TECHNICAL LEAD - Application Security

Happiest Minds Technologies

Bengaluru

On-site

INR 3,500,000 - 6,000,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Happiest Minds Technologies in Bengaluru seeks a Principal Security Engineer to lead application and cloud security, embedding security into CI/CD pipelines. You will drive VAPT, threat modeling, and secure SDLC across enterprise environments.

The role requires hands-on expertise in security reviews, cloud/container security, and collaboration with cross-functional teams to deliver compliant, secure applications.

Qualifications

  • 12+ years of experience in Application Security, Cloud Security and DevSecOps.
  • Hands-on in vulnerability assessment, penetration testing and secure SDLC implementations.
  • Experience integrating SAST/DAST into CI/CD pipelines.
  • Strong knowledge of OWASP Top 10, NIST, ISO 27001, PTES, ASVS.

Responsibilities

  • Conduct vulnerability assessments across applications, APIs, web and mobile.
  • Lead secure SDLC practices and threat modeling (STRIDE).
  • Manage vulnerability lifecycle from discovery to remediation and reporting.
  • Perform architecture security reviews for compliance with best practices.
  • Integrate security tooling into CI/CD pipelines (GitHub Actions).
  • Provide cloud/container security guidance (Docker, Kubernetes).
  • Collaborate with engineering and business stakeholders on secure, scalable solutions.

Skills

Application Security
Cloud Security
DevSecOps
VAPT
CI/CD Security

Education

Bachelor's degree in Computer Science or Information Security
CISSP
CISM
CEH

Tools

Fortify SCA/SSC
Checkmarx
Burp Suite
Invicti (Netsparker)
Qualys
Nessus

Job description

Principal Security Engineer

Location: Bengaluru, India

Years of Experience: 12+ years

Job Summary: We are seeking a highly skilled Principal Security Engineer with extensive experience in Application Security, Cloud Security, and DevSecOps. The ideal candidate will have a proven track record in enterprise and regulated environments, demonstrating expertise in vulnerability assessment and penetration testing (VAPT), threat modeling, and secure software development lifecycle (SDLC) implementation. This role requires a hands‑on approach to integrating security into CI/CD pipelines and collaborating with cross‑functional teams to ensure secure application deployments.

Responsibilities
  • Conduct comprehensive vulnerability assessments and penetration testing across applications, APIs, web, mobile, and thick-client environments.
  • Implement secure SDLC practices aligned with industry standards such as OWASP Top 10, NIST, ISO 27001, PTES, and ASVS.
  • Perform threat modeling using STRIDE methodology to identify and mitigate potential security risks.
  • Manage the vulnerability lifecycle, including identification, remediation, and reporting of security issues.
  • Conduct architecture security reviews to ensure compliance with security best practices.
  • Integrate security tools (SAST/DAST) into CI/CD pipelines using GitHub Actions and DevSecOps methodologies.
  • Provide guidance on cloud and container security, specifically with Docker and Kubernetes.
  • Collaborate with engineering, infrastructure, and business stakeholders to develop secure, scalable, and compliant enterprise solutions.
Mandatory Skills
  • Strong knowledge and experience in Application Security.
  • 12+ years of experience in Application Security, Cloud Security, and DevSecOps.
  • Hands‑on experience with SAST/DAST tools such as Fortify SCA/SSC, Checkmarx, Burp Suite, Invicti (Netsparker), Qualys, and Nessus.
  • Proven ability to manage vulnerability lifecycle and perform architecture security reviews.
  • Experience in integrating security into CI/CD pipelines.
  • Strong background in cloud and container security.
Preferred Skills
  • Experience with compliance and risk management frameworks.
  • Familiarity with secure application deployment practices.
  • Excellent communication and leadership skills.
Qualifications
  • Bachelor's degree in Computer Science, Information Security, or a related field.
  • Relevant security certifications (e.g., CISSP, CISM, CEH) are a plus.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SENIOR SOFTWARE ENGINEER - Application Security
SENIOR SOFTWARE ENGINEER - Application Security

Happiest Minds Technologies • Bengaluru

On-site
INR 1,700,000 - 2,100,000
Security Engineer (Application Security / Secure Coding)
Security Engineer (Application Security / Secure Coding)

Estaff Tech Private Limited • Bengaluru Urban

On-site
INR 1,400,000 - 2,200,000
Application Security Engineer
Application Security Engineer

US Software Group Inc • Bengaluru

Hybrid
INR 9,033,000 - 11,744,000
Application Security Engineer
Application Security Engineer

Byline Learning Solutions • Pune District

On-site
INR 1,200,000 - 1,800,000
Lead Engineer - Cyber Security
Lead Engineer - Cyber Security

Mphasis • Bengaluru

On-site
INR 3,500,000 - 7,000,000
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2coms • Bengaluru

On-site
INR 2,500,000 - 4,000,000
Application Security Manager
Application Security Manager

Coventine Digital • Chennai District, Bengaluru, Pune District

On-site
INR 3,000,000 - 6,000,000
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
Appsec Specialist - Lead
Appsec Specialist - Lead

Adani Group • Ahmedabad District

On-site
INR 2,800,000 - 4,200,000
Application Security Engineer
Application Security Engineer

Cynosure Corporate Solutions • Chennai District

On-site
INR 1,500,000 - 2,500,000