Security QA Engineer – Application & Open-Source Security

StackNexus

Pune District

Hybrid

INR 1,200,000 - 1,800,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Opportunity to work on enterprise-scale cloud platforms
Direct exposure to security architecture
Strong focus on hands-on learning

Job summary

A leading technology company is seeking a skilled Security QA Engineer in Pune, India, to enhance application security initiatives. The ideal candidate will have over 5 years of experience in application security, with strong expertise in Software Composition Analysis tools like Black Duck. This role involves collaborating closely with Security Architects and DevSecOps teams, focusing on vulnerability triage and security tooling. The position offers a hybrid working model, allowing flexibility between office and remote work based on business needs.

Qualifications

  • 5+ years of experience in Application Security, Security QA, or Software Security.
  • Strong handson experience with Black Duck or equivalent SCA tools.
  • Good understanding of CI/CD pipelines and cloud platforms.

Responsibilities

  • Perform Software Composition Analysis (SCA) using tools like Black Duck.
  • Analyze and triage security findings based on severity.
  • Integrate SCA tools into CI/CD pipelines.

Skills

Application Security
Security QA
Software Composition Analysis
Vulnerability Triage
DevSecOps
Cloud Platforms (AWS, Azure, GCP)
Secure SDLC

Tools

Black Duck
GitHub
GitLab
Jenkins

Job description

Job Description: Security QA Engineer – Application & Open-Source Security (Pune India)

Function: Security Engineering / DevSecOps

Business Unit: VSP 360 – Data Services Division

Position: 2

Experience: 5–8 Years

Location: India (Hybrid/Remote – based on business needs)

Role Overview

We are looking for a Security QA Engineer with strong handson experience in Software Composition Analysis (SCA) tools such as Black Duck or similar to support application security initiatives within the VSP 360 Data Services platform. This role demands a blend of security testing, vulnerability triage, OSS compliance, and security tooling operations, working closely with Security Architects, DevSecOps, and Engineering teams in a cloudnative environment.

Key Responsibilities
Application & OSS Security Testing
  • Perform Software Composition Analysis (SCA) using Black Duck (or tools like CodeDx, JFrog Xray, FOSSA).
  • Identify opensource vulnerabilities, license risks, and dependency issues across applications.
  • Support release readiness and security QA validation for product deliveries.
Vulnerability Triage & Remediation Support
  • Analyze, triage, and categorize security findings based on severity, exploitability, and business risk.
  • Work with Security Architecture teams to validate findings, eliminate false positives, and define remediation approaches.
  • Track security findings to closure and support risk acceptance workflows where approved.
CI/CD & Tool Integration
  • Integrate SCA tools into CI/CD pipelines (Any one of experience: GitHub, GitLab, Azure DevOps, Jenkins).
  • Support configuration, tuning, and onboarding of new repositories and services into security tools.
  • Troubleshoot issues related to scanning failures, pipeline integrations, and agent setup.
Reporting & Security Governance
  • Generate security reports, dashboards, and metrics for internal stakeholders.
  • Maintain evidence for audits, internal security reviews, and compliance requirements.
  • Assist in improving security testing processes and standard operating procedures.
Collaboration & Enablement
  • Work closely with developers, QA, and platform teams to promote secure coding and dependency hygiene.
  • Provide guidance on vulnerability fixes and coordinate followups with engineering teams.
  • Participate in security reviews and continuous improvement initiatives.
Mandatory Skills & Experience
  • 5+ years of experience in Application Security, Security QA, or Software Security.
  • Strong handson experience with Black Duck, OSS SCA or equivalent SCA tools.
  • Proven experience in:
    • OSS vulnerability analysis and license compliance.
    • Vulnerability triage and remediation tracking.
    • Security reporting and metrics.
  • Good understanding of:
    • Secure SDLC and DevSecOps practices.
    • CI/CD pipelines.
    • Cloud platforms (AWS, Azure, or GCP).
Good to Have
  • Exposure to SAST/DAST tools (Fortify, Checkmarx, Veracode, SonarQube, etc.).
  • Experience with container and image scanning or Kubernetes security.
  • Familiarity with microservices and APIbased architectures.
  • Security certifications such as CEH, CSSLP, GWAPT, or equivalent (preferred, not mandatory).
Soft Skills
  • Strong analytical and problemsolving skills.
  • Good communication skills to work effectively with crossfunctional teams.
  • Ability to work independently and manage multiple security tasks.
Why Join Us
  • Opportunity to work on enterprisescale cloud platforms
  • Direct exposure to security architecture and DevSecOps practices
  • Strong focus on handson learning, ownership, and impact
Role Fitment
This Role Is Ideal For Candidates Who
  • Enjoy handson security testing and analysis
  • Are comfortable working between security architecture and engineering teams
  • Can independently manage security tooling and drive findings to closure
Business Hour
  • Normal Business hours. The expectation would be to start early to cover PST timezone or start late to cover EST time. Exception subject to manager permission.
Job Type
  • Hybrid Working: Minimum 2 days from office Tuesday and Thursday, but in case of business need and high demand, the manager may request to be present in the office on other days.
Location
  • Pune – Maharashtra – India
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2coms • Bengaluru

On-site
INR 2,500,000 - 4,000,000
Application Security Engineer
Application Security Engineer

Byline Learning Solutions • Pune District

On-site
INR 1,200,000 - 1,800,000
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2COMS Consulting Pvt. Ltd. • Bengaluru Urban

On-site
INR 1,500,000 - 2,100,000
Security Test Engineer(SAST, DAST, IAST,OWASP Top 10, SANS CWE Top 25) With South Africa based [...]
Security Test Engineer(SAST, DAST, IAST,OWASP Top 10, SANS CWE Top 25) With South Africa based [...]

Seventh Contact Hiring Solutions • Pune District

Hybrid
INR 1,400,000 - 2,000,000
Vapt Engineer
Vapt Engineer

Persistent Systems • Pune District

Hybrid
INR 1,200,000 - 2,200,000
Hybrid work arrangement
Long Service awards
Group term life insurance
+1
Application Security Engineer
Application Security Engineer

US Software Group Inc • Bengaluru

Hybrid
INR 9,033,000 - 11,744,000
SENIOR SOFTWARE ENGINEER - Application Security
SENIOR SOFTWARE ENGINEER - Application Security

Happiest Minds Technologies • Bengaluru

On-site
INR 1,700,000 - 2,100,000
QA & DevOps Engineer
QA & DevOps Engineer

Astika Software Technologies • Hyderabad

On-site
INR 2,500,000 - 3,800,000
SENIOR ENGINEER - Penetration Testing
SENIOR ENGINEER - Penetration Testing

Happiest Minds Technologies • Bengaluru

On-site
INR 1,100,000 - 1,700,000
Offensive Security Engineer
Offensive Security Engineer

Systems Plus • Pune District

On-site
INR 1,800,000 - 2,800,000