Senior Application Security Engineer

FloQast, Inc.

Pune District

On-site

INR 1,500,000 - 2,500,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A leading software company in Pune District is looking for a Senior Application Security Engineer to help drive the 'Security by Design' philosophy across their product suite. Responsibilities include leading the implementation of security standards, managing vulnerabilities, and mentoring development teams. The ideal candidate should have over 6 years of experience in software engineering or application security, a strong development background, and expertise in threat modeling. The role emphasizes proactive security measures in software development.

Qualifications

  • 6+ years in software engineering or application security, with experience as a subject matter expert.
  • Strong background in software development, capable of reading/writing/debugging code in multiple languages.
  • Proven ability to lead complex technical projects and cross-functional initiatives.

Responsibilities

  • Contribute to the strategic AppSec roadmap and implement Secure Software Development Lifecycle.
  • Lead architectural reviews and threat modeling sessions for high-risk features.
  • Manage critical software vulnerabilities and drive automated remediation workflows.
  • Design security libraries and ensure the effective selection and tuning of AppSec tooling.
  • Serve as a core security expert and mentor junior engineers on secure practices.

Skills

Application Security Expertise
Threat Modeling
Software Development
Vulnerability Management
Technical Project Leadership
Identity Protocols

Tools

Snyk
Checkmarx
Burp Suite
Semgrep

Job description

We are seeking a highly skilled Senior Application Security Engineer to serve as a Subject Matter Expert and expert technical contributor within our security team. This role is focused on driving the hands‑on integration of the "Security by Design" philosophy across our product suite, ensuring our applications are resilient against modern threats. You will leverage deep technical expertise in software exploitation and defensive architecture to set secure standards, lead complex security projects, and mentor development teams on secure coding practices. The ideal candidate contributes significantly to technical strategy and architecture, focusing on building sustainable solutions that prevent security issues at scale.

Key Responsibilities
  • Application Security Strategy & Execution: Contribute to the strategic AppSec roadmap and lead the implementation of the Secure Software Development Lifecycle (SSDLC) and security standards for all software products.
  • Security Architecture & Design: Lead deep‑dive architectural reviews and hands‑on threat modeling sessions for high‑stakes product features. Define and implement secure development patterns (Authentication, Authorization, Encryption) for engineering teams to adopt.
  • Vulnerability Management & Triage: Lead the response to critical software vulnerabilities, contribute to managing the Bug Bounty program, and drive automated workflows for prioritizing remediation based on exploitability and business risk.
  • Secure Frameworks & Tooling: Design and implement internal security libraries and "paved roads" that allow developers to build securely by default. Oversee the selection, implementation, and tuning of AppSec tooling (SAST, DAST, SCA) to ensure high signal‑to‑noise ratios.
  • Cross‑Functional Technical Leadership: Serve as a core security subject matter expert for the Engineering organization. Lead technical initiatives to remediate security debt and mentor junior security engineers on advanced application defense.
  • Modern Web & API Security: Apply expert‑level knowledge of REST/GraphQL APIs, OAuth2/OIDC, and modern web frameworks to harden the application layer against sophisticated attacks.
  • Incident Response (App Layer): Serve as a key technical responder for application‑level security incidents, conducting forensic analysis of code execution and logic flaws to prevent recurrence.
  • Evangelism & Training: Lead technical developer workshops and contribute to the "Security Champions" program to elevate security awareness and secure‑coding practices across the engineering organization.
Required Qualifications
  • 6+ years of experience in software engineering or application security, with significant tenure as a subject matter expert.
  • Software Engineering Foundation: Strong background as a professional software developer, with the ability to read, write, and debug code in multiple languages (e.g., Python, Go, Java, or JavaScript/TypeScript).
  • Expert Threat Modeling: Proven ability to threat model complex, distributed systems and identify logic flaws that automated tools miss.
  • Deep Vulnerability Expertise: Demonstrated mastery of identifying and mitigating the OWASP Top 10, business logic vulnerabilities, and advanced exploitation vectors.
  • Tooling Mastery: Extensive experience implementing and customizing AppSec tools (e.g., Snyk, Checkmarx, Burp Suite, Semgrep) within enterprise‑scale CI/CD environments (GitHub Actions, GitLab, etc.).
  • Identity & Access Expert: Deep technical understanding of identity protocols (SAML, OAuth2, OIDC) and modern authorization models (RBAC, ABAC).
  • Technical Project Leadership: Proven ability to lead complex technical projects and drive large‑scale, cross‑functional AppSec initiatives to completion.
Preferred Qualifications
  • Certifications: OSCP, OSWA, OSWE, or Burp Suite Certified Practitioner (BSCP).
  • Programming: Strong programming skills in NodeJS, Python, and/or Go.
  • Cloud Fluency: Experience securing applications specifically within AWS environments (Lambda, ECS/EKS, DynamoDB security).
  • Compliance: Familiarity with mapping technical application controls to compliance frameworks like SOC 2, HIPAA, or PCI‑DSS.

FloQast, Inc is committed to operating fair and unbiased recruitment procedures allowing all applicants an equal opportunity for employment, free from discrimination on the basis of religion, race, sex, age, sexual orientation, disability, color, ethnic or national origin, or any other classification as may be protected by applicable law. We aim to recruit the right people for the jobs we have to offer, and to assess applications on the basis of relevant skills, education, and experience. We welcome people of different backgrounds, experiences, abilities, and perspectives. We are an equal opportunity employer and strive to provide a professional and welcoming workplace for all employees.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

DigiCert • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Generous time off policies
Top shelf benefits
Education, wellness, and lifestyle support
Application Security Architect
Application Security Architect

Mettler-Toledo, Inc. • Bengaluru

Hybrid
INR 2,000,000 - 3,000,000
Hybrid working model
Family mediclaim benefits
Wide portfolio of training opportunities
+1
Senior Manager - Application Security & AI Security
Senior Manager - Application Security & AI Security

Pine Labs • Dadri

On-site
INR 4,500,000 - 7,500,000
Application Security
Application Security

Airtel • India

On-site
INR 1,200,000 - 2,400,000
Security-focused culture
Specialist, Application Security
Specialist, Application Security

Pearson • Bengaluru

On-site
INR 1,800,000 - 2,800,000
Lead Engineer - Cyber Security
Lead Engineer - Cyber Security

Mphasis • Bengaluru

On-site
INR 3,500,000 - 7,000,000
Application Security Specialist
Application Security Specialist

Pearson India Education Services Pvt Ltd • Bengaluru

On-site
INR 1,800,000 - 3,200,000
Senior Application Security Engineer
Senior Application Security Engineer

First Advantage • India

On-site
INR 1,500,000 - 2,500,000
System Security
System Security

Bigship • Dadri

On-site
INR 8,000,000 - 12,000,000
Application Security Lead | Offshore
Application Security Lead | Offshore

Photon • Hyderabad

On-site
INR 850,000 - 1,800,000