
▷ [3 Days Left] Senior Application Security Engineer
5 days ago
About NopalCyber
NopalCyber makes cybersecurity manageable, affordable, reliable, and powerful for companies that need to be resilient and compliant. Through Managed Extended Detection and Response (MXDR), Attack Surface Management (ASM), Breach and Attack Simulation (BAS), and Advisory Services, we fortify our clients’ cybersecurity across both offense and defence.
Our AI-driven Nopal360° platform, NopalGo mobile app, and proprietary Cyber Intelligence Quotient (CIQ) enable organizations to quantify, track, and visualize their cybersecurity posture in real time. We democratize enterprise-grade security operations for organizations of all sizes by lowering the barrier to entry while raising the bar for security and service.
Location: Nopal Cyber, Hyderabad (Work from Office, 5 Days a Week)
Employment Type: Full-time
Key Responsibilities
- Run Static Application Security Testing (SAST) using tools such as SonarQube, Fortify, Checkmarx, Veracode, etc., to identify source-code vulnerabilities across multiple languages and frameworks (Java, .NET, Python, JavaScript, etc.).
- Configure and execute SAST scans, fine-tune rules, manage false positives, and integrate scans into CI/CD pipelines.
- Perform Dynamic Application Security Testing (DAST) (authenticated and unauthenticated) on web apps, APIs, and services; analyse results and validate findings.
- Combine SAST and DAST outputs to provide holistic vulnerability coverage and support secure SDLC initiatives.
- Plan and conduct Vulnerability Assessment and Penetration Testing (VAPT) for web applications, APIs, and backend services to identify business logic, configuration, and runtime flaws.
- Map VAPT findings back to code-level issues discovered in SAST to close the loop with development teams.
- Work with developers and DevSecOps engineers to remediate vulnerabilities and embed security testing into build pipelines.
- Use Software Composition Analysis (SCA) tools such as Snyk, White Source, Nexus Lifecycle, Black Duck to identify open-source and third-party risks (vulnerabilities, license issues, outdated components).
- Generate, validate, and manage Software Bills of Materials (SBOMs) in formats like CycloneDX and SPDX to strengthen software supply chain security.
- Monitor transitive dependencies and unverified sources to prevent supply-chain compromise.
- Apply secure coding principles aligned with OWASP Top 10, CWE, and language-specific security pitfalls.
Required Skills & Experience
- 8–12 years of experience in Application Security with direct, hands-on expertise in SAST, DAST, SCA, and VAPT.
- Strong knowledge of secure software development practices and common vulnerability classes (OWASP Top 10, CWE, ASVS, language-specific security pitfalls).
- Hands-on experience integrating security testing into CI/CD pipelines (Jenkins, Azure DevOps, GitLab CI, GitHub Actions).
- Practical expertise with SAST tools (SonarQube, Fortify, Checkmarx, Veracode) and SCA tools (Snyk, White Source, Nexus Lifecycle, Black Duck).
- Working knowledge of security architecture frameworks (e.g., SABSA) and threat modeling methodologies (e.g., STRIDE, attack trees) to support risk-based application security design and assessment.
- Ability to validate and triage false positives, priorities vulnerabilities, and provide actionable remediation guidance to developers.
- Ability to develop and present detailed application security assessment reports, code-level remediation plans, and secure coding guidance aligned with industry standards and compliance requirements.
- Strong communication skills to convey technical findings to technical and executive stakeholders.
Educational Qualifications
- Bachelor’s degree in engineering, Computer Science, or related discipline.
- CEH Certification (Mandatory) plus one or more advanced certifications:
- EC-Council Certified Application Security Engineer (CASE – Java/.NET)
- GIAC Secure Software Programmer (GSSP – Java/.NET)
- Programming language-neutral certifications like CSSLP.
Personal attributes
- Self-starter and quick learner requiring minimal ramp-up
- Excellent written, oral, and interpersonal communication skills
- Highly self-motivated, self-directed, and attentive to detail
- Ability to effectively prioritize and execute tasks in a high-pressure environment
-
Hyderabad, Chennai, Pune, India Maven Wave Partners Full timeJob Description ENGINEER - Job Profile Details: Execute complex Application Security Code Review projects for different types of applications including mobile, web services, web apps and thick-client - Execute Application Penetration Testing projects as business demands Gain in-depth knowledge and understanding of applications developed in various...
-
Hyderabad, India Pepsico Full timeOverview This Role is for SAP Security Asst. Analyst, the primary focus is to support business and IT users having security issues. They also ensure that application security standards are well maintained and supported in collaboration with the global SAP Security team leads. The SAP security Asst. Analyst also ensures that global SAP application security...
-
Application Security Engineer III
1 week ago
Hyderabad, India Phenom Full timeJob Description Job description Job Requirements - We're looking for a full-time phenomenal Application Security Engineer III to architect and lead the implementation of the security-related aspects of our ITX platform. This will include evaluating and recommending new and emerging cloud security technologies and standards to ensure it is highly secure,...
-
Application Security Engineer III
2 weeks ago
Hyderabad, Telangana, India Phenom Full timeJob DescriptionJob descriptionJob Requirements- We're looking for a full-time phenomenal Application Security Engineer III to architect and lead the implementation of the security-related aspects of our ITX platform. This will include evaluating and recommending new and emerging cloud security technologies and standards to ensure it is highly secure,...
-
▷ [3 Days Left] Quality Assurance Engineer
1 week ago
Hyderabad, India IntraEdge Full timeJob Title: Senior Quality Assurance Engineer Responsibilities: As a Senior Quality Assurance Engineer, you will oversee the entirety of Citizens engineering and development efforts. You will help lead a team of highly-skilled engineers tasked with ensuring the development of top-quality technical solutions. The Senior Quality Assurance Engineer will be...
-
[3 Days Left] Cyber Security Engineer
5 days ago
Hyderabad, India Insight Global Full timeTitle: Cyber Security Engineer Duration: Perm Location: Hybrid in Hyderabad 2 times a week Pay Rate: $17/hr - $24/hr USD or ₹31.6–₹44.5 LPA REQUIRED SKILLS AND EXPERIENCE • Bachelor’s degree in Computer Science, Information Security, or related field • 7+ years of hands-on cloud security engineering experience. • Strong expertise with...
-
▷ 3 Days Left: Senior Network Consultant
1 week ago
Hyderabad, India ACL Digital Full timeDear Connections, ACL Digital is hiring for senior network engineer -Cisco ACI(SDN Technologies) for Hyderabad/Chennai Location. Senior Data Center Network Engineer-Cisco ACI Work Location: Hyderabad / Chennai Notice Period: Immediate / 30 Days Experience: 3 Years to 10 Years Job Summary: We are seeking highly skilled L2 ACI Cisco Consulting Engineers...
-
3 Days Left: Senior Lead
2 weeks ago
Gurugram, Hyderabad, Bengaluru, India Security and Intelligence Services Full timeJob DescriptionAs a Senior Lead Machine Learning Engineer of the Document Platforms and AI team, you will play a critical role in building the next generation of data extraction tools, working on cutting-edge ML-powered products and capabilities that power natural language understanding, information retrieval, and data sourcing solutions for the Enterprise...
-
Hyderabad, India Blackbaud Full timeAs a member of the Cyber Security organization at Blackbaud, the Application Security Engineer is a specialized position that plays a key role in securing software built and/or used by Blackbaud.You can expect to work closely with software development teams as well as third-party organizations to ensure that security, privacy, and compliance requirements are...
-
3 Days Left) Senior Cloud Engineer
4 weeks ago
Hyderabad, Telangana, India Soothsayer Analytics Full timeJob Title: Senior Cloud EngineerLocation: HyderabadExperience: 8–10 yearsJob Type: Full-timeAbout UsSoothsayer Analytics is a global AI & Data Science consultancy headquartered in Detroit, with a thriving delivery center in Hyderabad. We design and deploy end-to-end custom Machine Learning & GenAI solutions—spanning predictive analytics, optimization,...