Application Security Test Engineer

7 days ago


Bengaluru India STEP One Step Ahead Full time

Job Description We are seeking a skilled DevSecOps Engineer with strong expertise in Application Security, SAST, and SCA tools. The ideal candidate will collaborate closely with development and DevOps teams to integrate security seamlessly into the CI/CD pipeline, identify and eliminate false positives, and drive vulnerability remediation across multiple business applications. Hands-on experience in Snyk or equivalent platforms will be a significant advantage. Key Responsibilities: - Implement and maintain SAST and SCA tools within the CI/CD pipeline for continuous code scanning. - Analyze scan results, validate and triage false positives, and ensure accuracy of reported vulnerabilities. - Collaborate with development teams to guide and support remediation of security vulnerabilities. - Work with DevOps teams to automate security checks and streamline secure build and deployment processes. - Perform tool integrations (Snyk, SonarQube, Checkmarx, or similar) to improve visibility of the organization's security posture. - Provide technical guidance and training to developers on secure coding practices. - Participate in threat modeling, secure design discussions, and application architecture reviews. - Prepare and maintain documentation for processes, standards, and tool usage. Required Skills & Experience: - 2-3 years of experience in Application Security or DevSecOps domain. - Strong understanding of SAST and SCA tools (e.g., Checkmarx, Fortify, SonarQube, Snyk, or similar). - Proven ability to identify, analyze, and manage false positives effectively. - Good understanding of Secure SDLC and CI/CD environments. - Solid knowledge of web and API security concepts, OWASP Top 10, and secure coding standards. - Hands-on experience with DevOps tools such as Jenkins, GitLab, or Azure DevOps. - Excellent communication and collaboration skills to influence security adoption across teams. - Availability to join immediately. Preferred / Nice to Have: - Experience using Snyk for open-source dependency management. - Exposure to container security, IaC scanning, or cloud-native security controls. - Security certifications such as CEH, OSCP, or CSSLP.



  • Bengaluru, India Application Security Full time

    **Qualifications and Experience** 1. Bachelor’s degree in Computer Engineering/Computer Science, Information Technology, MCA or M.Sc. (IT). 2. 5+ years of experience in manual and automaton testing for previous software development. 3. Strong technical skills including scripting language and test automation disciplines, tools and processes. **Skills...


  • India Symosis Security Full time

    Location: Remote (India)Type: Full-TimeCompany: Symosis SecurityAbout Symosis SecuritySymosis Security is a fast-growing cybersecurity and technology firm helping global organizations strengthen their cloud, application, and AI security posture. We combine deep technical expertise with practical execution—supporting clients across threat modeling,...


  • India Symosis Security Full time

    Location : Remote (India) Type : Full-Time Company : Symosis Security About Symosis Security Symosis Security is a fast-growing cybersecurity and technology firm helping global organizations strengthen their cloud, application, and AI security posture. We combine deep technical expertise with practical execution—supporting clients across threat modeling,...


  • India Symosis Security Full time

    Location: Remote (India) Type: Full-Time Company: Symosis Security About Symosis Security Symosis is a cybersecurity consulting firm purpose-built for the AI-native, cloud-first era. We help public-sector and enterprise clients mature their security operations through managed services, offensive testing, governance, and automation. We're expanding our MSSP...


  • India Symosis Security Full time

    Location : Remote (India) Type : Full-Time Company : Symosis Security About Symosis Security Symosis is a cybersecurity consulting firm purpose-built for the AI-native, cloud-first era. We help public-sector and enterprise clients mature their security operations through managed services, offensive testing, governance, and automation. We’re expanding our...


  • India Symosis Security Full time

    Location: Remote (India)Type: Full-TimeCompany: Symosis SecurityAbout Symosis SecuritySymosis is a cybersecurity consulting firm purpose-built for the AI-native, cloud-first era. We help public-sector and enterprise clients mature their security operations through managed services, offensive testing, governance, and automation. We’re expanding our MSSP...


  • India Symosis Security Full time

    Location: Remote (India) Type: Full-Time Company: Symosis Security About Symosis Security Symosis Security is a fast-growing cybersecurity and technology firm helping global organizations strengthen their cloud, application, and AI security posture. We combine deep technical expertise with practical execution—supporting clients across threat modeling,...


  • Bengaluru, India RSA Security Full time

    Product Overview Outseer Fraud Manager is an advanced, omnichannel fraud detection hub that provides risk-based, multi-factor authentication for organizations seeking to protect their consumers from fraud across digital channels. Powered by the AI/ML based Risk Engine, Outseer Fraud Manager is designed to measure the risk associated with a user’s login...


  • Bengaluru, Karnataka, India UV Cyber Solutions Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Hiring for Application Security Testing -L3 - Staff Consultant UV Cyber -- (Hosur Main Road-Koramangala, Bangalore)Role : Application Security Testing -L3 - Staff ConsultantExperience: 5 yrs to 12 YrsNotice Period: 0 to 30 days(Applicants must attend face-to-face interview in Bangalore)Address: UV Cyber solutions,1ST Block,1ST Floor, PRESTIGE BLUE CHIP...


  • Bengaluru, India Operlity Full time

    We are hiring an experienced Application Security (AppSec) Engineer to strengthen secure software development across our products and platforms. You will collaborate with development teams, perform secure code reviews, lead threat modeling sessions, orchestrate security testing, and ensure our applications meet the highest security and compliance standards....