Security Engineer (Application Security / Secure Coding)

Estaff Tech Private Limited

Bengaluru Urban

On-site

INR 1,400,000 - 2,200,000

Part time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Tata Consultancy Services (TCS) is seeking an experienced Security Engineer (Application Security / Secure Coding) for a long-term engagement in Bangalore North, India. The role focuses on establishing secure development standards, reviews, vulnerability remediation, and integrating security controls across the SDLC.

The ideal candidate will drive SDL, implement SAST/DAST solutions, and collaborate with Development, QA, DevOps, and Architecture teams to ensure secure and compliant software

Qualifications

  • Strong secure coding practices across development teams.
  • Experience identifying and mitigating web app vulnerabilities (XSS, CSRF, SQLi, auth flaws).
  • Hands-on with SAST/DAST tools in secure SDLC.
  • Familiar with OWASP Top 10 and SDL processes.

Responsibilities

  • Establish and enforce secure coding standards across development teams.
  • Conduct secure code reviews and security audits for backend and mobile apps.
  • Identify, analyze, and remediate application and infrastructure security vulnerabilities.
  • Design and implement SAST and DAST solutions and integrate into CI/CD.
  • Mentor teams on SDL and OWASP best practices.
  • Collaborate with architects to apply security-by-design principles.
  • Maintain security documentation and compliance artifacts.
  • Support DevSecOps initiatives and continuous security improvements.

Skills

Secure coding practices
Application security
DevSecOps
Threat modeling
CI/CD security integration

Tools

SonarQube
Semgrep
Fortify

Job description

Security Engineer (Application Security / Secure Coding)

Bangalore North, India

Security Engineer (Application Security / Secure Coding)

Client: Tata Consultancy Services (TCS)

Employment Type: Long-Term Contract

Experience Required: 4–6 Years

Job Summary

We are seeking an experienced Security Engineer with a strong background in Application Security, Secure Coding Practices, and DevSecOps. The ideal candidate will be responsible for establishing secure development standards, conducting security reviews, identifying vulnerabilities, and integrating security controls throughout the software development lifecycle.

The role requires close collaboration with Development, QA, DevOps, and Architecture teams to ensure applications are secure, compliant, and aligned with industry best practices.

Key Responsibilities
  • Establish and enforce secure coding standards across development teams.
  • Conduct secure code reviews and security audits for backend and mobile applications.
  • Identify, analyze, and remediate application and infrastructure security vulnerabilities.
  • Design and implement Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) solutions.
  • Improve code quality, test coverage, and documentation standards.
  • Train and mentor development teams on Secure Development Lifecycle (SDL) and OWASP best practices.
  • Integrate security controls and automated security gates into CI/CD pipelines.
  • Perform threat modeling and security risk assessments for new features and applications.
  • Collaborate with architects and engineering teams to incorporate security-by-design principles.
  • Maintain security documentation, standards, and compliance-related artifacts.
  • Support DevSecOps initiatives and continuous security improvement programs.
Required Skills
Application Security
  • Strong understanding of secure software development practices.
  • Experience identifying and mitigating common web application vulnerabilities:
    • Cross-Site Scripting (XSS)
    • Cross-Site Request Forgery (CSRF)
    • SQL Injection (SQLi)
    • Authentication and Authorization vulnerabilities
    • API Security risks
Programming & Development
  • Hands-on experience in one or more of the following:
    • Java
    • JavaScript
    • Node.js
    • Kotlin
  • Strong debugging and code analysis capabilities.
Security Tools
  • Experience with secure code review and vulnerability assessment tools such as:
    • SonarQube
    • Semgrep
    • Fortify
    • Similar SAST/DAST tools
Security Standards & Frameworks
  • Strong knowledge of:
    • OWASP Top 10
    • CWE (Common Weakness Enumeration)
    • CVSS (Common Vulnerability Scoring System)
    • Secure Development Lifecycle (SDL)
DevOps & Automation
  • Experience working in Agile and DevSecOps environments.
  • Knowledge of CI/CD pipelines and security automation.
  • Experience integrating security testing into deployment workflows.
Soft Skills
  • Excellent verbal and written communication skills.
  • Ability to collaborate with cross‑functional teams.
  • Strong analytical and problem‑solving skills.
Preferred Skills
  • Experience with threat modeling and architecture security reviews.
  • Exposure to cloud security concepts (AWS, Azure, or GCP).
  • Knowledge of container and Kubernetes security.
  • Experience with Infrastructure as Code (IaC) security scanning.
  • Familiarity with compliance and security governance frameworks.
  • Experience implementing enterprise‑wide secure coding initiatives.
  • Security certifications such as:
    • Certified Secure Software Lifecycle Professional (CSSLP)
    • Certified Ethical Hacker (CEH)
    • CompTIA Security+
    • GIAC Certifications
    • CISSP (Preferred)
Ideal Candidate Profile

The ideal candidate should have 4–6 years of experience in Application Security or Secure Software Development, strong expertise in secure coding practices, hands‑on exposure to SAST/DAST tools, and the ability to drive security‑first development practices across engineering teams. They should be comfortable working in a fast‑paced Agile environment and collaborating with developers, architects, QA, and DevOps teams.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

TECHNICAL LEAD - Application Security
TECHNICAL LEAD - Application Security

Happiest Minds Technologies • Bengaluru

On-site
INR 3,500,000 - 6,000,000
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2coms • Bengaluru

On-site
INR 2,500,000 - 4,000,000
Application Security Engineer
Application Security Engineer

US Software Group Inc • Bengaluru

Hybrid
INR 9,033,000 - 11,744,000
Application Testing Engineer
Application Testing Engineer

Quess • Chennai District, Bengaluru, Pune District

Hybrid
INR 700,000 - 1,500,000
Application Security Engineer
Application Security Engineer

Basebiz • Pune District

On-site
INR 1,800,000 - 3,000,000
Application Security Engineer
Application Security Engineer

Basebiz • Bengaluru

On-site
INR 1,800,000 - 2,800,000
Application Security Engineer
Application Security Engineer

Basebiz • Chennai District

On-site
INR 1,200,000 - 1,800,000
Application Security Manager
Application Security Manager

Coventine Digital • Chennai District, Bengaluru, Pune District

On-site
INR 3,000,000 - 6,000,000
Application Security Engineer
Application Security Engineer

Cynosure Corporate Solutions • Chennai District

On-site
INR 1,500,000 - 2,500,000
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000