Security Engineer - SAST & SCA

Sonata Software

Bengaluru

On-site

INR 1,500,000 - 2,700,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Sonata Software is seeking a Security Engineer to join the Application Security team in Noida. The role focuses on hands-on SAST and SCA tooling to identify, prioritize and remediate vulnerabilities across the software development lifecycle.

You will drive remediation with development teams, integrate scanners into CI/CD pipelines and help mature DevSecOps practices, while upholding secure coding standards and threat-model awareness.

Qualifications

  • Hands-on with SAST and SCA tools to identify and remediate vulnerabilities throughout SDLC.
  • Experience with integrating security tools into CI/CD pipelines and automating workflows.
  • Strong knowledge of OWASP Top 10 and secure coding practices.

Responsibilities

  • Perform static code analysis and open-source dependency scanning using SAST and SCA tools.
  • Analyze and prioritize findings and drive remediation with development teams.
  • Integrate security scanning into CI/CD pipelines and automate security workflows.
  • Manage vulnerability lifecycle, reporting and compliance metrics.
  • Promote secure coding practices and provide remediation guidance to engineers.
  • Support DevSecOps initiatives and shift-left security adoption.

Skills

SAST
SCA
OWASP Top 10
CI/CD integration
Security best practices
Scripting (Python/Bash/PowerShell)
Communication

Tools

Checkmarx
Fortify
Veracode
CodeQL
Snyk
Black Duck
Mend (WhiteSource)
Sonatype
Dependabot
GitHub
GitLab
Jenkins
Azure DevOps
Python
Bash
PowerShell

Job description

ABOUT SONATA SOFTWARE

Sonata Software, with over $1.2 Billion Revenue, is a leading AI-first Modernization Engineering company, powered by our unique Platformation(TM) framework. Our 6400+ AI Engineers are helping enterprises transform from systems to intelligent business platforms leveraging partner ecosystem to drive speed, efficiency and growth. Our bouquet of Modernization Engineering Services with AI-first approach cuts across Cloud, Data, AI, Dynamics, Test Automation, and Managed Services.

Sonatas AI-led modernization is enabled by a powerful suite of proprietary tools and assets. At the core is the Harmoni.AI Enterprise Platform, which includes Agent Bridge – a governance and observability framework; Agent Builder – a development toolkit for fungible agents integrated into enterprise systems; and the Agent Marketplace – an internal ecosystem for modular, reusable agents.

Headquartered in Bengaluru, India, Sonata Software has a strong global presence, including key regions US, UK, India, Malaysia, Mexico, Australia, DACH (Germany/Switzerland), Nordics (Finland). We are a trusted partner of Fortune 500 companies in Banking, Financial Services and Insurance; Healthcare and Lifesciences; Telecom, Media, and Technology; and Retail, Manufacturing and Distribution space.

Deep collaborations with partners like Microsoft, AWS, Salesforce, and Snowflake strengthen our ability to deliver cutting-edge AI solutions. Our 30+ years of partnership with Microsoft, and being part of the elite Microsoft Inner Circle, places us among the top 1% of global Microsoft partners. Sonata is now among the first companies to earn the Microsoft Frontier Partner Badge. Also; Sonata Software is proud to achieve AWS Premier Tier Status in the AWS Partner Network.

Job Title

Security Engineer SAST SCA (Application Security)

Location

Noida

Experience

4-7 years

Mandatory Skills

SAST, SCA.

Job Description

We are looking for a Security Engineer SAST SCA to join our Application Security team. The ideal candidate will have hands-on experience with Static Application Security Testing (SAST) and Software Composition Analysis (SCA) tools, helping development teams identify, prioritize, and remediate application and open-source vulnerabilities throughout the SDLC.

Key Responsibilities
  • Perform static code analysis and open-source dependency scanning using SAST and SCA tools.
  • Analyze and prioritize security findings and work with development teams to drive remediation.
  • Integrate security scanning into CI/CD pipelines and automate security workflows.
  • Manage vulnerability lifecycle, reporting, and compliance metrics.
  • Promote secure coding practices and provide remediation guidance to engineering teams.
  • Support DevSecOps initiatives and shift-left security adoption.
Required Skills
  • 36+ years of experience in Application Security, DevSecOps, or Secure Software Development.
  • Hands-on experience with SAST tools such as Checkmarx, Fortify, Veracode, or CodeQL.
  • Experience with SCA tools such as Snyk, Black Duck, Mend (WhiteSource), Sonatype, or Dependabot.
  • Strong understanding of OWASP Top 10, secure coding practices, and vulnerability management.
  • Experience integrating security tools with GitHub, GitLab, Jenkins, or Azure DevOps.
  • Scripting knowledge in Python, Bash, or PowerShell.
  • Excellent communication and collaboration skills.
Preferred Qualifications
  • Experience with SBOM, container security, IaC security, or cloud-native application security.
  • Certifications such as CSSLP, GWAPT, or OSCP are a plus.
Why join Sonata Software

At Sonata, you'll have an outstanding opportunity. The chance to use your skills and imagination to push the boundaries of what's possible. To build never-seen before solutions to some of the world's toughest problems. You'll be challenged, but you will not be alone. You'll be joining a team of diverse innovators, all driven to go beyond the status quo to craft what comes next.

Equality and Diversity

Sonata Software is an Equal Opportunity Employer encouraging diversity in the workplace. All qualified applicants will receive consideration for employment without regard to race, national origin, gender identity, age, religion, disability, sexual orientation, veteran status, marital status, or any other characteristics protected by law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2coms • Bengaluru

On-site
INR 2,500,000 - 4,000,000
Senior Java Software Engineer
Senior Java Software Engineer

Sonata Software • Chennai District

On-site
INR 1,200,000 - 2,400,000
Equal Opportunity Employer
Software Security Engineer
Software Security Engineer

Axway • Dadri

On-site
INR 900,000 - 1,500,000
Solution Architect - PAAS
Solution Architect - PAAS

Sonata Software • Bengaluru

On-site
INR 3,000,000 - 6,000,000
Software Security Engineer
Software Security Engineer

74Software • Dadri

Hybrid
INR 900,000 - 1,500,000
M365 Apps and Services
M365 Apps and Services

Sonata Software • Bengaluru

On-site
INR 2,200,000 - 3,400,000
Solution Architect - PAAS
Solution Architect - PAAS

Sonata Software • Bengaluru Urban

On-site
INR 3,500,000 - 6,000,000
Entra ID Customer Engineer
Entra ID Customer Engineer

Sonata Software • Bengaluru

On-site
INR 2,500,000 - 5,000,000
Software Security Engineer II
Software Security Engineer II

SBS • Dadri

On-site
INR 1,200,000 - 1,800,000
Application Security Engineer (SAST/DAST)
Application Security Engineer (SAST/DAST)

Appit LLC • Hyderabad

On-site
INR 1,200,000 - 1,800,000
Flexible work arrangements
Career growth opportunities
Competitive salaries