- 14+ years of experience in Application Security, secure SDLC,DevSecOps, application-security architecture, and vulnerability management.
General Description
- Serve as AppSec L3 SME, providing advanced finding validation, remediation advisory, secure-SDLC guidance, technical governance, andoperating-model improvement.
- Lead complex vulnerability analysis, application onboarding patterns, policy-driven security gates, exception analysis, and developer enablement.
- Mentor L2 engineers andcoordinatewith security architecture, engineering, risk, external testing providers, and application owners.
Key Responsibilities
Years of Experience
- 14+ years of experience in Application Security, secure SDLC,DevSecOps, application-security architecture, and vulnerability management.
General Description
- Serve as AppSec L3 SME, providing advanced finding validation, remediation advisory, secure-SDLC guidance, technical governance, andoperating-model improvement.
- Lead complex vulnerability analysis, application onboarding patterns, policy-driven security gates, exception analysis, and developer enablement.
- Mentor L2 engineers andcoordinatewith security architecture, engineering, risk, external testing providers, and application owners.
Skill Requirements
Technical Requirements
- Hands-on experience with SAST, SCA, DAST, API security testing,secretsscanning, container/image scanning, and cloud-code security tools such as Wiz Code or equivalent.
- Strong understanding of OWASP Top 10, CWE, CVSS, secure coding practices, vulnerability lifecycle, and risk-based prioritization.
- Experience triaging application-security findings,validatingfalse positives, assigning severity, andprovidingremediation guidance.
- Experience supporting application onboarding into AppSec tools andsecure-SDLCworkflows.
- Experience with Jira/ServiceNow, finding backlogs, exception workflows, evidence preparation, and AppSec reporting.
- Understanding of CI/CD security integration and policy-driven security gates.
- Deepexpertisein advanced web, API, cloud-native, container, microservices, authentication, authorization, cryptography, and business-logic vulnerabilities.
- Experience defining AppSec standards, threat-modeling approaches, secure-design reviews, testing strategies, and risk-based remediation models.
- Ability to review complex Java/Spring Boot, Angular, Python, API, AWS, and Kubernetes/EKS application architectures.
- Experience designing and integrating AppSec controls into CI/CD pipelines, including policy-as-code and release-security gates.
- Ability to lead tool tuning, false-positive reduction, coverage analysis, AppSec metrics, exception governance, and maturity improvement.
- Experience supporting regulatory/audit evidence and communicating application risk to senior stakeholders.
Soft Skills
- Excellent communication and presentation skills.
- Strong problem-solving and critical thinking skills.
- Exceptional project management and organizational abilities.
- Team collaboration and leadership skills.
- Client-focused approach with a commitment to delivering exceptional customer service.
Certifications (Good to have)
Good to have relevant certificates like (any of the below):
- CSSLP, OSWE, GWAPT, GWEB, CISSP, or equivalent advanced application-security certification.
- Cloud-security orDevSecOpscertification is preferred.
Educational Qualifications
- University degree in IT or/and IT Security.
- Bachelor’s degree in computer science/ IT or any relevant fields.
At HCLTech, you'll supercharge your potential. You'll find your career. And you'll find your spark. All at a place that knows that helping its customers stay on top starts by putting its people first.
HCLTech is a global technology company, home to more than 223,000 people across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud and AI, powered by a broad portfolio of technology services and products. We work with clients across all major verticals, providing industry solutions for Financial Services, Manufacturing, Life Sciences and Healthcare, Technology and Services, Telecom and Media, Retail and CPG, and Public Services. Consolidated revenues as of 12 months ending June 2026totaled $14.8billion.