
Senior application security engineer
2 weeks ago
About Nopal Cyber Nopal Cyber makes cybersecurity manageable, affordable, reliable, and powerful for companies that need to be resilient and compliant. Through Managed Extended Detection and Response (MXDR), Attack Surface Management (ASM), Breach and Attack Simulation (BAS), and Advisory Services, we fortify our clients’ cybersecurity across both offense and defence. Our AI-driven Nopal360° platform, Nopal Go mobile app, and proprietary Cyber Intelligence Quotient (CIQ) enable organizations to quantify, track, and visualize their cybersecurity posture in real time. We democratize enterprise-grade security operations for organizations of all sizes by lowering the barrier to entry while raising the bar for security and service. Location : Nopal Cyber, Hyderabad (Work from Office, 5 Days a Week) Employment Type : Full-time Key Responsibilities Run Static Application Security Testing (SAST) using tools such as Sonar Qube, Fortify, Checkmarx, Veracode, etc., to identify source-code vulnerabilities across multiple languages and frameworks (Java,. NET, Python, Java Script, etc.). Configure and execute SAST scans, fine-tune rules, manage false positives, and integrate scans into CI/CD pipelines. Perform Dynamic Application Security Testing (DAST) (authenticated and unauthenticated) on web apps, APIs, and services; analyse results and validate findings. Combine SAST and DAST outputs to provide holistic vulnerability coverage and support secure SDLC initiatives. Plan and conduct Vulnerability Assessment and Penetration Testing (VAPT) for web applications, APIs, and backend services to identify business logic, configuration, and runtime flaws. Map VAPT findings back to code-level issues discovered in SAST to close the loop with development teams. Work with developers and Dev Sec Ops engineers to remediate vulnerabilities and embed security testing into build pipelines. Use Software Composition Analysis (SCA) tools such as Snyk, White Source, Nexus Lifecycle, Black Duck to identify open-source and third-party risks (vulnerabilities, license issues, outdated components). Generate, validate, and manage Software Bills of Materials (SBOMs) in formats like Cyclone DX and SPDX to strengthen software supply chain security. Monitor transitive dependencies and unverified sources to prevent supply-chain compromise. Apply secure coding principles aligned with OWASP Top 10, CWE, and language-specific security pitfalls. Required Skills & Experience 8–12 years of experience in Application Security with direct, hands-on expertise in SAST, DAST, SCA, and VAPT. Strong knowledge of secure software development practices and common vulnerability classes (OWASP Top 10, CWE, ASVS, language-specific security pitfalls). Hands-on experience integrating security testing into CI/CD pipelines (Jenkins, Azure Dev Ops, Git Lab CI, Git Hub Actions). Practical expertise with SAST tools (Sonar Qube, Fortify, Checkmarx, Veracode) and SCA tools (Snyk, White Source, Nexus Lifecycle, Black Duck). Working knowledge of security architecture frameworks (e.g., SABSA) and threat modeling methodologies (e.g., STRIDE, attack trees) to support risk-based application security design and assessment. Ability to validate and triage false positives, priorities vulnerabilities, and provide actionable remediation guidance to developers. Ability to develop and present detailed application security assessment reports, code-level remediation plans, and secure coding guidance aligned with industry standards and compliance requirements. Strong communication skills to convey technical findings to technical and executive stakeholders. Educational Qualifications Bachelor’s degree in engineering, Computer Science, or related discipline. CEH Certification (Mandatory) plus one or more advanced certifications: EC-Council Certified Application Security Engineer (CASE – Java/. NET) GIAC Secure Software Programmer (GSSP – Java/. NET) Programming language-neutral certifications like CSSLP. Personal attributes Self-starter and quick learner requiring minimal ramp-up Excellent written, oral, and interpersonal communication skills Highly self-motivated, self-directed, and attentive to detail Ability to effectively prioritize and execute tasks in a high-pressure environment
-
Senior Application Security Engineer
2 weeks ago
Hyderabad, Telangana, India Backbase Full time ₹ 20,00,000 - ₹ 25,00,000 per yearThe job in shortNo day at Backbase is the same, and even more so for our security engineers. We all know that security and banking need to go hand in hand and with hackers and tech evolving by the day, you'll need to stay on your toes and ahead of the game.Your core responsibility is to guide and support the developer teams in delivering and deploying...
-
Senior Cyber Security Application Engineer
2 weeks ago
Hyderabad, Telangana, India Blackbaud Full time US$ 1,25,000 - US$ 1,75,000 per yearAbout UsAt Blackbaud, we are at the forefront of innovation for the non-profit sector. We are seeking a passionate and skilled Senior Cyber Security Application Engineer to join our Threat and Vulnerability Management team to help with cutting-edge projects that push the boundaries of Cyber Security tools and provide secure solutions for our internal...
-
Senior Cyber Security Application Engineer
1 week ago
Hyderabad, India Blackbaud Full timeDescription :As a Senior Cyber Security Application Engineer, you will play a pivotal role in designing, implementing, and managing advanced security application solutions that enable application and security engineers to work more effectively to detect and resolve security issues. Your expertise will be crucial in automating processes related to...
-
Senior Cyber Security Application Engineer
1 week ago
Hyderabad, India Blackbaud Full timeDescription :As a Senior Cyber Security Application Engineer, you will play a pivotal role in designing, implementing, and managing advanced security application solutions that enable application and security engineers to work more effectively to detect and resolve security issues. Your expertise will be crucial in automating processes related to...
-
Application Security Engineer III
4 weeks ago
Hyderabad, India Phenom Full timeJob Description Job description Job Requirements - We're looking for a full-time phenomenal Application Security Engineer III to architect and lead the implementation of the security-related aspects of our ITX platform. This will include evaluating and recommending new and emerging cloud security technologies and standards to ensure it is highly secure,...
-
Senior Application Security Engineer
6 days ago
hyderabad, India MOURI Tech Full timeWe are seeking a highly skilled DevSecOps Engineer with a strong background in application security, penetration testing, and secure development practices. The ideal candidate will bring hands-on experience in SAST, DAST, Kubernetes, CI/CD pipelines, and a solid understanding of DevSecOps principles. You will work closely with engineering, DevOps, and...
-
Senior Application Security Engineer
4 days ago
Hyderabad, India MOURI Tech Full timeWe are seeking a highly skilled DevSecOps Engineer with a strong background in application security, penetration testing, and secure development practices. The ideal candidate will bring hands-on experience in SAST, DAST, Kubernetes, CI/CD pipelines, and a solid understanding of DevSecOps principles. You will work closely with engineering, DevOps, and...
-
Senior application security engineer
5 days ago
Hyderabad, India MOURI Tech Full timeWe are seeking a highly skilled Dev Sec Ops Engineer with a strong background in application security , penetration testing , and secure development practices . The ideal candidate will bring hands-on experience in SAST , DAST , Kubernetes , CI/CD pipelines , and a solid understanding of Dev Sec Ops principles . You will work closely with...
-
Senior Application Security Engineer
6 days ago
Hyderabad, India MOURI Tech Full timeWe are seeking a highly skilled DevSecOps Engineer with a strong background in application security, penetration testing, and secure development practices. The ideal candidate will bring hands-on experience in SAST, DAST, Kubernetes, CI/CD pipelines, and a solid understanding of DevSecOps principles. You will work closely with engineering, DevOps, and...
-
Senior Application Security Engineer
6 days ago
Hyderabad, India MOURI Tech Full timeWe are seeking a highly skilled DevSecOps Engineer with a strong background in application security , penetration testing , and secure development practices . The ideal candidate will bring hands-on experience in SAST , DAST , Kubernetes , CI/CD pipelines , and a solid understanding of DevSecOps principles . You will work closely with engineering, DevOps,...