Application Security Engineer

4 weeks ago


Varanasi, India Foodsmart Full time

About us:Foodsmart is the leading telenutrition and foodcare solution, backed by a robust network of Registered Dietitians. Our platform is designed to foster healthier food choices, drive lasting behavior change, and deliver long-term health outcomes. Through our highly personalized, digital platform, we guide our 2.2 million members—including those in employer-sponsored health plans, regional and national Medicaid managed care organizations, Medicare Advantage plans, and commercial insurers—on a tailored journey to eating well while saving time and money.Foodsmart seamlessly integrates dietary assessments and nutrition counseling with online food ordering and cost-effective meal planning for the entire family, optimizing ingredients both at home and on the go. We partner with national and regional retailers across the U.S., many of whom accept SNAP/EBT, making healthier food more accessible. Additionally, we assist members with SNAP enrollment and management, providing tangible access to nutritious food.In 2024, Foodsmart secured a $200 million investment from TPG’s Rise Fund, which supports entrepreneurs dedicated to achieving the United Nations’ Sustainable Development Goals. This investment will help us expand our reach, particularly to low-income workers who are disproportionately affected by diet-related diseases.At Foodsmart, our mission is to make nutritious food accessible and affordable for everyone, regardless of economic status. We are committed to a set of core values that shape our culture and work environment:⚖️ Measured: We make data-driven, truth-seeking decisions.💥 Impactful: We are fueled by achieving our mission and vision.🙏 Collaborative: We help each other be better and create a positive environment.📈 Hungry: We maintain a healthy growth mindset, seeking to overcome challenges with courage.😊 Joyful: We take joy in each other, our work, and the privilege of doing this work.Whether you're a dietitian, a commercial leader, or a technologist, working at Foodsmart means being part of a team that is passionate, supportive, and driven by a shared purpose. Join us in transforming the way people access and enjoy healthy food.About the role:We are seeking an Application Security Engineer who will work at the intersection of security, DevOps, and development to ensure security is embedded throughout our SDLC. This role requires deep technical expertise in secure code review, static and dynamic application security testing (SAST/DAST), and infrastructure governance, especially in the segregation of environments, separation of duties, and branch protection in source control systems.You will:Code & Application SecurityConduct manual and automated code reviews to identify security vulnerabilities (e.g., XSS, SQLi, logic flaws).Define and implement SAST and DAST pipelines using tools such as SNYK, Checkmarx, Fortify, OWASP ZAP, or Burp Suite.Collaborate with development teams to remediate vulnerabilities and educate on secure coding standards (e.g., OWASP Top 10).DevSecOps & CI/CD Pipeline SecurityIntegrate security controls into CI/CD pipelines using tools like GitHub Actions, Jenkins, and GitLab CI.Define and enforce branch protection rules, code signing, and commit validation policies (e.g., mandatory code reviews, signed commits).Work closely with DevOps to ensure security-as-code is implemented across build, test, and deployment stages.Infrastructure & Environment SegregationEnsure proper segregation between development, staging, and production environments, following least privilege principles.Collaborate with infra and cloud teams to enforce network and access segregation (e.g., VPC segmentation, IAM policies).Governance & Policy EnforcementDefine and monitor separation of duties policies between developers, testers, and deployers.Create security baselines and compliance checks (e.g., CIS Benchmarks, SOC 2/ISO 27001 readiness).Set up auditing and alerting for anomalous activities in source control and deployment platforms.Tooling & AutomationDeploy and maintain security tools (e.g., GitGuardian, Aqua, Prisma Cloud) to detect hard coded secrets, policy violations, and misconfigurations.Automate remediation workflows where possible (e.g., auto-patching vulnerable dependencies).You have:7-10 years in Security Architecture, AppSec, or a combined development and security engineering role.Strong hands-on experience in secure coding, application security testing, and source code analysis.Solid knowledge of CI/CD pipelines, version control (especially GitHub/GitLab), and branch control strategies.Familiarity with cloud platforms (AWS, Azure, GCP) and security practices for each.In-depth understanding of network security, access controls, and zero trust architecture.Practical knowledge of regulatory or compliance frameworks (e.g., ISO 27001, SOC 2, NIST).Preferred QualificationsExperience working with Infrastructure as Code (IaC) tools (e.g., Terraform, CloudFormation) with embedded security checks.Familiarity with container security (Docker, Kubernetes, image scanning).Certifications: OSCP, CSSLP, CEH, GSEC, or AWS Security Specialty.Contributions to open-source security tools or projects is a plus.Key KPIs / Metrics of SuccessTime-to-remediate for identified vulnerabilities.Percentage of pipelines with integrated SAST/DAST.Number of policy violations prevented via branch rules and access controls.Coverage of secure coding training among developers.**Sign on bonus offered for immediate joiners**



  • Varanasi, India PeopleLogic Full time

    Experience: 10 - 25 years Role Overview: We are seeking a seasoned Cyber Security Architect with over a decade of experience to lead and guide our technical teams in implementing robust security controls across on-premises infrastructure and software applications. The ideal candidate will collaborate closely with Corporate Security and other stakeholders to...


  • Varanasi, India Palo Alto Networks Full time

    Our MissionAt Palo Alto Networks® everything starts and ends with our mission:Being the cybersecurity partner of choice, protecting our digital way of life.Our vision is a world where each day is safer and more secure than the one before. We are a company built on the foundation of challenging and disrupting the way things are done, and we’re looking for...


  • Varanasi, India HotelTrader LodgIQ Full time

    About Hotel Trader : Hotel Trader is a 100% automated & cloud-based distribution management company providing the tools necessary for hotels to seamlessly connect to global demand with the click of a button. We fully embrace an entrepreneurial culture where taking risks and doing things differently is the only way. Our Mission is to remove friction caused by...

  • Network engineer

    3 weeks ago


    Varanasi, India Insight Global Full time

    Title: Network Engineer Company: Confidential until initial phone screening (Aviation Industry) Location: Bengaluru, India (3x Onsite) Type: 12-Month Contract Open to immediate joiners only Required Skills & Experience 7+ years of progressive experience in network engineering, with at least 3 years in a senior role. F5 Load Balancing: Manage, configure, and...

  • Devops Engineer

    3 weeks ago


    Varanasi, India Whatjobs IN C2 Full time

    A fast-growing SaaS company is on a mission to transform how businesses manage and recover debt through the power of AI and automation. As a DevOps Engineer you’ll play a critical role in scaling, securing, and automating our LAMP-based SaaS infrastructure on AWS. In this role you’ll take full ownership of our cloud architecture, CI/CD pipelines and...


  • Varanasi, Uttar Pradesh, India Satin Finserv Limited Full time ₹ 6,00,000 - ₹ 8,00,000 per year

    Company DescriptionSatin Finserv Limited specializes in providing business loans to individuals, Micro, Small, and Medium Enterprises (MSMEs), as well as other corporate setups. As a partner to growing businesses, the company focuses on offering financial solutions to empower enterprises. Satin Finserv is committed to supporting entrepreneurs and fostering...


  • Varanasi, India Whatjobs IN C2 Full time

    We are looking for a highly skilled Senior Software Engineer with expertise in mobile and full-stack development. The role requires strong hands-on experience in React Native, Flutter, React.Js, Node.Js, JavaScript, and TypeScript , along with the ability to design, develop, and deploy scalable applications. The ideal candidate will be responsible for...

  • Cloud engineer

    5 days ago


    Varanasi, India People Prime Worldwide Full time

    Important Note (Please Read Before Applying) ???? Do NOT apply if: You have less than of 5+ years’ experience in combined roles of cloud engineer, infrastructure engineer, Dev Ops experience. You do not have 2+ years’ experience designing, building, and deploying scalable cloud-based solutions in GCP experience. You are on a notice period longer than 15...

  • Software Engineer

    17 hours ago


    varanasi, India Seceon Inc. Full time

    Job Title: Software Engineer – Fresher (50 Open Positions)Location: Seceon India – Onsite (Varanasi / Mumbai)Employment Type: Initial Internship Cum Full EmploymentExperience: 0–1 yearsDepartment: Engineering – aiXDR, aiSIEM, Cloud Security, Platform R&D, Automation & AI, aiSecOT360, aiIDGuardAbout SeceonSeceon is a global cybersecurity leader...

  • AI Engineer

    1 week ago


    Varanasi, India Entrepreneur Gulf Full time

    We at Entrepreneur Gulf are looking for a AI Engineer to join our Marketing Team, with the primary role of researching and identifying ways to build our brand while analyzing consumer behavior and exploring market trends and opportunities.For More Job Updates, Please Follow Our Page (Entrepreneur Gulf)Job Responsibilities:Design, build, and deploy...