SENIOR SOFTWARE ENGINEER - Application Security

Happiest Minds Technologies

Bengaluru

On-site

INR 1,700,000 - 2,100,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Happiest Minds Technologies in Bengaluru, India is seeking an experienced Application Security Analyst to join our Vulnerability Operations Center. You will apply in-depth knowledge of vulnerability types, risk assessment and DevSecOps to strengthen secure development practices.

The role requires strong communication with cross‑functional teams, threat modeling, and manual/semi-automatic triage to improve triage efficiency and incident coordination across projects.

Qualifications

  • Bachelor's degree in Computer Science, Information Security, or a related field.
  • 5+ years of experience in application security or a related field.
  • Strong knowledge of security standards, CVSS scoring, MITRE ATT&CK.

Responsibilities

  • Understand vulnerability types (OWASP Top 10, CWE, CVE) and explain attack techniques.
  • Prioritize vulnerabilities based on exploitability and business impact.
  • Uplift DevSecOps vulnerability triage operations.
  • Perform triage of findings, assess severity and risks.
  • Collaborate with application teams, DevOps to communicate risks.
  • Automate triage workflows and tool integration.
  • Develop SOPs and knowledge base documentation.

Skills

Security standards
CVSS scoring
MITRE ATT&CK
Vulnerability assessment
Scripting languages
Automation
Stakeholder communication

Education

Bachelor's degree in Computer Science, Information Security, or related field

Tools

Vulnerability scanners
SAST/DAST tools
Automation platforms
Threat modeling tools

Job description

Application Security - Vulnerability Operations Center

Location: Bengaluru, India

Years of Experience: 5+ Years

Job Summary: We are seeking a skilled Application Security Analyst with a strong background in application security principles and practices. The ideal candidate will possess in-depth knowledge of vulnerability types, risk assessment, and DevSecOps processes. This role requires a proactive individual who can enhance our vulnerability triage operations and collaborate effectively with cross-functional teams to ensure secure application development.

Responsibilities
  • Possess a strong understanding of vulnerability types (OWASP Top 10, CWE, CVE, misconfiguration, insecure API) and clearly explain common attack techniques.
  • Demonstrate capability in vulnerability prioritization based on exploitability, asset criticality, and business context.
  • Uplift DevSecOps vulnerability triage operations to enhance effectiveness and efficiency.
  • Perform manual and semi-automated triage of vulnerability findings, providing expert judgment on severity, exploitability, and business impact.
  • Conduct false positive analysis, de-duplication, and tool output normalization.
  • Provide technical input during project releases to prepare triage readiness.
  • Identify and correlate recurring vulnerability data across projects or business units to observe trends and streamline triage processes.
  • Collaborate with application teams, DevOps, BISOs, and developers to explain vulnerabilities and risks clearly.
  • Participate in security tool PoC/PoV and selection processes.
  • Drive implementation and integration of selected tools into the triage workflow to enhance automation, data accuracy, and analyst efficiency.
  • Design and implement automation workflows for enrichment, de-duplication, and ticketing.
  • Contribute to strategic planning and continuous improvement of VOC capabilities.
  • Prepare documentation and reporting on knowledge base documentation and playbook creation, maintaining accurate records of analysis, risk decisions, and triage actions.
  • Provide guidance to developers and application teams on secure coding best practices.
Mandatory Skills
  • Strong knowledge of security standards, CVSS scoring, EPSS, CWE, CVE, KEV database, and MITRE ATT&CK.
  • Experience with CVSS tuning, exploit intelligence, and SLA tagging.
  • Familiarity with exploitation techniques, including SQL injection, XSS, CSRF, SSRF, and RCE.
  • Proficiency in one or more scripting languages (JavaScript, Python, PowerShell, Bash) and automation platforms.
  • Advanced knowledge of vulnerability assessment tools and threat modeling.
  • Strong analytical and communication skills, with excellent stakeholder communication and incident coordination abilities.
  • Ability to explain technical vulnerabilities clearly to developers and other stakeholders.
  • Critical thinking skills to trigger deep-rooted problem solving and multi-disciplinary analytical skills.
  • Effective technical writing and documentation skills for SOPs and evaluation reports.
Preferred Skills
  • Experience in a legacy environment with technical debt and internal challenges.
  • Positive mindset for growth and driving change.
Qualifications
  • Bachelor's degree in Computer Science, Information Security, or a related field.
  • 5+ years of experience in application security or a related field.

Application Security

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

TECHNICAL LEAD - Application Security
TECHNICAL LEAD - Application Security

Happiest Minds Technologies • Bengaluru

On-site
INR 3,500,000 - 6,000,000
SENIOR ENGINEER - Penetration Testing
SENIOR ENGINEER - Penetration Testing

Happiest Minds Technologies • Bengaluru

On-site
INR 1,100,000 - 1,700,000
Lead Engineer - Cyber Security
Lead Engineer - Cyber Security

Mphasis • Bengaluru

On-site
INR 3,500,000 - 7,000,000
Application Security Engineer
Application Security Engineer

Byline Learning Solutions • Pune District

On-site
INR 1,200,000 - 1,800,000
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2coms • Bengaluru

On-site
INR 2,500,000 - 4,000,000
Application Security Engineer
Application Security Engineer

US Software Group Inc • Bengaluru

Hybrid
INR 9,033,000 - 11,744,000
Application Security Manager
Application Security Manager

Coventine Digital • Chennai District, Bengaluru, Pune District

On-site
INR 3,000,000 - 6,000,000
Application Security Engineer
Application Security Engineer

Cynosure Corporate Solutions • Chennai District

On-site
INR 1,500,000 - 2,500,000
CYBER security Analyst
CYBER security Analyst

Cortex Consultants LLC • Chennai

On-site
INR 1,200,000 - 1,800,000
Application Security Engineer
Application Security Engineer

Basebiz • Pune District

On-site
INR 1,800,000 - 3,000,000