SENIOR SOFTWARE ENGINEER - Application Security

Happiest Minds Technologies

Bengaluru

On-site

INR 1,200,000 - 1,800,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Happiest Minds Technologies in Bengaluru, India, is seeking an Application Security Analyst with a strong background in vulnerability management, risk assessment, and secure development practices. You will enhance our vulnerability triage operations and work with cross‑functional teams to ensure secure application delivery.

The ideal candidate has 5+ years of experience, deep knowledge of OWASP Top 10, CVE/S, CWE, and MITRE ATT&CK, plus scripting and automation skills to design scalable triage

Qualifications

  • Strong knowledge of security standards, CVSS, EPSS, CWE/CVE, and MITRE ATT&CK.
  • Experience with CVSS tuning, exploit intelligence, and SLA tagging.
  • Familiarity with exploitation techniques (SQLi, XSS, CSRF, SSRF, RCE).
  • Proficiency in scripting languages (JavaScript, Python, PowerShell, Bash) and automation.
  • Analytical mindset with excellent communication and incident coordination.

Responsibilities

  • Understand vulnerability types and explain attack techniques clearly.
  • Prioritize vulnerabilities by exploitability and business context.
  • Uplift DevSecOps vulnerability triage operations.
  • Perform manual and semi-automated triage of findings and assess severity.
  • Conduct false positive analysis, de-duplication, and tool output normalization.
  • Provide technical input during project releases for triage readiness.
  • Identify recurring vulnerability data to observe trends and streamline triage.
  • Collaborate with application teams, DevOps, BISOs, and developers.
  • Participate in security tool PoC/PoV and tool selection processes.
  • Drive integration of tools into triage workflow and automation.
  • Design automation workflows for enrichment, de-duplication, and ticketing.
  • Contribute to VOC capability improvements and playbooks.
  • Prepare documentation and SOPs for risk decisions and triage actions.
  • Guide developers on secure coding best practices.

Skills

CVSS scoring
MITRE ATT&CK
CWE
CVE
EPSS
Threat modeling
Python
Automation
Communication
Documentation

Education

Bachelor's degree in Computer Science, Information Security, or related field

Tools

SAST tools
DAST tools
Threat modeling tools
Automation platforms

Job description

Application Security - Vulnerability Operations Center
Location: Bengaluru, India
Years of Experience: 5+ Years
Job Summary

We are seeking a skilled Application Security Analyst with a strong background in application security principles and practices. The ideal candidate will possess in-depth knowledge of vulnerability types, risk assessment, and DevSecOps processes. This role requires a proactive individual who can enhance our vulnerability triage operations and collaborate effectively with cross-functional teams to ensure secure application development.

Responsibilities
  • Possess a strong understanding of vulnerability types (OWASP Top 10, CWE, CVE, misconfiguration, insecure API) and clearly explain common attack techniques.
  • Demonstrate capability in vulnerability prioritization based on exploitability, asset criticality, and business context.
  • Uplift DevSecOps vulnerability triage operations to enhance effectiveness and efficiency.
  • Perform manual and semi-automated triage of vulnerability findings, providing expert judgment on severity, exploitability, and business impact.
  • Conduct false positive analysis, de-duplication, and tool output normalization.
  • Provide technical input during project releases to prepare triage readiness.
  • Identify and correlate recurring vulnerability data across projects or business units to observe trends and streamline triage processes.
  • Collaborate with application teams, DevOps, BISOs, and developers to explain vulnerabilities and risks clearly.
  • Participate in security tool PoC/PoV and selection processes.
  • Drive implementation and integration of selected tools into the triage workflow to enhance automation, data accuracy, and analyst efficiency.
  • Design and implement automation workflows for enrichment, de-duplication, and ticketing.
  • Contribute to strategic planning and continuous improvement of VOC capabilities.
  • Prepare documentation and reporting on knowledge base documentation and playbook creation, maintaining accurate records of analysis, risk decisions, and triage actions.
  • Provide guidance to developers and application teams on secure coding best practices.
Mandatory Skills
  • Strong knowledge of security standards, CVSS scoring, EPSS, CWE, CVE, KEV database, and MITRE ATTCK.
  • Experience with CVSS tuning, exploit intelligence, and SLA tagging.
  • Familiarity with exploitation techniques, including SQL injection, XSS, CSRF, SSRF, and RCE.
  • Proficiency in one or more scripting languages (JavaScript, Python, PowerShell, Bash) and automation platforms.
  • Advanced knowledge of vulnerability assessment tools and threat modeling.
  • Strong analytical and communication skills, with excellent stakeholder communication and incident coordination abilities.
  • Ability to explain technical vulnerabilities clearly to developers and other stakeholders.
  • Critical thinking skills to trigger deep-rooted problem solving and multi-disciplinary analytical skills.
  • Effective technical writing and documentation skills for SOPs and evaluation reports.
Preferred Skills
  • Experience in a legacy environment with technical debt and internal challenges.
  • Positive mindset for growth and driving change.
Qualifications
  • Bachelors degree in Computer Science, Information Security, or a related field.
  • 5+ years of experience in application security or a related field.

Disclaimer: This job description has been sourced from a public domain and may have been modified by Naukri.com to improve clarity for our users. We encourage job seekers to verify all details directly with the employer via their official channels before applying.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SENIOR ENGINEER - Penetration Testing
SENIOR ENGINEER - Penetration Testing

Happiest Minds Technologies • Bengaluru

On-site
INR 1,100,000 - 1,700,000
Lead Engineer - Cyber Security
Lead Engineer - Cyber Security

Mphasis • Bengaluru

On-site
INR 3,500,000 - 7,000,000
Application Security Engineer
Application Security Engineer

US Software Group Inc • Bengaluru

Hybrid
INR 9,033,000 - 11,744,000
Application Security Consultant
Application Security Consultant

ERM Placement Services • Gurugram District

On-site
INR 1,800,000 - 2,700,000
Application Security Consultant
Application Security Consultant

ERM Placement Services • Lucknow

On-site
INR 1,400,000 - 2,100,000
Application Security Consultant
Application Security Consultant

ERM Placement Services • New Delhi

On-site
INR 1,500,000 - 2,500,000
Application Security Consultant
Application Security Consultant

ERM Placement Services • Ernakulam

On-site
INR 1,800,000 - 2,400,000
Application Security Consultant
Application Security Consultant

ERM Placement Services • Jaipur

On-site
INR 1,200,000 - 1,800,000
Application Security Consultant
Application Security Consultant

ERM Placement Services • Surat

On-site
INR 1,600,000 - 2,800,000
Application Security Consultant
Application Security Consultant

ERM Placement Services • Coimbatore District

On-site
INR 2,500,000 - 4,200,000