,300,000