Senior Application Security Engineer

Employ

Bengaluru

On-site

INR 1,000,000 - 1,500,000

Part time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A leading IT consulting firm in Bengaluru is looking for an Application Security Engineer specializing in code remediation. The ideal candidate will have 4-8 years of experience, focusing on identifying and fixing security vulnerabilities across languages. Responsibilities include analyzing security reports, remediating OWASP Top 10 issues, and mentoring junior developers. This is a contract role for 3 months, offering the potential for extension, and requires a deep understanding of secure coding practices.

Qualifications

  • 4–8 years of experience in application development, with 2 years focusing on security code remediation.
  • Experience in analyzing and fixing vulnerabilities across various programming languages.
  • Strong collaboration skills with security, QA, and development teams.

Responsibilities

  • Analyze vulnerability reports and implement strategies.
  • Perform hands-on code remediation for OWASP Top 10 issues.
  • Refactor SQL queries to prevent injections.
  • Document remediation actions and accept risks.
  • Mentor junior developers in secure practices.

Skills

Understanding of OWASP Top 10
Experience with SAST and DAST tools
IIS and SQL Server security
Secure SQL queries
Secure SDLC and CI/CD pipelines

Tools

Fortify
Veracode
Burp Suite

Job description

Job Title: Application Security Engineer – Code Remediation

Experience - 5-8 years

Employment Type - Contract (3 months with possibility of further extension)

About the Role: We are seeking a highly skilled Application Security Engineer – Code Remediation to join our client’s growing team. This role is focused on analyzing, identifying, and remediating security vulnerabilities in both legacy and modern applications. You will work closely with development, QA, and security teams to ensure enterprise-grade security hygiene in all application codebases.

If you're passionate about writing secure code, eliminating OWASP Top 10 vulnerabilities, and securing systems end-to-end, we’d love to speak with you.

Key Responsibilities
  • Analyse security vulnerability reports (SAST, DAST, penetration tests) and implement remediation strategies across Classic ASP, ASP.NET (C#), Perl, Java.
  • Perform hands‑on code remediation for OWASP Top 10 issues, such as:
    • SQL Injection
    • Cross‑Site Scripting (XSS)
    • Cross‑Site Request Forgery (CSRF)
    • Insecure Direct Object References
    • and more
  • Refactor insecure SQL queries to prevent injection and enforce database‑layer security.
  • Configure and harden IIS servers:
    • Apply security headers
    • Enforce HTTPS
    • Disable insecure modules
  • Secure SQL Server configurations and eliminate insecure deployment patterns.
  • Collaborate with developers to introduce and enforce secure coding standards.
  • Validate fixes through static/dynamic scanning and manual security validation.
  • Document all remediation actions, accepted risks, and security changes thoroughly.
  • Assist in threat modelling and risk assessments for both legacy and modern applications.
  • Mentor junior developers and share best practices in secure software development.
Key Skills & Technologies
  • Deep understanding of OWASP Top 10 and secure coding principles
  • Experience with static and dynamic application security testing tools (Fortify, Veracode, Burp Suite, etc.)
  • Strong understanding of IIS and SQL Server security configurations
  • Proficient in writing secure, parameterised SQL queries
  • Familiarity with secure SDLC and CI/CD pipelines (optional but preferred)
Ideal Candidate Profile
  • 4–8 years of experience in application development with at least 2 years in security‑focused code remediation
  • Proven experience in analysing, fixing, and testing vulnerabilities across different languages
  • Strong ability to collaborate across security, QA, and development teams
  • Excellent problem‑solving skills and attention to detail
  • Industry certifications (preferred): OSCP, CEH, CSSLP, GWAPT, or equivalent
Seniority Level

Mid‑Senior level

Employment Type

Contract

Job Function

IT Services and IT Consulting, Hospitals and Health Care, and Software Development

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer (Code & Refactoring Specialist)
Application Security Engineer (Code & Refactoring Specialist)

Codvo.ai • Hyderabad

On-site
INR 1,000,000 - 1,800,000
Application Security
Application Security

Airtel • India

On-site
INR 1,200,000 - 2,400,000
Security-focused culture
Application Security Engineer
Application Security Engineer

DigiCert • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Generous time off policies
Top shelf benefits
Education, wellness, and lifestyle support
Senior Application Security Engineer
Senior Application Security Engineer

FloQast, Inc. • Pune District

On-site
INR 1,500,000 - 2,500,000
Application Security Specialist
Application Security Specialist

Pearson India Education Services Pvt Ltd • Bengaluru

On-site
INR 1,800,000 - 3,200,000
Application Security Engineer (Code & Refactoring Specialist)
Application Security Engineer (Code & Refactoring Specialist)

Codvo Private Limited • Hyderabad

Hybrid
INR 1,200,000 - 1,800,000
Security Expert (Application / Web Security) (Min 5 Years)
Security Expert (Application / Web Security) (Min 5 Years)

AagatiServe Pvt Ltd • India

On-site
INR 1,000,000 - 1,500,000
Senior Vulnerability Management Engineer
Senior Vulnerability Management Engineer

LSEG • Bengaluru

On-site
INR 1,200,000 - 1,800,000
System Security
System Security

BigShip Technologies Pvt. Ltd • Dadri

On-site
INR 1,000,000 - 1,500,000
Application Security Engineer
Application Security Engineer

Security Lit • Mumbai

On-site
INR 900,000 - 1,200,000