Senior Application Security Engineer

17 hours ago


Gurugram, India Cvent Full time

Overview
You are an experienced, hands-on Application Security Engineer who's passionate about building secure products, automating security workflows, and influencing development teams to embed security into the product development lifecycle. Whether you're ready to take ownership or growing your deep technical skills as a
Senior Engineer
, you're ready to make a measurable impact. You are required to be in the office for 2 days/week.

You excel at the core of Application Security—from secure design reviews, threat modeling to vulnerability discovery via penetration tests and remediation—and bring an engineering mindset that enhances your impact. You're also passionate about building internal tools, scripting automation, and scaling security practices across diverse tech stacks as part of Cvent's Application Security Research & Engineering (ASRE) program

In This Role, You Will

  • Integrate and scale security across the SDLC, embedding tools like SAST, DAST, and SCA within CI/CD pipelines.
  • Perform threat modeling, secure code and design reviews, penetration testing and risk assessments for new and existing features—including cloud-native and AI/ML systems.
  • Develop internal tools to automate security testing, support securing cloud-native applications using AWS CDK (CDF), and governance processes using scripting languages like Python, JavaScript, TypeScript, or similar.
  • Collaborate with engineering teams to remediate vulnerabilities identified via scans, manual testing, or external assessments.
  • Partner with product and engineering teams to improve the security posture of APIs, web apps, mobile apps, and infrastructure.
  • Communicate risks clearly to technical and non-technical audiences and support compliance efforts with ISO 27001, SOC2, and PCI.

Why You'll Love This Role

  • You'll build and automate security programs that scale across hundreds of apps and services.
  • You'll join the ASRE team to innovate at the forefront of Application Security.
  • You'll work with teams who take security seriously and give you the support to make meaningful change.
  • You'll grow in a role that offers both technical depth and leadership opportunities, depending on your experience and ambition.

Here's What You Need

  • 6+ years of hands-on experience in application security or secure software development.
  • Strong scripting/programming skills—able to automate tasks and build internal tools using Python, JavaScript, Bash, or similar.
  • Experience with CI/CD toolchains and integration of security tools in SDLC.
  • Strong familiarity with cloud platforms (AWS-preferred, GCP, or Azure) and principles of cloud-native security.
  • Proficiency in security testing tools (e.g., BurpSuite, Checkmarx, Mend, Veracode, Fortify, ZAP, etc.).
  • Strong grasp of OWASP Top 10, CWE, SANS Top 25, secure coding practices, and web application vulnerabilities.

Bonus If You Have

  • Experience securing AI/ML pipelines and understanding of adversarial ML or model privacy concerns.
  • Exposure to DevSecOps, SBOMs, IaC security, or supply chain risk management
  • Security certifications such as AWS Certified Security - Specialty, AWS Certified Solutions Architect - Associate/Professional, CSSLP, OSWE, GWAPT, CISSP, OSCP

  • Senior Manager

    3 days ago


    Gurugram, India Questhiring Full time

    Job Description :About the job :We are seeking a highly skilled and experienced Senior Manager Application Security to lead our application security strategy, governance, and execution. This role will oversee secure software development practices, drive security reviews and testing, and partner with engineering teams to ensure security is embedded across the...


  • Gurugram, India eSec Forte® Technologies Full time

    Serve as a trusted advisor to our enterprise customers, leading the analysis and remediation efforts of complex vulnerabilities using the full Checkmarx platform. Lead security reviews and consultation efforts across various SDLC stages, focusing on holistic application security. Guide customers in adopting secure coding practices, threat modeling, and...


  • Gurugram, India AIS business solution Full time

    Job Tittle - Security Test Engineer Job Type: Full-time EXP 5+ Years Location - Gurgaon Roles & Responsibilities: Perform Security Assessments: Conduct various types of security testing, including: 1. Penetration Testing: Perform black-box, gray-box, and white-box penetration testing on web applications, APIs, mobile applications (iOS/Android), and network...


  • Gurugram, India Senior Full time

    Company Description Senior is a UK based MNC and has operations in 12 countries and has 26 operating businesses worldwide serving number of markets. Senior's experienced manpower support, effective use of raw material as well as high technology enable it to deliver optimized components within a short development time and at most competitive prices. Senior...


  • Gurugram, India noon Full time

    About noon noon, the region's leading consumer commerce platform. On December 12th, 2017, noon launched its consumer platform in Saudi Arabia and the UAE, expanding to Egypt in February 2019. The noon ecosystem of services now includes marketplaces for food delivery, quick-commerce, fintech, and fashion. noon is a work in progress; we're six years in, but...

  • Application Security

    16 hours ago


    Gurugram, India eSec Forte® Technologies Full time

    · Serve as a trusted advisor to our enterprise customers, leading the analysis and remediation efforts of complex vulnerabilities using the full Checkmarx platform. · Lead security reviews and consultation efforts across various SDLC stages, focusing on holistic application security. · Guide customers in adopting secure coding practices, threat modeling,...

  • Security Engineer

    15 hours ago


    Gurugram, India Steerlean Full time

    Cloud Security Architecture : Asses, help in design and development of AWS, Azure and AWS security architectures for protecting PII/PCI data deployed into different types of cloud and cloud/hybrid systems. Improve the security around cloud-based applications, across all types (including Infrastructure, Platform, and Software as a Service...


  • Gurugram, Pune, India Acz Global Private Limited Full time

    Job DescriptionSenior Application Engineer - Control:Role Description:In this role, you will work as high level product technology expert, provide best technical consulting and solutions for customers applications to the sales teams independent of the industry segments with a strong focus on technologies. You will take commercial considerations fully into...


  • Gurugram, India Simpplr Full time

    Who We AreSimpplr is the AI-powered platform that unifies the digital workplace – bringing together engagement, enablement, and services to transform the employee experience. It streamlines communication, simplifies interactions, automates workflows, and elevates the everyday experience of work. The platform is intuitive, highly extensible, and built to...

  • Security Engineer

    3 days ago


    Gurugram, India HyreSnap Full time

    Responsibilities :- Vulnerability Assessment and Penetration Testing against Web applications, Mobile applications(Android and iOS), and Infrastructure.- Vulnerability management adheres to the ISMS policy and regulatory compliance.- Document TTP (Techniques, Tactics, and Procedures) used during a security assessment- Hands-on experience with SAST, DAST, and...