Application Security Engineer (AppSec Engineer) - Bengaluru

Omnissa

Hinoba-an

Hybrid

PHP 789,000 - 1,183,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Omnissa is seeking an Application Security Engineer to strengthen our security posture across Web, Mobile, and Thick Client platforms. You will lead threat modelling, secure code reviews, and automation efforts to identify vulnerabilities and improve secure development practices.

The role requires deep technical expertise and proactive process improvements. As an individual contributor, you will partner with product and engineering teams to implement secure development practices and drive

Qualifications

  • 5 to 8 years of experience in application/product security.
  • Expertise in testing Web, Mobile, and Thick Client security.
  • Threat modelling and secure design reviews.
  • Manual code reviews across multiple languages.

Responsibilities

  • Conduct in-depth manual and automated security testing of Web, Mobile (Android/iOS), and Thick Client apps.
  • Perform secure code reviews using manual techniques and Semgrep; integrate into CI/CD.
  • Review features early in the lifecycle and provide risk-based recommendations.
  • Facilitate threat modelling and architecture reviews with product teams.
  • Provide guidance on secure design patterns and defense-in-depth strategies.
  • Lead initiatives to improve security posture and establish scalable controls.
  • Collaborate with incident response and bug bounty teams on issues.

Skills

Security testing
Threat modelling
Secure code reviews
Web security testing
Mobile security testing
CI/CD security
Communication skills

Tools

Semgrep
SAST/DAST tools
CI/CD security tooling

Job description

Job Description: We are Omnissa! The world is evolving fast, and organizations everywhere—from corporations to schools—are under immense pressure to provide flexible, work-from-anywhere solutions. They need IT infrastructure that empowers employees and customers to access applications from any device, on any cloud, all while maintaining top-tier security. That’s where Omnissa comes in. The Omnissa Platform is the first AI-driven digital work platform that enables smart, seamless and secure work experiences from anywhere. It uniquely integrates multiple industry-leading solutions including Unified Endpoint Management, Virtual Apps and Desktops, Digital Employee Experience, and Security & Compliance through common data, identity, administration, and automation services. Built on the vision of autonomous workspaces - self configuring, self-healing, and self-securing - Omnissa continuously adapts to the way people work; delivering personalized and engaging employee experiences, while optimizing security, IT operations and costs. we're experiencing rapid growth—and this is just the beginning of our journey! At Omnissa, we’re driven by a shared mission to maximize value for our customers. Our five Core Values guide us: Act in Alignment, Build Trust, Foster Inclusiveness, Drive Efficiency, and Maximize Customer Value—all with the aim of achieving shared success for our clients and our team. As a global private company with over 4,000 employees, we’re always looking for passionate, talented individuals to join us. If you're ready to make an impact and help shape the future of work, we’d love to hear from you!

What is the opportunity?

Application Security Engineer plays a critical role in improving the overall security posture of our products and platforms. This role focuses on end-to-end security testing across Web, Mobile, and Thick Client applications, and partners closely with product and engineering teams to implement secure development practices. The candidate will lead initiatives related to threat modelling, secure code reviews, feature assessments, automation (e.g., Semgrep), and root cause analysis for high-impact vulnerabilities. This is an Individual contributor role that requires deep technical expertise, leadership in security initiatives, and a proactive mindset for process improvement. Must have Skills :

  • 5 to 8 years of experience in the security domain, specifically in Application/Product Security.
  • Demonstrated expertise in: Web, Mobile, and Thick Client security testing.
  • Threat modelling and secure design review.
  • Manual code reviews across multiple languages and frameworks.
  • Use and automation of security tools such as Semgrep, SAST/DAST tools, and custom scripts.
  • Proficiency with languages such as Java, Kotlin, Swift, JavaScript, Python, C#/.NET.
  • Strong understanding of security principles including authentication, authorization, secure storage, and cryptographic best practices.
  • Excellent communication skills, including the ability to present security issues and recommendations to technical and non-technical stakeholders.
Good to have skills :
  • Hands-on experience with CI/CD security automation, container security, and cloud environments (AWS/GCP/Azure).
  • Certifications such as OSWE, OSCP, OSEP, GWAPT, GMOB, or equivalent.
  • Experience working with bug bounty programs, VDPs, or vulnerability triage.
  • Track record of contributions to the security community (e.g., blogs, talks, open-source tools, CVEs).
Key Responsibilities
  • Security Testing & Reviews Conduct in-depth manual and automated security testing of Web, Mobile (Android/iOS), and Thick Client applications.
  • Perform secure code reviews using both manual techniques and tools like Semgrep, integrated into CI/CD pipelines.
  • Review product features for potential security issues early in the development lifecycle and provide risk-based recommendations.
  • Security Architecture & Threat Modelling Facilitate threat modelling and architecture reviews with product and engineering teams.
  • Provide guidance on secure design patterns, attack surface reduction, and defense-in-depth strategies.
  • Process & Posture Improvement Lead and drive initiatives to improve the overall security posture of products and development practices.
  • Define and implement scalable security controls and development guardrails.
  • Security Issue & Incident Collaboration Work with Incident Response and Bug Bounty teams to evaluate researcher-submitted and customer-reported issues.
  • Conduct variant and root cause analysis for high-severity (P0/P1) bugs and provide long-term remediation guidance.
  • Stakeholder Management Collaborate with Product BU leaders and engineering stakeholders to align on security goals and assist in their execution.
  • Act as a trusted security advisor to cross-functional teams across the organization.

What will you bring to Omnissa? Work closely with teams to create, update and maintain threat models Perform secure code reviews and manual application security testing across all our products Triage and validate externally reported issues against our products Provide guidance and education to developers Develop ways to help identify and prevent systematic issues

Location: Bengaluru Location Type: HYBRID. NO REMOTE. This role offers a balanced arrangement, with the expectation of working 3 days a week in our local office and the flexibility to work from home for the remaining days. It is essential that you reside within a reasonable commuting distance of the office location for the in-office workdays. Travel Expectations: 5% of travel Domestic/International only if business demands.

Leadership & Team Culture

Report to the Manager / Sr. Manager. Work closely with a committed team of security engineers, product managers, and developers focused on innovation and getting things done. Build trust among team members and stakeholders, committing to customer success. Operate in a transparent, communicative environment that emphasizes work-life balance and having fun at work.

Omnissa is the digital work platform leader, trusted by thousands of organizations worldwide as the former VMware End-User Computing business. We make digital work, work – for businesses and their people. No painful IT processes or productivity trade-offs. Instead, a seamlessly delivered digital employee experience that simplifies work. Our comprehensive digital work platform enables IT teams to provide secure, personalized experiences for every employee, on any device. Omnissa unifies, automates, and efficiently scales the digital workspace. By empowering employees to do their best work, anywhere, we help workforces everywhere unlock exponential business value. All is made possible with the Omnissa™ Platform, the first AI-driven digital work platform for smart, seamless, and secure work experiences from anywhere.

It integrates multiple industry-leading solutions across Unified Endpoint Management, Virtual Desktops and Apps, Digital Employee Experience, and Security and Compliance. By continuously adapting to users’ work styles, Omnissa optimizes user experience, security, IT operations and costs.

Recognized as 2025 Digital Workplace Company of the Year 2025 InfoWorld Awards Finalist – App Volumes RemoteTech Breakthrough Award Winner – Digital Workplace Company of the Year CRN Product of the Year Finalist – Omnissa Horizon (DaaS) Omnissa is committed to building a workforce that reflects the communities we serve across the globe. We believe this brings unique perspectives, experiences, and ideas, which are essential for driving innovation and achieving business success. We hire based on merit and with equal opportunity for all.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Quality Assurance
Quality Assurance

Omnissa • Hinoba-an

Hybrid
PHP 924,000 - 1,385,000
Senior Site Reliability Engineer
Senior Site Reliability Engineer

Omnissa • Hinoba-an

On-site
PHP 1,000,000 - 1,800,000
Remote AppSec Engineer — AI-Driven SaaS Security
Remote AppSec Engineer — AI-Driven SaaS Security

Coberon Chronos • España

Remote
PHP 4,972,000 - 7,813,000
Security Analyst New India
Security Analyst New India

BloomReach Inc. • Hinoba-an

Hybrid
PHP 600,000 - 1,000,000
Flexible working hours
Remote-friendly
Stock options
+3
APPLICATION SECURITY LEAD
APPLICATION SECURITY LEAD

City Government of Muntinlupa - Government • Muntinlupa

On-site
PHP 1,000,000 - 1,500,000
Security Engineer - AppSec
Security Engineer - AppSec

Coberon Chronos • España

Remote
PHP 4,972,000 - 7,813,000
Lead Security Engineer India
Lead Security Engineer India

Amtech Software • Hinoba-an

On-site
PHP 1,200,000 - 2,000,000
Application Security Engineer
Application Security Engineer

Recruitify_HR • Quezon City

Hybrid
Up to 80k joining bonus
Hybrid work model
Competitive salary
Product Security Engineer
Product Security Engineer

GoMining • España

On-site
USD 120,000 - 180,000
Professional growth support
Remote or hybrid format
Flexible hours
+2
Technical Success Architect Bengaluru, India
Technical Success Architect Bengaluru, India

Endor Labs • Hinoba-an

On-site
PHP 900,000 - 1,300,000