Security Engineer

Cloudxtreme

Hyderabad

On-site

INR 1,200,000 - 1,800,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Cloudxtreme is seeking a Security Engineer to embed security across the SDLC, focusing on threat modeling, code analysis, vulnerability management, and risk prioritization.

You will work with DevOps and cloud teams to identify and remediate risks, integrating security into CI/CD and promoting secure coding practices across engineering.

Qualifications

  • Hands-on with Checkmarx SAST.
  • Experience with Threat Modeler for design-level security analysis.
  • Knowledge of Zafran Security or similar ASPM platforms.
  • Strong understanding of OWASP Top 10 and secure coding practices.
  • Familiar with CI/CD tools (Jenkins, GitHub Actions, GitLab CI).
  • Experience with cloud platforms (AWS, Azure, or GCP).
  • Soft skills: communication and translating risks into business impact.

Responsibilities

  • Integrate security into all phases of the SDLC.
  • Perform automated threat modeling during design and architecture phases.
  • Identify potential attack vectors and recommend controls.
  • Conduct SAST using Checkmarx.
  • Review findings and reduce false positives.
  • Remediate vulnerabilities with developers (SQL injection, XSS, CSRF, insecure authentication).
  • Use Zafran Security to prioritize vulnerabilities.

Skills

Checkmarx
Threat Modeler
Zafran Security
ASPM platform
OWASP Top 10
Secure coding
Web security
API security
CI/CD tools
Cloud platforms

Tools

Threat Modeler

Job description

Role & responsibilities

Security Engineer

Job Summary


We are seeking an experienced Security Engineer to help embed security throughout the SDLC. The role involves threat modeling, secure code analysis, vulnerability management, and risk prioritization using tools such as Threat Modeler, Checkmarx, and Zafran Security. You will work closely with development, DevOps, and cloud teams to proactively identify and remediate security risks.


Key Responsibilities

Application Security & SDLC


  • Integrate security into all phases of the Software Development Life Cycle (SDLC).

  • Perform automated threat modeling using Threat Modeler during design and architecture phases.

  • Identify potential attack vectors and recommend security controls and mitigations.


Code & Vulnerability Analysis


  • Conduct Static Application Security Testing (SAST) using Checkmarx.

  • Review and validate security findings, reducing false positives.

  • Work with developers to remediate vulnerabilities such as SQL Injection, XSS, CSRF, and insecure authentication.


Risk Management & Prioritization


  • Use Zafran Security to aggregate and prioritize vulnerabilities from multiple AppSec tools.

  • Focus remediation efforts based on exploitability, business impact, and application exposure.

  • Track vulnerability remediation and risk acceptance.


DevSecOps Enablement


  • Integrate security tools into CI/CD pipelines.

  • Automate security testing and reporting.

  • Collaborate with DevOps teams to implement secure build and deployment practices.


Collaboration & Reporting


  • Partner with engineering teams to promote secure coding best practices.

  • Provide security guidance, training, and awareness sessions.

  • Prepare security metrics, dashboards, and executive-level reports.


Required Skills & Qualifications

Technical Skills


  • Hands-on experience with Checkmarx (SAST).

  • Experience with Threat Modeler for design-level security analysis.

  • Knowledge of Zafran Security or similar ASPM / vulnerability prioritization platforms.

  • Strong understanding of:


    • OWASP Top 10

    • Secure coding practices

    • Web and API security



  • Familiarity with CI/CD tools (Jenkins, GitHub Actions, GitLab CI, etc.).

  • Experience with cloud platforms (AWS, Azure, or GCP).


Soft Skills


  • Strong communication skills to work with developers and stakeholders.

  • Ability to translate technical risks into business impact.

  • Problem-solving mindset with attention to detail.


Preferred Qualifications


  • Experience with DAST, SCA, or container security tools.

  • Knowledge of threat modeling frameworks (STRIDE, PASTA).

  • Security certifications such as CEH, CSSLP, GWAPT, or CISSP.

  • Experience in Agile / DevOps environments.


Nice to Have


  • Python, Java, or JavaScript security testing experience.

  • Exposure to regulatory standards (ISO 27001, SOC 2).

  • Experience building AppSec programs from scratch.


Preferred candidate profile
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

Kyndryl • Dadri, Greater Noida

On-site
INR 2,500,000 - 4,500,000
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
Appsec Specialist - Lead
Appsec Specialist - Lead

Adani Group • Ahmedabad District

On-site
INR 2,800,000 - 4,200,000
DevSecOps (Security test lead) Engineer
DevSecOps (Security test lead) Engineer

D-techworks • Mumbai, Bengaluru

On-site
INR 2,500,000 - 4,000,000
Cyber Security Engineer
Cyber Security Engineer

Tecnots • India

On-site
INR 1,500,000 - 2,100,000
Application Security Engineer
Application Security Engineer

Ola • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Cybersecurity Subject Matter Expert
Cybersecurity Subject Matter Expert

Sunovaa Tech • Pune District, Bengaluru

Hybrid
INR 2,500,000 - 4,000,000
Staff Software Engineer
Staff Software Engineer

Movate Technologies • India

On-site
INR 4,000,000 - 7,000,000
DevSecOps Engineer (SAST/DAST)
DevSecOps Engineer (SAST/DAST)

Alignity Solutions • Hyderabad

Hybrid
INR 1,200,000 - 1,800,000
Hybrid work model
Product Security Engineer
Product Security Engineer

Atlas Consolidated • Hyderabad

On-site
INR 1,800,000 - 2,400,000