Application Security Engineer

5 days ago


Chennai, India Cynosure Corporate Solutions Full time

Role Summary The Application Security Engineer is responsible for ensuring that all developed or acquired software meets security standards while supporting rapid innovation. The role involves integrating security into the software development lifecycle, conducting security assessments, and providing expert guidance on secure coding, vulnerability management, and penetration testing. Key Responsibilities Integrate security tools, best practices, and standards into the product/software development lifecycle. Conduct vulnerability assessments and penetration testing for infrastructure, web applications, APIs, mobile applications, and cloud environments. Identify, analyze, and exploit cybersecurity vulnerabilities, demonstrating attack vectors and providing remediation guidance. Support incident response and architecture review processes with application security expertise. Develop penetration testing plans, methodologies, and documentation, and report findings to stakeholders. Manage annual penetration testing activities with external vendors and internal teams. Provide manual penetration testing, security gap analysis, and application code review support. Evaluate third-party software for security compliance during vendor due diligence. Track and report on application security metrics, team performance, and security program effectiveness. Contribute to improving application frameworks, perimeter security, and overall security posture. Requirements Strong understanding of common security vulnerabilities (OWASP Top 10, SANS 25) and mitigation techniques. Experience with penetration testing tools (e.g., Kali Linux, Burp Suite, Metasploit, Nmap NSE, Mimikatz, Bloodhound, OpenVAS, Rapid7 InsightVM, Tenable.io). Knowledge of SSDLC, threat modeling, and secure coding practices. Proficient in scripting/programming: Python, Bash, PowerShell, JavaScript, Java, .NET, or Node.js (basic to intermediate). Experience with REST APIs, SOA architecture, and API Gateway concepts. Knowledge of cloud platforms (AWS, Azure, or GCP) and pen testing for IaaS, SaaS, PaaS, and containerized environments. Familiarity with vulnerability scoring systems (CVSS, EPSS) and security frameworks (CIS Benchmark, NIST). Strong understanding of MITRE ATT&CK Framework, attack path management, red teaming, privilege escalation, lateral movement, and defense evasion techniques. Good understanding of Windows and Linux operating systems, Apache/Unix servers. Additional Skills (Preferred) Experience in maintaining external attack surface security posture. Experience in application security testing (white-box, black-box, and code review). Certifications such as CISSP, CEH, OSCP, CSSLP are an advantage.


  • Application security

    2 weeks ago


    Chennai, Tamil Nadu, India Codincity Digital Technologies Full time ₹ 12,00,000 - ₹ 24,00,000 per year

    Exp - 5+ysAbout the Opportunity:Experienced Application Security Engineer to join a growing information security team responsible for securing next-generation, cloud-native financial technology systems, in the Chennai India. As our Senior Application Security Engineer, you will be responsible for owning application security program. This role will entail...


  • Chennai, Tamil Nadu, India ALIQAN Technologies Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Job Title: Application Security EngineerExperience: 5+ YearsDepartment: Technology – Information SecurityLocation: Chennai (Hybrid – 3 days from office)Reporting To: Application Security ArchitectWorking Hours: Full Time (9 hours/day)About LebaraLebara is a global telecommunications company, operating across Europe and several international markets...


  • Chennai, India Cynosure Corporate Solutions Full time

    Role Summary The Application Security Engineer is responsible for ensuring that all developed or acquired software meets security standards while supporting rapid innovation. The role involves integrating security into the software development lifecycle, conducting security assessments, and providing expert guidance on secure coding, vulnerability...


  • Chennai, India Cynosure Corporate Solutions Full time

    Job Description Role Summary The Application Security Engineer is responsible for ensuring that all developed or acquired software meets security standards while supporting rapid innovation. The role involves integrating security into the software development lifecycle, conducting security assessments, and providing expert guidance on secure coding,...


  • Chennai, India Cyanous Software Private Limited Full time

    Role Summary :The application security program is designed to ensure that any software developed or acquired meets stringent standards while enabling rapid innovation to meet customers ever? changing needs. The Application Security Engineer is responsible for providing application security services including secure coding techniques, security testing support...


  • Chennai, Tamil Nadu, India CyberFort DigiSec Solution Private Ltd Full time ₹ 6,00,000 - ₹ 18,00,000 per year

    Company DescriptionCyberfort Digisec Solution Private Ltd. is lead by a team of seasoned Information Security Management professionals with over three decades of industry experience. They possess technical and managerial expertise, having held strategic roles in multinational corporations, government entities, Big4 firms, and the banking sector. The company...


  • Chennai, India Tazapay Pte Ltd Full time

    Job Title - Senior Security Engineer (Application & Cloud Security) Location: Chennai About Tazapay Tazapay is a cross border payment service provider. They offer local collections via local payment methods, virtual accounts and cards in over 70 markets. The merchant does not need to create local entities anywhere and Tazapay offers the additional compliance...


  • Chennai, Tamil Nadu, India Sattrix Information Security Full time ₹ 6,00,000 - ₹ 18,00,000 per year

    Network Security Engineer L2Location: Chennai and HyderabadEmployment Type: Full-timeShifts: Rotational ShiftsWork Mode: Work from OfficeExperience:At least 4 to 6 Years of experience out of which, minimum 5 years' experience in Security device management and operation.Technical Skills & ToolsMandatory: WAF: F5Preferred (any 2–3):Proxy: SkyHigh, Zscaler...


  • Chennai, India NETSACH GLOBAL Full time

    Greetings from Netsach - A Cyber Security Company. We are looking for Web Application Security consultant with minimum of 3+ years of relevant experience in an information security function with good background in information technology, stakeholder management and people management. Their primary purpose is to Design, Engineer & eventually Embed practical &...


  • chennai, India NETSACH GLOBAL Full time

    Greetings from Netsach - A Cyber Security Company.We are looking for Web Application Security consultant with minimum of 3+ years of relevant experience in an information security function with good background in information technology, stakeholder management and people management. Their primary purpose is to Design, Engineer & eventually Embed practical &...