Security Engineer III

Verizon

Chennai District

Hybrid

INR 1,400,000 - 1,900,000

Full time

7 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Verizon is seeking a Security Engineer to join its Application Security team. The role focuses on integrating DAST into the SDLC, tuning scanners, and helping developers remediate vulnerabilities in Java applications.

You will develop and mature DAST practices, configure authenticated scans, and collaborate with cross-functional teams. The position is hybrid with work-from-home options and defined office days. The team values proactive learning and strong security foundations.

Qualifications

  • Bachelor's degree or two or more years of work experience.
  • Three or more years of experience in Software Engineering, Application Security, or a related role.
  • DAST Expertise: Deep, hands-on experience managing and operating DAST tools in an enterprise environment, including configuring authenticated scans and handling SSO contexts.
  • Java Development: 2+ years of professional software development using Java and frameworks like Spring Boot or Jakarta EE/JEE.
  • Web Technologies: Deep understanding of web app architecture, HTTP, REST, and security controls (CORS, CSRF, XSS).
  • Vulnerability Knowledge: Knowledge of OWASP Top 10 or CWE/SANS Top 25.
  • CI/CD: Experience integrating security tools into CI/CD pipelines (Jenkins, GitLab, Azure DevOps).
  • Cloud: Familiarity securing apps on AWS, Azure, or GCP.

Responsibilities

  • Strategy & Implementation: Defining and maturing the organization's DAST strategy and integrating automated scanning into CI/CD pipelines.
  • Tool Management: Selecting, configuring, and maintaining DAST solutions.
  • Scanning & Analysis: Performing DAST scans on web apps, APIs, and microservices and reporting vulnerabilities.
  • Custom Scripting & Automation: Developing scripts to enhance DAST coverage and integrate outputs with defect tracking.
  • Vulnerability Remediation: Guiding development teams to remediate vulnerabilities with secure coding guidance.
  • Code Review: Conducting security code reviews focusing on architectural flaws and deserialization, insecure configurations, etc.
  • Secure Coding Standards: Developing and promoting secure coding standards and best practices.
  • Documentation & Training: Creating documentation and hands-on training for engineering teams.
  • Incident Response: Assisting in investigating application security incidents with deep technical insights.
  • Stay Current: Researching new attack techniques and emerging Java vulnerabilities.

Skills

DAST Expertise
Java Development
Web Technologies
CI/CD
Cloud
Security Testing

Education

Bachelor's degree or two or more years of work experience

Tools

OWASP ZAP
Burp Suite Enterprise
Tenable WAS
Jira
Jenkins
GitLab
SSO

Job description

When you join Verizon

You want more out of a career. A place to share your ideas freely - even if they're daring or different. Where the true you can learn, grow, and thrive. At Verizon, we power and empower how people live, work and play by connecting them to what brings them joy. We do what we love - driving innovation, creativity, and impact in the world. Our V Team is a community of people who anticipate, lead, and believe that listening is where learning begins. In crisis and in celebration, we come together - lifting our communities and building trust in how we show up, everywhere & always. Want in? Join the #VTeamLife.

We are seeking a highly skilled and motivated Security Engineer to join our Application Security team. This role requires a unique blend of deep expertise in Dynamic Application Security Testing (DAST) methodologies and tools, coupled with strong hands-on experience in Java development. The ideal candidate will be instrumental in integrating security practices directly into our Software Development Lifecycle (SDLC), particularly by establishing, tuning, and operating our DAST program and helping development teams remediate complex security vulnerabilities.

What You'll Be Doing…
  • Strategy & Implementation: Defining, implementing, and continuously maturing the organization's DAST strategy, integrating automated scanning into CI/CD pipelines (e.g., Jenkins, GitLab CI).
  • Tool Management: Selecting, configuring, managing, and maintaining DAST solutions (e.g., OWASP ZAP, Burp Suite Enterprise, or commercial tools like Tenable WAS).
  • Scanning & Analysis: Performing comprehensive DAST scans on web applications, APIs, and microservices, analyzing results for false positives and reporting actionable vulnerabilities.
  • Custom Scripting & Automation: Developing custom scripts and automation (using Python, Java, or Shell) to enhance DAST coverage, automate testing scenarios, and integrate DAST output with defect tracking systems (e.g., Jira).
  • Vulnerability Remediation: Partnering directly with development teams to explain vulnerability root causes, provide secure coding examples, and guide them through the remediation process.
  • Code Review: Conducting targeted security code reviews for critical applications, focusing on architectural security flaws and common specific vulnerabilities (e.g., deserialization issues, Spring/Struts security misconfigurations, injection flaws).
  • Secure Coding Standards: Developing and promoting secure coding standards and best practices and associated frameworks.
  • Documentation & Training: Creating high-quality documentation, training materials, and run hands-on workshops to elevate the security knowledge of engineering teams.
  • Incident Response: Assisting in the investigation and resolution of application security incidents, providing deep technical insight into Java application behavior and potential attack vectors.
  • Stay Current: Researching continuously for new attack techniques, security trends, and emerging Java-related vulnerabilities.
What We're Looking For…
You'll need to have:
  • Bachelor's degree or two or more years of work experience.
  • Three or more years of experience in Software Engineering, Application Security, or a related role.
  • DAST Expertise: Deep, hands-on experience managing and operating DAST tools in an enterprise environment, including configuring authenticated scans and handling Single Sign-On (SSO) contexts.
  • Java Development: Strong background (2+ years) in professional software development, primarily using Java and common frameworks (Spring Boot, Jakarta EE/JEE).
  • Web Technologies: Expert understanding of web application architecture, HTTP protocols, RESTful APIs, and associated security controls (CORS, CSRF, XSS, etc.).
  • Vulnerability Knowledge: Expert knowledge of the OWASP Top 10 or CWE/SANS Top 25.
  • CI/CD: Experience integrating security tools (DAST, SAST) into automated CI/CD pipelines (e.g., Jenkins, GitLab, Azure DevOps).
  • Cloud: Familiarity with securing applications deployed on major cloud platforms (AWS, Azure, or GCP).
Even better if you have one or more of the following…
  • Good communication and presentation skills.
  • Relevant industry certifications (e.g: CSSLP, OSCP, eJPT ).
  • Experience with other security testing methodologies (SAST, IAST, Penetration Testing).
  • Familiarity with containerization and orchestration technologies (Docker, Kubernetes).

If Verizon and this role sound like a fit for you, we encourage you to apply even if you don't meet every "even better" qualification listed above.

Where you'll be working

In this hybrid role, you'll have a defined work location that includes work from home and assigned office days set by your manager.

Scheduled Weekly Hours

40

Equal Employment Opportunity

Verizon is an equal opportunity employer. We evaluate qualified applicants without regard to race, gender, disability or any other legally protected characteristics.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer III
Security Engineer III

verizon • Bengaluru

Hybrid
INR 1,500,000 - 2,400,000
Hybrid work model
Engr IV-Security Engineering
Engr IV-Security Engineering

Verizon • Chennai District

Hybrid
INR 2,500,000 - 6,000,000
Engr IV-Security Engrg (Network)
Engr IV-Security Engrg (Network)

Verizon Communications • Chennai District

Hybrid
INR 3,500,000 - 6,500,000
Dynamic application security Engineer
Dynamic application security Engineer

Cloudxtreme • Hyderabad, Chennai District, Bengaluru

Hybrid
INR 1,200,000 - 2,400,000
Hybrid work model
Dynamic Application Security Testing
Dynamic Application Security Testing

Cloudxtreme • Hyderabad, Bengaluru, Delhi

Hybrid
INR 1,500,000 - 3,500,000
SDE I - Security
SDE I - Security

Navi Limited • Bengaluru

On-site
INR 600,000 - 1,000,000
Senior Security Specialist
Senior Security Specialist

Lennox • Chennai District

On-site
INR 3,000,000 - 4,200,000
Senior Application Security Engineer
Senior Application Security Engineer

FloQast, Inc. • Pune District

On-site
INR 1,500,000 - 2,500,000
Security Engineer
Security Engineer

Cloudxtreme • Hyderabad

On-site
INR 1,200,000 - 1,800,000
Staff Application Security Engineer
Staff Application Security Engineer

Ivanti • Bengaluru

Remote
INR 1,500,000 - 2,000,000
Remote-friendly schedules
Competitive compensation
Global collaboration
+2