Senior Application Security Engineer

Hyland

Hyderabad

Hybrid

INR 2,500,000 - 4,200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Hyland in Hyderabad, India, is seeking a Senior Application Security Engineer to embed security across the SDLC in a hybrid work model. You’ll work with developers to secure cloud-native architectures, automate security in CI/CD, and lead threat modeling and security assessments.

The role emphasizes AI security risks and secure coding guidance for rapid engineering velocity. You will mentor engineers, define secure coding standards, and shape tooling and processes to scale AppSec across cloud

Qualifications

  • 5+ years in application security or related role.
  • Hands-on security of cloud-native environments (AWS/GCP/Azure).
  • Experience integrating security into CI/CD pipelines (GitHub Actions, Jenkins).
  • Strong knowledge of OWASP Top 10 and common vulnerabilities.
  • Proficiency with AppSec tooling and secure coding guidance.

Responsibilities

  • Embed security across the SDLC with cloud-native and automated pipelines.
  • Design and maintain SAST, DAST, SCA, secrets detection, and container scanning gates.
  • Guide security posture for cloud-native environments across AWS, GCP, or Azure.
  • Lead threat modeling and perform app security assessments.
  • Triage and remediate findings from security testing and bug bounty programs.
  • Define secure coding standards and developer-facing security docs.
  • Advise on AI security best practices in development workflows.
  • Evaluate AppSec tooling to improve detection and feedback.
  • Respond to security incidents involving application layer issues.
  • Mentor engineers on security and AI-related risks.

Skills

Cloud-native security
CI/CD security
Threat modeling
Penetration testing
Security architecture
AI security

Tools

Checkmarx
Burp Suite
Trivy
Checkov
Veracode

Job description

Senior Application Security Engineer

Location: Hyderabad
Work Arrangement: Hybrid - 3 Days

About The Role

We’re looking for a Senior Application Security Engineer to help build and mature our application security program. You’ll be a hands‑on technical leader embedded across our engineering organization, working with developers to embed security into the SDLC, identifying and remediating vulnerabilities, and shaping the tools and processes that keep our products and customers safe. Deep expertise in securing cloud‑native architectures and automating security into CI/CD pipelines is essential, as security needs to scale with our engineering velocity. As AI‑powered development becomes a bigger part of how we build and ship software, you’ll also help engineers navigate the security challenges that come with it. This is a high‑impact, generalist AppSec role for someone equally comfortable reviewing threat models, triaging bug bounty reports, and writing secure coding guidance.

Your Role Responsibilities – Here’s What You’ll Do
  • Partner with engineering, product, and DevOps teams to integrate security practices throughout the software development lifecycle, with a strong focus on cloud‑native environments and automated pipelines.
  • Design, implement, and maintain security tooling and gates within CI/CD pipelines, covering SAST, DAST, SCA, secrets detection, and container scanning, so security feedback reaches developers early and automatically.
  • Collaborate with infrastructure and platform teams to help guide and improve the security posture of cloud‑native environments across AWS, GCP, or Azure, including containerized workloads, Kubernetes clusters, serverless functions, and managed services.
  • Lead and own the threat modeling process across product and engineering teams, conducting application security assessments including code review and manual penetration testing of applications.
  • Triage and remediate findings from SAST, DAST, SCA, and bug bounty programs; help engineering teams understand and fix vulnerabilities.
  • Define and maintain secure coding standards, security testing requirements, and developer‑facing security documentation.
  • Advise developers on AI security best practices, covering risks introduced by LLM integrations such as prompt injection, insecure output handling, and data leakage, as well as the secure use of AI coding assistants.
  • Evaluate and implement AppSec tooling to improve detection and developer feedback loops.
  • Respond to and investigate security incidents involving application‑layer issues.
  • Mentor engineers on security best practices, including emerging AI‑related risks, and serve as a trusted security advisor to product teams.
  • Contribute to security architecture reviews for new features and systems, including cloud‑native and AI/ML components.
Role Essentials – What You’ll Need
  • 5+ years of experience in application security, software security engineering, or a closely related role.
  • Hands‑on experience securing cloud‑native environments on AWS, GCP, or Azure, including containers, Kubernetes, IAM, and serverless architectures.
  • Proven experience integrating security into CI/CD pipelines (e.g., GitHub Actions, Jenkins) automating SAST, DAST, SCA, and secrets scanning.
  • Strong command of application security fundamentals: OWASP Top 10, secure design principles, and common vulnerability classes such as injection, auth flaws, and business logic issues.
  • Experience with security testing across applications.
  • Proficiency with AppSec tooling such as Checkmarx, Burp Suite, Trivy, Checkov, and Veracode.
  • Ability to read and reason about code in at least one of: Python, JavaScript/TypeScript, Java, Go, .NET (C#), or similar.
  • Strong written and verbal communication skills, with the ability to explain security risk to both technical and non‑technical audiences.
What We’d Like To See – Preferred Skills
  • Experience with infrastructure‑as‑code security (Terraform, CloudFormation, Helm) and policy‑as‑code frameworks such as OPA.
  • Familiarity with AI/LLM security risks including prompt injection, model abuse, and insecure integrations, as well as frameworks like the OWASP Top 10 for LLMs.
  • Experience securing AI‑assisted development workflows and reviewing AI‑generated code for security issues.
  • One or more relevant certifications: OSCP, CISSP, CEH, GWEB, CCSP, or equivalent.
  • Prior experience in a product‑led tech or SaaS environment.
Equal Opportunity Statement

Hyland is an equal opportunity employer. We value diversity and are committed to providing an inclusive workplace for all employees and applicants. Employment decisions are made without regard to any characteristic protected by applicable laws and regulations. Information collected during the hiring process is used solely to assess qualifications, verify identity, and comply with legal requirements.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Architect
Application Security Architect

Mettler-Toledo, Inc. • Bengaluru

Hybrid
INR 2,000,000 - 3,000,000
Hybrid working model
Family mediclaim benefits
Wide portfolio of training opportunities
+1
Application Security Engineer
Application Security Engineer

US Software Group Inc • Bengaluru

Hybrid
INR 9,033,000 - 11,744,000
Lead Software Security Architect (Cloud Security)
Lead Software Security Architect (Cloud Security)

Hyland • Hyderabad

Hybrid
INR 2,000,000 - 3,000,000
Senior Security Engineer - Applications Identity and Access Management
Senior Security Engineer - Applications Identity and Access Management

Swiss Re • Hyderabad

On-site
INR 1,200,000 - 1,800,000
Senior Manager - Application Security & AI Security
Senior Manager - Application Security & AI Security

Pine Labs • Dadri

On-site
INR 4,500,000 - 7,500,000
Lead Engineer - Cyber Security
Lead Engineer - Cyber Security

Mphasis • Bengaluru

On-site
INR 3,500,000 - 7,000,000
Lead Cyber Security Analyst
Lead Cyber Security Analyst

Hyland • Hyderabad

On-site
INR 1,500,000 - 2,500,000
Application Security Engineer
Application Security Engineer

Byline Learning Solutions • Pune District

On-site
INR 1,200,000 - 1,800,000
Senior Application Security Engineer
Senior Application Security Engineer

FloQast, Inc. • Pune District

On-site
INR 1,500,000 - 2,500,000
Application Security Engineer (6 Months Contract)
Application Security Engineer (6 Months Contract)

Weekday AI (YC W21) • Hyderabad

On-site
INR 1,500,000 - 2,000,000