Staff Engineer - Application Security

UST

Bengaluru

On-site

INR 2,400,000 - 4,200,000

Full time

42 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

UST is seeking a senior Application Security Engineer to conduct comprehensive security testing, coordinate cross-functional teams, and guide developers on secure coding practices. The role emphasizes SAST/DAST/SCA, threat modeling, and DevSecOps integrations within a large enterprise environment.

The ideal candidate will have 10–12 years in IT with 5+ years in application security, strong cloud security knowledge, and a hands-on approach to AI-driven security automation.

Qualifications

  • 10-12 years IT experience with 5+ years in application security.
  • 1- Strong knowledge of OWASP, web/mobile/API security.

Responsibilities

  • Conduct thorough application security penetration tests.

Skills

Threat Modeling
DevSecOps
Cloud Security
Penetration Testing
AI/Automation in security

Education

Bachelor's degree in CS/IT
Advanced degree preferred
Security certifications (GWAPT/GWEB/GPEN/OSCP/CSSLP)

Tools

SAST
DAST
SCA

Job description

Role Description

Conduct application security testing in order to comply with corporate policies, and regulatory requirements. Coordinate and execute application security tests, communicate the results to relevant stakeholders, and help application developers understand how to fix code security issues.

Responsibilities
  • Conduct thorough application security penetration tests
  • Work effectively with a cross-functional team to plan, execute, and communicate findings from application security testing
  • Work with application owners to improve their knowledge and practical application of information security best practices, including but not limited to threat assessment, vulnerability prevention and secure coding practices.
  • Partner with DevOps team to ensure application security tools such as SAST and DAST are performing well and generating accurate testing results.
  • Flexibility to change direction and manage conflicting demands.
Experience
  • 10 -12 years progressive Information Technology experience or equivalent specialized skills with 5+ years of application security experience.
  • Experience in running & administrating static analysis (SAST), dynamic analysis (DAST), and Software Composition Analysis (SCA) tools and processes
  • Experience in conducting and training application penetration testing
  • Experience in Cloud Security.
  • Experience and strong understanding of DevSecOps processes, tools, and integrations.
Qualifications
  • Strong knowledge and ability to work with DevOps teams on the processes and integrations.
  • Strong web application security knowledge with thorough understanding of web, mobile, and API testing Knowledge of application security architecture and ability to perform threat modeling and risk assessments on identified applications.
  • Knowledge of DevSecOps processes and ability to work with the stakeholders to deliver the results for security integrations in DevOps.
  • Development background in .Net, Java, and/or Python a plus
  • Strong knowledge of Security Standards, frameworks and groups (OWASP, WASC, OSSTMM)
  • Knowledge of the software development lifecycle under agile environment in a large enterprise
  • Knowledge of database, application and Web server design
  • Knowledge of current and emerging security technologies, threats and techniques for exploiting security vulnerabilities Knowledge of public cloud services
Education
  • Bachelor's degree in Computer Science, Information Technology or equivalent
  • Advanced degree preferred
  • Certifications including GWAPT, GWEB, GPEN, OSCP, CSSLP, CASE, or similar preferred

The priority is not tool-specific expertise but strong security fundamentals combined with hands‑on execution: Application Security (SAST, DAST, SCA, secrets management) Threat Modelling Penetration Testing DevSecOps and Cloud Security Ability to leverage AI/LLMs and automation in security processes Strong coding and integration capabilities to build or automate workflows Strong Emphasis on Automation and AI Highlighted that the primary need is for engineers who can: Evaluate and implement security automation solutions. Use AI tools and agents to improve: Threat modelling SAST analysis Penetration testing Security workflow automation

Skills
  • Threat Modeling, SAST, DevSecOps, Cloud Security, Application Security, AWS Security, Workflow Automation, DAST, DevSecOps, Vulnerability Assessment and Penetration Testing, AI Security
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principle Engineer - Application Security
Principle Engineer - Application Security

UST • Bengaluru

On-site
INR 2,500,000 - 4,800,000
Application Security Engineer
Application Security Engineer

Kyndryl • Dadri, Greater Noida

On-site
INR 2,500,000 - 4,500,000
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
Security Engineer
Security Engineer

Cloudxtreme • Hyderabad

On-site
INR 1,200,000 - 1,800,000
Appsec Specialist - Lead
Appsec Specialist - Lead

Adani Group • Ahmedabad District

On-site
INR 2,800,000 - 4,200,000
Application Security Engineer
Application Security Engineer

Ola • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2COMS Consulting Pvt. Ltd. • Bengaluru Urban

On-site
INR 1,500,000 - 2,100,000
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2coms • Bengaluru Urban

On-site
INR 1,800,000 - 2,400,000
Application Security Analyst
Application Security Analyst

Zs Associates • Mumbai

Hybrid
INR 900,000 - 1,500,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Nextwebi • Bengaluru

On-site
INR 1,500,000 - 3,000,000