TECHNICAL LEAD - Application Security

Happiest Minds Technologies

Bengaluru

On-site

INR 4,000,000 - 6,000,000

Full time

4 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Happiest Minds Technologies in Bengaluru, India is seeking a Principal Security Engineer with 12+ years of experience in Application Security, Cloud Security and DevSecOps. You will lead vulnerability assessments, perform threat modeling, and drive secure SDLC implementations across enterprise and regulated environments.

The role emphasizes hands-on VAPT, integration of SAST/DAST into CI/CD (GitHub Actions), and guidance on Docker and Kubernetes security, collaborating with cross-functional

Qualifications

  • 12+ years of experience in Application Security, Cloud Security and DevSecOps.
  • Hands-on with SAST/DAST tools such as Fortify SCA/SSC, Checkmarx, Burp Suite, Invicti, Qualys and Nessus.
  • Proven ability to manage vulnerability lifecycle and perform architecture security reviews.
  • Experience integrating security into CI/CD pipelines.

Responsibilities

  • Conduct vulnerability assessments and penetration testing across applications, APIs, web, mobile, and thick-client environments.
  • Implement secure SDLC practices aligned with OWASP Top 10, NIST, ISO 27001, PTES, and ASVS.
  • Perform threat modeling using STRIDE to identify and mitigate security risks.
  • Manage the vulnerability lifecycle, including identification, remediation, and reporting of security issues.
  • Conduct architecture security reviews to ensure security best practices.
  • Integrate security tools (SAST/DAST) into CI/CD pipelines using GitHub Actions and DevSecOps methodologies.
  • Provide guidance on cloud and container security, specifically with Docker and Kubernetes.
  • Collaborate with engineering, infrastructure, and business stakeholders to develop secure, scalable enterprise solutions.

Skills

App Security
Cloud Security
DevSecOps
VAPT
Threat Modeling
Secure SDLC
CI/CD
SAST/DAST

Education

Bachelor’s degree in Computer Science or Information Security

Tools

Fortify SCA/SSC
Checkmarx
Burp Suite
Invicti/Netsparker
Qualys
Nessus

Job description

Location:

Bengaluru, India


Years of Experience:

12+ years


Job Summary:

We are seeking a highly skilled Principal Security Engineer with extensive experience in Application Security, Cloud Security, and DevSecOps. The ideal candidate will have a proven track record in enterprise and regulated environments, demonstrating expertise in vulnerability assessment and penetration testing (VAPT), threat modeling, and secure software development lifecycle (SDLC) implementation. This role requires a hands‑on approach to integrating security into CI/CD pipelines and collaborating with cross-functional teams to ensure secure application deployments.


Responsibilities:


  • Conduct comprehensive vulnerability assessments and penetration testing across applications, APIs, web, mobile, and thick-client environments.

  • Implement secure SDLC practices aligned with industry standards such as OWASP Top 10, NIST, ISO 27001, PTES, and ASVS.

  • Perform threat modeling using STRIDE methodology to identify and mitigate potential security risks.

  • Manage the vulnerability lifecycle, including identification, remediation, and reporting of security issues.

  • Conduct architecture security reviews to ensure compliance with security best practices.

  • Integrate security tools (SAST/DAST) into CI/CD pipelines using GitHub Actions and DevSecOps methodologies.

  • Provide guidance on cloud and container security, specifically with Docker and Kubernetes.

  • Collaborate with engineering, infrastructure, and business stakeholders to develop secure, scalable, and compliant enterprise solutions.


Mandatory Skills:


  • Strong knowledge and experience in Application Security.

  • 12+ years of experience in Application Security, Cloud Security, and DevSecOps.

  • Hands‑on experience with SAST/DAST tools such as Fortify SCA/SSC, Checkmarx, Burp Suite, Invicti (Netsparker), Qualys, and Nessus.

  • Proven ability to manage vulnerability lifecycle and perform architecture security reviews.

  • Experience in integrating security into CI/CD pipelines.

  • Strong background in cloud and container security.


Preferred Skills:


  • Experience with compliance and risk management frameworks.

  • Familiarity with secure application deployment practices.

  • Excellent communication and leadership skills.


Qualifications:


  • Bachelor's degree in Computer Science, Information Security, or a related field.

  • Relevant security certifications (e.g., CISSP, CISM, CEH) are a plus.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

Zoho • Bengaluru Urban

On-site
INR 1,500,000 - 2,100,000
Application security
Application security

Codincity Digital Technologies • Chennai District

On-site
INR 3,500,000 - 5,500,000
Information Security Engineer
Information Security Engineer

Tredence Inc. • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Staff Engineer - Application Security
Staff Engineer - Application Security

UST • Bengaluru

On-site
INR 2,400,000 - 4,200,000
Application Security Engineer
Application Security Engineer

US Software Group Inc • Bengaluru

On-site
INR 9,033,424 - 11,743,451
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
DIRECTOR - Application Security
DIRECTOR - Application Security

Happiest Minds Technologies • Bengaluru

On-site
INR 400,000 - 1,000,000
Application Security Lead
Application Security Lead

Airtel Payments Bank • Gurugram District

On-site
INR 1,200,000 - 2,400,000
Application Security Consultant
Application Security Consultant

SecurityBoat Cybersecurity Solutions Private Limited • Mumbai

On-site
INR 1,200,000 - 2,200,000
Competitive compensation
Specialized cybersecurity team
Professional development
Application Security Engineer
Application Security Engineer

GCS Recruitment Specialists • Pune District

On-site
INR 1,800,000 - 2,800,000