Senior Application Security Engineer

Lever, Inc.

India

Remote

INR 2,000,000 - 4,200,000

Full time

37 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Remote working India
Senior ownership
Global collaboration
Professional development
Health & wellbeing

Job summary

Lever, Inc. partner is seeking a Senior Application Security Engineer in India to strengthen security across the full SDLC. You will lead threat modeling, define security requirements, and drive secure coding with engineers.

You will own tooling for static/dynamic testing and supply‑chain security, and influence product security decisions across multiple lines. The role is hands‑on, globally distributed, and focused on measurable security improvements, with opportunity to shape security

Qualifications

  • 6+ years in software engineering or security with 3+ in app security.
  • Hands-on security across SDLC for products deployed in customer environments.
  • Strong coding in C#/.NET and enough Java to review Java apps.
  • Experience with AI-assisted development or AI-enabled security tooling.
  • Ability to communicate risks clearly to technical and non-technical stakeholders.

Responsibilities

  • Lead threat modeling for authentication, session management, and integrations.
  • Define security requirements early in architecture and development.
  • Lead vulnerability triage, remediation, and disclosure processes.
  • Review code and implement security fixes with development teams.
  • Own and improve SAST, DAST, and dependency scanning programs.
  • Promote secure coding across large C#/.NET and Java codebases.
  • Oversee SBOM generation and software provenance documentation.

Skills

C#/.NET
Java
Threat modeling
Security tooling
AI-assisted security
Code review

Tools

SAST tools
DAST tools
SBOM tooling

Job description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Application Security Engineer based in India.

This is a senior individual contributor role embedded directly within product engineering and focused on strengthening security throughout the software development lifecycle. You will help secure enterprise products that are deployed across customer-managed environments as well as hosted offerings. The role combines threat modeling, secure coding, vulnerability management, security testing, and software supply‑chain security. You will work directly with engineers and product leaders to identify risks early and turn security requirements into practical, scalable solutions. Your work will influence what gets designed, developed, tested, released, and ultimately deployed by customers. The environment is technically hands‑on, globally distributed, and focused on measurable security improvements rather than simply identifying issues. This is an opportunity to shape application security practices across multiple product lines while remaining close to production code and engineering teams.


Accountabilities
  • Lead threat modeling for critical application areas, including authentication and session management, privilege escalation, integrations, tenant isolation, cryptography, and secrets management.
  • Define security requirements early in the architecture and development process, working directly with engineering teams to address risks before release.
  • Assess security risks and provide clear recommendations to product and engineering leadership to support informed release and risk-acceptance decisions.
  • Contribute directly to product repositories by reviewing and implementing security fixes, dependency updates, and code‑level remediation in collaboration with development teams.
  • Own and improve static application security testing, dynamic testing, dependency scanning, and related security tooling across product lines.
  • Tune security tools to improve signal quality, reduce unnecessary disruption, and ensure findings reach the teams responsible for remediation.
  • Promote secure coding practices across large C#/.NET and Java codebases through reusable patterns, libraries, reference implementations, and targeted code reviews.
  • Establish appropriate security review practices for AI‑assisted software development, including assessment of AI‑generated code and automated remediation workflows.
  • Lead product vulnerability response from intake through triage, remediation, coordinated disclosure, CVE management and customer‑facing security advisories.
  • Analyze penetration‑testing and bug‑bounty findings to identify recurring weaknesses and implement systemic controls that prevent similar vulnerabilities.
  • Own software composition analysis and SBOM generation, including software provenance and licensing information required by customers and internal stakeholders.
  • Maintain security evidence that can support customer questionnaires, security reviews, certifications, and other assurance activities.
  • Collaborate with engineering, product, legal, and other stakeholders to continuously strengthen application security across the product portfolio.
Requirements
  • 6+ years of experience in software engineering or security, including at least 3 years focused on application or product security; equivalent professional depth may be considered.
  • Demonstrated application security experience with products that customers deploy and operate within their own environments.
  • Strong production‑level programming skills in C# and .NET, with sufficient experience in Java to review and contribute to Java‑based applications.
  • Recent hands‑on experience with AI‑assisted development or AI‑enabled security tooling, ideally within the last six months.
  • Strong understanding of threat modeling and the ability to collaborate with engineering teams during the design stage.
  • Experience with static analysis, dynamic application testing, software composition analysis, dependency scanning, and security tooling optimization.
  • Knowledge of identity and authentication technologies and protocols such as OAuth, OIDC, SAML, and SCIM.
  • Experience with coordinated vulnerability disclosure, vulnerability triage, CVE processes, and customer‑facing security advisories.
  • Strong secure code review capabilities across web applications and APIs.
  • Understanding of software supply‑chain security, SBOM standards, dependency management, and license compliance.
  • Experience with cryptographic reviews, security champion programs, PCI DSS, FedRAMP, or similar security frameworks is advantageous.
  • Ability to communicate complex security risks clearly to technical and non‑technical stakeholders and influence senior engineers effectively.
  • Strong analytical …
  • Prior experience as a product or software engineer is a plus.
Benefits
  • Remote working opportunity based in India.
  • Senior-level ownership across multiple product lines and application security initiatives.
  • Direct collaboration with engineering and product leadership.
  • Opportunity to influence security architecture, secure development practices, and vulnerability management at scale.
  • Hands‑on exposure to modern application security, AI‑assisted development, software supply‑chain security, and cloud-hosted products.
  • Globally distributed and collaborative working environment.
  • Opportunities for professional development, learning, and career growth.
  • Employee-focused health and wellbeing programs.
  • Inclusive and equal‑opportunity workplace committed to diversity and respect.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application security
Application security

Codincity Digital Technologies • Chennai District

On-site
INR 3,500,000 - 5,500,000
Senior Application Security Engineer
Senior Application Security Engineer

Hyland • Hyderabad

On-site
INR 2,500,000 - 4,200,000
Application Security Engineer
Application Security Engineer

US Software Group Inc • Bengaluru

On-site
INR 9,033,424 - 11,743,451
Principal Security Engineer Cloud and Infrastructure Security
Principal Security Engineer Cloud and Infrastructure Security

Lever, Inc. • India

Remote
INR 4,000,000 - 8,000,000
Remote working in India
Direct visibility with leadership
Career growth & professional dev
Application Security Analyst – Java / DevSecOps
Application Security Analyst – Java / DevSecOps

Hireflex247 India Private Limited • India

On-site
INR 1,500,000 - 2,700,000
Application Security Engineer
Application Security Engineer

Greenlight Planet Inc. • India

On-site
USD 12,000 - 19,000
Senior Application Security Engineer
Senior Application Security Engineer

Tenarai • Bengaluru

On-site
INR 2,500,000 - 4,200,000
Senior Application Security / Product Security Engineer Cybersecurity & Networking Practice Mum[...]
Senior Application Security / Product Security Engineer Cybersecurity & Networking Practice Mum[...]

Galaxy Office Automation Pvt. Ltd. • Mumbai

On-site
INR 4,000,000 - 7,000,000
Lead Engineer, Information Security
Lead Engineer, Information Security

Lever, Inc. • India

Remote
INR 1,500,000 - 2,200,000
Fully remote within India
Senior technical ownership
Exposure to enterprise SIEM/EDR/cloud
+3
Senior Security Research Engineer
Senior Security Research Engineer

Jobgether • India

On-site
INR 1,200,000 - 1,800,000
Competitive salary
Fully remote work
Open vacation policy
+3