Security/SAST/DAST/SCA

Heptarc

Bengaluru

On-site

INR 3,500,000 - 5,500,000

Part time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Heptarc is seeking an experienced Senior Application Security Engineer for a contract role in India, with onsite work in Bengaluru or Hyderabad. You will lead SAST/DAST/SCA scans, interpret CVEs/CWEs, and coordinate with development teams to cover all code branches in compiled binaries.

You should have 8+ years in IT, 7+ years in application security, and strong knowledge of OWASP Top 10 and ASVS. Proficiency with Veracode or AppScan is required. Excellent communication is essential.

Qualifications

  • 8+ years of IT experience
  • 7+ years of application security
  • 5+ years of Application Security testing experience
  • Bachelor's degree required
  • Familiarity with OWASP Top 10 and ASVS
  • Understanding of SAST/DAST/SCA scanning
  • Experience with Veracode, AppScan or similar tools
  • Ability to interpret CVEs and CWEs
  • Knowledge of secret management systems
  • Strong documentation and communication skills

Responsibilities

  • Perform SAST/SCA/DAST scans using industry vulnerability scanners
  • Configure Veracode or AppScan for static and CVE/CWE scanning
  • Coordinate with app owners to include all code branches in compiled binaries
  • Conduct crawling and DAST scans to identify dynamic issues
  • Collaborate with teams to improve security posture and documentation

Skills

IT experience
Application security
Application security testing
OWASP ASVS
SAST/DAST/SCA
CWE/CVE interpretation
Secret management
Front-end/back-end knowledge
Documentation
Team collaboration
Communication skills

Education

Bachelor's degree

Tools

Veracode
AppScan
SAST tools
DAST tools
Secret management systems

Job description

Experience-8+ years Job Type-Contract with client Location-Hyderabad/Bangalore

Job Description-
Roles and Responsibilities:
  • Perform SAST/SCA/DAST scans using industry vulnerability scanner
  • SAST/SCA - Veracode, using supplied compiled binary, configure scan platform to correct scan for both static code CWE's as well as SCA derived CVEs. Work will include coordination with app owner to ensure all branches of code are included in compiled binary file.
  • DAST - Work begins with crawling the target application to identify existing directory and file structure. Once identified, execute DAST scan using HCL product to identify dynamic issue only visible during code execution.
Primary / Mandatory skills:
  • Overall - 8+ years of IT experience
  • 7+ years of application security Experience
  • 5+ years of Application Security testing Experience
  • Bachelor's degree required.
  • Deep familiarity with the OWASP Top 10 and other security concerns for web applications
  • Deep Understanding of OWASP Application Security Verification Standards (ASVS)
  • Deep understanding of SAST, DAST, SCA Scanning practices
  • Experience in scanning leveraging Veracode, Appscan.or other enterprise tools.
  • Understand how to interpret and assess CVEs (Common Vulnerability and Exposures) and CWEs (Common Weakness Enumeration) as found by scanning tools.
  • Understanding of SAST, DAST tools and dependency scanning tools
  • Experience working/integrating with secret management systems.
  • Advanced knowledge of front-end and back-end web application development in at least one technology stack (.NET, Java, PHP, Ruby/Rails, Angular, Node.js, etc.)
  • Track record of staying current with trends, techniques, tools, and processes that drive improvement of security posture of applications.
  • Strong documentation skills
  • Excellent verbal and written communication skills, with proven technical writing abilities (English language proficiency required)
  • Team-oriented thinking with demonstrated ability to produce high-quality work as part of a fast-paced, dynamic team.
  • Proven ability to communicate, collaborate, and present effectively with teams and individuals in different disciplines or areas.
Technical Skills:

SAST, DAST, SCA

Must have skills:

Application Security/SAST/DAST/SCA

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security / SAST / DAST / SCA Professional
Security / SAST / DAST / SCA Professional

Heptarc • Bengaluru

On-site
INR 2,500,000 - 3,800,000
Application Security Consultant
Application Security Consultant

Heptarc • Hyderabad

On-site
INR 1,200,000 - 1,800,000
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2COMS Consulting Pvt. Ltd. • Bengaluru Urban

On-site
INR 1,500,000 - 2,100,000
Application Security Testing Consultant with SAST and DAST
Application Security Testing Consultant with SAST and DAST

Cloudxtreme • Hyderabad, Pune District, Bengaluru

On-site
INR 1,200,000 - 1,800,000
Application Security Engineer
Application Security Engineer

Cloudxtreme • Hyderabad

On-site
INR 1,400,000 - 2,600,000
Application Security Engineer (SAST / DAST / DevSecOps / SCA)
Application Security Engineer (SAST / DAST / DevSecOps / SCA)

Qualizeal India • Hyderabad

On-site
INR 1,200,000 - 1,800,000
Application Security Consultant
Application Security Consultant

ERM Placement Services • Delhi

On-site
INR 1,200,000 - 1,800,000
Application Security Consultant
Application Security Consultant

ERM Placement Services • Kolkata District

On-site
INR 2,800,000 - 4,000,000
Dynamic application security Engineer
Dynamic application security Engineer

Cloudxtreme • Hyderabad, Chennai District, Bengaluru

Hybrid
INR 1,200,000 - 2,400,000
Hybrid work model
Security Testing Engineer
Security Testing Engineer

Talent21 Management and Shared Services Pvt Ltd • Chennai District

On-site
INR 900,000 - 1,500,000