Application Security Specialist
3 weeks ago
About the Company:
Headquartered in California, U.S.A., GSPANN provides consulting and IT services to global clients. We help clients transform how they deliver business value by helping them optimize their IT capabilities, practices, and operations with our experience in retail, high-technology, and manufacturing. With five global delivery centers and 2000+ employees, we provide the intimacy of a boutique consultancy with the capabilities of a large IT services firm.
Role Purpose:
Own operational SSDLC for 180 in-house apps + 900 third party/SaaS, drive adoption of Client SSDLC processes/tools, integrate security in Agile/DevOps/CI CD, coordinate remediation, and deliver pre release security reviews and monthly reporting.
Job Position: Application Security Specialist (L3) – SSDLC Operations
Experience Required: 8 to 10 Years.
Location: Hyderabad/Gurugram
Primary Tools: Apiiro ASPM, GitHub Advanced Security (CodeQL, Secret scanning, Dependabot), Checkmarx, SD Elements, Jira/Confluence, GitHub Actions.
Key Responsibilities
• Drive SSDLC adoption across design→build→test→release→operate
• Conduct security reviews before release and enforce gates
• Integrate SAST/SCA/Secrets (Checkmarx, GitHub AS) and ASPM (Apiiro) into CI/CD (GitHub Actions/PR checks)
• Coordinate DAST enablement with DAST Ops; ensure pipelines block on critical findings
• Triage findings; create Jira remediation workflows; track SLA fixes and escalate delays
• Maintain vulnerability dashboards (Jira/Confluence, Apiiro)
• Provide developer training and Security Champions enablement
• Perform security assessments of third party/SaaS apps
Required Skills & Experience
8 to 10 years in AppSec/SSDLC operations; hands on with Apiiro, GitHub Advanced Security (CodeQL, secrets), Checkmarx, Jira/Confluence; strong CI/CD experience (GitHub Actions), SAST/SCA/DAST pipelines; vendor coordination; ability to coach developers (Java/.NET/JS/Python).
Shift Coverage 24×7 roster; L2/L3 on-call for P1 release blockers and urgent findings; formal handovers.
Systems Access & Request Process
- Apiiro: Project Admin via Jira/ServiceNow → AppSec Manager approval → Platform owner grant → quarterly recert.
- GitHub AS: Repo security settings via DevTools; approvals by Repo Owner + AppSec.
- Checkmarx: Project Admin; license tracked in Confluence; AppSec Manager approval. Jira/Confluence: Project + dashboard permissions via group; AppSec approval. SD Elements: Analyst/Admin (limited to leads).
Why choose GSPANN
“We GSPANNians” are at the heart of the technology that we pioneer. We do not service our customers, we co-create.
With the passion to explore solutions to the most challenging business problems, we support and mentor the technologist in everyone who is a part of our team. This translates into innovations that are path-breaking and inspirational for the marquee clients, we co-create a digital future with.
GSPANN is a work environment where you are constantly encouraged to sharpen your abilities and shape your growth path, We support you to become the best version of yourself by feeding your curiosity, providing a nurturing environment, and giving ample opportunities to take ownership, experiment, learn and succeed.
We’re a close-knit family of more than 2000 people that supports one another and celebrates successes, big or small. We work together, socialize together, and actively serve the communities we live in.
We invite you to carry forward the baton of innovation in technology with us.
At GSPANN, we do not service. We Co-create.
Discover your inner technologist - Explore and expand the boundaries of tech innovation without the fear of failure.
Accelerate your learning - Shape your career while scripting the future of tech. Seize the ample learning opportunities to grow at a rapid pace
Feel included - At GSPANN, everyone is welcome. Age, gender, culture, and nationality do not matter here, what matters is YOU
Inspire and Be Inspired - When you work with the experts, you raise your game. At GSPANN, you’re in the company of marquee clients and extremely talented colleagues
Enjoy Life - We love to celebrate milestones and victories, big or small. Ever so often, we come together as one large GSPANN family
Give Back - Together, we serve communities. We take steps, small and large so we can do good for the environment, weaving in sustainability and social change in our endeavors.
We invite you to carry forward the baton of innovation in technology with us.
Let’s Co-create.
-
Application Security
2 weeks ago
Hyderabad, Telangana, India, Telangana Bharat Financial Inclusion Limited Full timeJob Role & ResponsibilitiesConduct comprehensive application security assessments to verify adherence to security standards and best practices, ensuring coverage of areas such as authentication, authorization, session, data protection, secure coding and security compliance etcCoordinate extensively with application and SDG teams to establish, maintain, and...
-
Application Security Analyst
3 weeks ago
Hyderabad, Telangana, India, Telangana ADP Full timeApplication Security AnalystJob description:This position will be responsible for• conducting hands-on security tests on web, mobile, premise based, mainframe based , citrix based applications & platforms to identify security vulnerabilities and preparing documentation and reports• responsible for assessing risk of the found vulnerabilities as per ADP...
-
Senior Application Security Analyst
3 weeks ago
Hyderabad, Telangana, India, Telangana ADP Full timeLead/Senior Application Security AnalystJob description:This position will be responsible for• conducting hands-on security tests on web, mobile, premise based, mainframe based , citrix based applications & platforms to identify security vulnerabilities• responsible for assessing risk of the found vulnerabilities as per ADP standards and documenting them...
-
Service Now Security Operations
3 weeks ago
Hyderabad, Telangana, India, Telangana Tata Consultancy Services Full timeTCS hiring Service Now Security OperationsLocation : Hyderabad/ MumbaiMust-Have1. Security Operations Suite Expertise Security Incident Response (SIR): Implementing workflows for detecting, analyzing, and resolving security incidents. servicenow Vulnerability Response (VR): Automating vulnerability identification, prioritization, and remediation....
-
Engineer, Application Security
2 weeks ago
Hyderabad, Telangana, India ICE Full timeJob DescriptionJob PurposeAn ICE Application Security Engineer is part of a team responsible for ensuring that ICE produces and maintains secure applications. This team member influences secure design, performs code analysis, identifies vulnerabilities through hands-on penetration testing, assists developers in remediation efforts, and communicates findings...
-
Application Security Engineer
52 minutes ago
Hyderabad, Telangana, India Weekday AI Full timeThis role is for one of the Weekday's clientsMin Experience: 4 yearsLocation: HyderabadJobType: full-timeWe are seeking an experienced Application Security Engineer for a 6-month full-time contract based in Hyderabad. This role is critical to strengthening application security posture across products by identifying vulnerabilities early, embedding...
-
Security Analyst
3 weeks ago
Hyderabad, Telangana, India, Telangana Brace Infotech Private Ltd Full timeJob Title: Security Testing / Application Security EngineerExperience: 2–4 Years Location: Hyderabad / Hybrid Job Summary:We are looking for a Security Testing / Application Security Engineer with strong expertise in OWASP, VAPT, and application security. The ideal candidate will have hands-on experience in Web, Mobile, Network, and Infrastructure...
-
Hyderabad, Telangana, India, Telangana Evoke Technologies Full timeHiring: Oracle Applications Functional Testing SpecialistExperience: 4–8 YearsLocation: [Hyderabad )Employment Type: Full-timeAbout the RoleWe are looking for an experienced Oracle Applications Functional Testing professional to validate and ensure the quality of Oracle ERP applications. The ideal candidate will have strong functional knowledge of Oracle...
-
OCI & IDCS Infrastructure Support Specialist
2 weeks ago
Hyderabad, Telangana, India, Telangana Metasys Technologies Full timeJob Title: OCI & IDCS Infrastructure Support SpecialistLocation: REMOTENotice Period: 30 DaysJob Summary: We are seeking an experienced professional to provide infrastructure support services for Oracle Cloud Infrastructure (OCI) and Identity Cloud Service (IDCS). The role involves implementing and integrating E-Business Suite (EBS) and other applications...
-
Lead – Application Security
7 days ago
Hyderabad, Telangana, India ETT CareerMove Full timeWe are seeking an experienced Application Security & Technology Auditor to lead and execute end-to-end technology audits for a Fortune 500 client in Hyderabad.This role offers high visibility, strong learning opportunities, and the chance to work closely with senior stakeholders while leveraging modern tools, AI, and data analytics.Work location : Hyderabad...