Application security engineer

3 weeks ago


Vellore, India Foodsmart Full time

About us:Foodsmart is the leading telenutrition and foodcare solution, backed by a robust network of Registered Dietitians. Our platform is designed to foster healthier food choices, drive lasting behavior change, and deliver long-term health outcomes. Through our highly personalized, digital platform, we guide our 2.2 million members—including those in employer-sponsored health plans, regional and national Medicaid managed care organizations, Medicare Advantage plans, and commercial insurers—on a tailored journey to eating well while saving time and money.Foodsmart seamlessly integrates dietary assessments and nutrition counseling with online food ordering and cost-effective meal planning for the entire family, optimizing ingredients both at home and on the go. We partner with national and regional retailers across the U. S., many of whom accept SNAP/EBT, making healthier food more accessible. Additionally, we assist members with SNAP enrollment and management, providing tangible access to nutritious food. In 2024, Foodsmart secured a $200 million investment from TPG’s Rise Fund, which supports entrepreneurs dedicated to achieving the United Nations’ Sustainable Development Goals. This investment will help us expand our reach, particularly to low-income workers who are disproportionately affected by diet-related diseases.At Foodsmart, our mission is to make nutritious food accessible and affordable for everyone, regardless of economic status. We are committed to a set of core values that shape our culture and work environment:⚖️ Measured: We make data-driven, truth-seeking decisions.???? Impactful: We are fueled by achieving our mission and vision.???? Collaborative: We help each other be better and create a positive environment.???? Hungry: We maintain a healthy growth mindset, seeking to overcome challenges with courage.???? Joyful: We take joy in each other, our work, and the privilege of doing this work.Whether you're a dietitian, a commercial leader, or a technologist, working at Foodsmart means being part of a team that is passionate, supportive, and driven by a shared purpose. Join us in transforming the way people access and enjoy healthy food.About the role:We are seeking an Application Security Engineer who will work at the intersection of security, Dev Ops, and development to ensure security is embedded throughout our SDLC. This role requires deep technical expertise in secure code review, static and dynamic application security testing (SAST/DAST), and infrastructure governance, especially in the segregation of environments, separation of duties, and branch protection in source control systems.You will:Code & Application SecurityConduct manual and automated code reviews to identify security vulnerabilities (e.g., XSS, SQLi, logic flaws).Define and implement SAST and DAST pipelines using tools such as SNYK, Checkmarx, Fortify, OWASP ZAP, or Burp Suite.Collaborate with development teams to remediate vulnerabilities and educate on secure coding standards (e.g., OWASP Top 10).Dev Sec Ops & CI/CD Pipeline SecurityIntegrate security controls into CI/CD pipelines using tools like Git Hub Actions, Jenkins, and Git Lab CI.Define and enforce branch protection rules, code signing, and commit validation policies (e.g., mandatory code reviews, signed commits).Work closely with Dev Ops to ensure security-as-code is implemented across build, test, and deployment stages.Infrastructure & Environment SegregationEnsure proper segregation between development, staging, and production environments, following least privilege principles.Collaborate with infra and cloud teams to enforce network and access segregation (e.g., VPC segmentation, IAM policies).Governance & Policy EnforcementDefine and monitor separation of duties policies between developers, testers, and deployers.Create security baselines and compliance checks (e.g., CIS Benchmarks, SOC 2/ISO 27001 readiness).Set up auditing and alerting for anomalous activities in source control and deployment platforms.Tooling & AutomationDeploy and maintain security tools (e.g., Git Guardian, Aqua, Prisma Cloud) to detect hard coded secrets, policy violations, and misconfigurations.Automate remediation workflows where possible (e.g., auto-patching vulnerable dependencies).You have:7-10 years in Security Architecture, App Sec, or a combined development and security engineering role.Strong hands-on experience in secure coding, application security testing, and source code analysis.Solid knowledge of CI/CD pipelines, version control (especially Git Hub/Git Lab), and branch control strategies.Familiarity with cloud platforms (AWS, Azure, GCP) and security practices for each.In-depth understanding of network security, access controls, and zero trust architecture.Practical knowledge of regulatory or compliance frameworks (e.g., ISO 27001, SOC 2, NIST).Preferred QualificationsExperience working with Infrastructure as Code (Ia C) tools (e.g., Terraform, Cloud Formation) with embedded security checks.Familiarity with container security (Docker, Kubernetes, image scanning).Certifications: OSCP, CSSLP, CEH, GSEC, or AWS Security Specialty.Contributions to open-source security tools or projects is a plus.Key KPIs / Metrics of SuccessTime-to-remediate for identified vulnerabilities.Percentage of pipelines with integrated SAST/DAST.Number of policy violations prevented via branch rules and access controls.Coverage of secure coding training among developers.



  • Vellore, India Symosis Security Full time

    About Symosis Security Symosis is a fast-growing US cybersecurity and engineering firm building real, high-impact security automation for some of the largest tech companies in the world. We move fast, solve hard problems, and ship clean, production-grade engineering — not slides, not theory. If you want to work on serious API engineering, data pipelines,...


  • vellore, India beBeeCybersecurity Full time

    Join Our Cybersecurity TeamWe are seeking a highly motivated and passionate student or recent graduate for an exciting opportunity to gain hands-on experience as an Information Security Intern specializing in Penetration Testing and Application Security.This internship is structured as follows:Comprehensive Training Period (First 12 Months): This is an...


  • vellore, India beBeeSecurity Full time

    Job Title: Security Expert for AppScan ProductJob DescriptionAs a key member of our team, you will be responsible for leading the security efforts for our AppScan product. You will identify and develop procedures to discover new vulnerabilities in application source code, demonstrate expertise with multiple operating systems/RDBMS, and provide guidance on...


  • vellore, India beBeeApplication Full time

    Senior Security Engineer OpportunityWe are seeking a seasoned Senior Security Engineer to enhance the security of our products. The successful candidate will collaborate with cross-functional teams, including development and product management, to ensure the integrity of our applications.The role involves working closely with stakeholders to identify and...


  • vellore, India beBeeMobileSecurity Full time

    Job SummaryWe are seeking a mobile security expert to ensure our Android applications comply with Google Play security policies, privacy standards, and data protection requirements.This role includes auditing apps before release, reviewing Data Safety Forms, analyzing SDKs, monitoring Play Store policy updates, and addressing app rejections or compliance...


  • vellore, India Recfront Full time

    Cloud Security and DevOps Engineer (GCP + AI-Driven) Location: India (Remote)Availability: 0-15 days / ImmediateTimings: EST Timezone (7PM to 4AM IST)About our client:Our client is redefining hormone health by blending clinical expertise, data-driven innovation, and a fully integrated digital platform. They empower patients and practitioners with...


  • vellore, India beBeeCybersecurity Full time

    Job Title: Cyber Security SpecialistProtecting computer networks, applications, and data is of paramount importance.As a Cyber Security Specialist, you will be responsible for designing, implementing, and maintaining security systems to safeguard our organization's digital assets.Key Responsibilities:Security Architecture & Implementation:Develop and deploy...


  • Vellore, India Peoplefy Full time

    We are looking for a senior-level IT Applications Engineer ( Functional/Technical Specialist) with strong expertise in middleware and API development to design, build, and lead high-performance integration solutions. This role combines hands-on technical leadership with team management, working closely with architects, developers, QA teams, and...


  • vellore, India beBeecybersecurity Full time

    Cyber Security Engineer Job DescriptionThe Cyber Security Engineer plays a pivotal role in safeguarding an organization's computer networks, applications, and data. This position involves designing, implementing, and maintaining security systems to mitigate vulnerabilities and ensure compliance with industry standards.


  • vellore, India beBeeCyber Full time

    Network DefenderThe role of Network Defender is crucial in safeguarding an organization's computer networks, applications, and data from cyber threats. This position involves designing, implementing, and maintaining security systems to protect against potential vulnerabilities.Key responsibilities include:Security Architecture & Implementation: Develop,...