Senior Application Security Engineer

12 hours ago


Bangalore Karnataka, India Hewlett Packard Enterprise Full time

Senior Application Security Engineer This role has been designed as Hybrid with an expectation that you will work on average 2 days per week from an HPE office Who We Are Hewlett Packard Enterprise is the global edge-to-cloud company advancing the way people live and work We help companies connect protect analyze and act on their data and applications wherever they live from edge to cloud so they can turn insights into outcomes at the speed required to thrive in today s complex world Our culture thrives on finding new and better ways to accelerate what s next We know varied backgrounds are valued and succeed here We have the flexibility to manage our work and personal needs We make bold moves together and are a force for good If you are looking to stretch and grow your career our culture will embrace you Open up opportunities with HPE About our Cybersecurity team Are you ready to make an impact at one of the world s leading tech companies HPE s Cybersecurity team is where you can do just that We re looking for an Expert level Cybersecurity Incident Response Analyst to join our Incident Command team in Bangalore As an expert you will be responsible for leading the detection analysis containment and remediation of cybersecurity incidents across the organization This role demands a deep technical understanding of cyber threats advanced incident handling skills and the ability to act decisively in high-pressure situations You will work closely with other cybersecurity teams to ensure a coordinated and effective response to security incidents helping to minimize the impact on the organization Within the scope of the role will be mentoring junior team members and contributing to the continuous improvement of the organization s incident response capabilities What you ll do Key Responsibilities Secure SDLC DevSecOps Integration - Partner with engineering and DevOps teams to embed security into the entire software delivery process Software Delivery Pipeline CI CD Security - Design and implement security controls for build and release pipelines GitHub Actions Jenkins GitLab Azure DevOps etc Ensure code integrity via signing artifact scanning and build provenance Automate SAST DAST SCA and container image scanning as part of the software delivery pipeline Identify and remediate misconfigurations in pipeline environments and access control Web API Security - Design implement and monitor WAF rules and API protections perform API risk assessments and champion secure design patterns Code Review Testing - Conduct secure code reviews and support automation of testing pipelines Vulnerability Management - Triage prioritize and track security issues identified in code pipelines and deployed environments Threat Modeling Risk Assessment - Facilitate threat modeling sessions for applications APIs and pipeline workflows Tooling Automation - Expand security automation coverage including API discovery dependency scanning SBOM generation and secrets detection Security Champion Enablement - Mentor developers and DevOps engineers on secure pipeline and coding practices Collaboration Advisory - Act as a trusted partner to product platform engineering and DevOps leaders translating security risk into business impact Incident Support - Collaborate with SOC IR teams in response to software supply chain or pipeline compromises What you need to bring Qualifications Required 5-8 years of experience in Application Security Product Security or Secure Software Development Hands-on experience securing software delivery pipelines CI CD and source code repositories GitHub GitLab Jenkins Knowledge of supply chain security frameworks and controls e g SLSA NIST SSDF Familiarity with secrets management artifact signing Sigstore Cosign and build integrity practices Hands-on experience with WAF tuning API security controls and vulnerability remediation Proficiency with one or more programming languages Python Java Go JavaScript Node js Experience with SAST DAST SCA and container image scanning tools Cloud security experience with AWS Azure or GCP Deep understanding of OWASP Top 10 Web API CWE and secure coding practices Preferred Experience integrating SBOM generation and software composition analysis into software delivery pipelines Knowledge of runtime protection tools API security RASP EDR for containers Familiarity with GitOps Infrastructure as Code IaC scanning Terraform CloudFormation and policy-as-code solutions Experience responding to pipeline compromises or dependency poisoning incidents Relevant certifications OSWE CSSLP GPCS GIAC GWEB GIAC Cloud Security Automation GCSA Soft Skills Excellent communication skills with the ability to influence developers DevOps engineers and leadership Strong problem solving mindset with an automation first approach Collaborative outcome oriented and able to balance security with speed of delivery cybersecurity Additional Skills Accountability Accountability Action Planning Active Learning Active Listening Agile Methodology Bias Business Coaching Creativity Critical Thinking Cybersecurity Data Analysis Management Data Collection Management Inactive Data Controls Design Thinking Development Methodologies Empathy Follow-Through Growth Mindset Implementation Methodologies Infrastructure Design Intellectual Curiosity Inactive Long Term Planning Managing Ambiguity 4 more What We Can Offer You Health Wellbeing We strive to provide our team members and their loved ones with a comprehensive suite of benefits that supports their physical financial and emotional wellbeing Personal Professional Development We also invest in your career because the better you are the better we all are We have specific programs catered to helping you reach any career goals you have whether you want to become a knowledge expert in your field or apply your skills to another division Unconditional Inclusion We are unconditionally inclusive in the way we work and celebrate individual uniqueness We know varied backgrounds are valued and succeed here We have the flexibility to manage our work and personal needs We make bold moves together and are a force for good Let s Stay Connected Follow on Instagram to see the latest on people culture and tech at HPE india Job Information Technology Job Level TCP 04 HPE is an Equal Employment Opportunity Veterans Disabled LGBT employer We do not discriminate on the basis of race gender or any other protected category and all decisions we make are made on the basis of qualifications merit and business need Our goal is to be one global team that is representative of our customers in an inclusive environment where we can continue to innovate and grow together Please click here Hewlett Packard Enterprise is EEO Protected Veteran Individual with Disabilities HPE will comply with all applicable laws related to employer use of arrest and conviction records including laws requiring employers to consider for employment qualified applicants with criminal histories



  • Bangalore, Karnataka, India Victoria's Secret Full time

    Description Purpose Senior Security Engineer works within global information security function and will be responsible for Infrastructure and Application Pentest that includes Dynamic Application Security Testing API Pentest manual application and infrastructure Pentest Candidate will be responsible for ensuring the security and integrity of...


  • Bangalore, Karnataka, India Zscaler Full time

    About Zscaler Serving thousands of enterprise customers around the world including 45 of Fortune 500 companies Zscaler NASDAQ ZS was founded in 2007 with a mission to make the cloud a safe place to do business and a more enjoyable experience for enterprise users As the operator of the world s largest security cloud Zscaler accelerates digital...


  • Bangalore, Karnataka, India Amazon Full time

    DESCRIPTIONIn Amazon Stores we ship some of the widest arrays of technology found at any company From amazon com to world class machine learning pipelines from Innovative digital healthcare to no-checkout retail we push the boundaries of technology in every direction using the globe s largest AWS deployment As an AppSec engineer you will collaborate...


  • Bangalore, Karnataka, India ecolab Full time

    Job Position Senior Security Engineer - Product Security Location Bangalore Karnataka Experience 6-8 Years Department Information Security Employment Type Full-Time Overview Ecolab s Information Security team is seeking a Senior Security Engineer with strong expertise in Product Security to lead and enhance secure software development practices...


  • Bangalore, Karnataka, India Dell Full time

    Public Cloud Security Engineer- Senior Advisor The Dell Security Resiliency organization manages the security risk across all aspects of Dell s business You will have an excellent opportunity to influence the security culture at Dell and further develop your career Join us as a Public Cloud Security Engineer- Senior Advisor on our Cybersecurity...


  • Bangalore, Karnataka, India Victoria's Secret Full time

    Description Purpose Our team is seeking an experienced technologist to join our Cybersecurity team This Engineer is responsible for designing implementing and managing micro-segmentation strategies using advanced solutions to enhance network security within the organization s data centres remote offices and cloud environments This role involves...


  • Bangalore, Karnataka, India ResMed Full time

    The Information Technology IT team plays a key role in providing business enablement throughout ResMed We are focused on application infrastructure and user productivity solutions with innovation efficiency and security Our goal is providing customer oriented agile delivery effective business partnership and state-of-the-art technology solutions...


  • Bangalore, Karnataka, India Victoria's Secret Full time

    Description Purpose Our team is seeking an experienced Security engineer to join our Cybersecurity team This Engineer is responsible for securing cloud environments by implementing and managing security controls detecting threats and establishing robust logging systems to monitor and audit cloud infrastructure and data Responsibilities include...


  • Bangalore, Karnataka, India Jobted IN C2 Full time

    Note By applying to this position you will have an opportunity to share your preferred working location from the following Bengaluru Karnataka India Hyderabad Telangana India Minimum qualifications Bachelor s degree or equivalent practical experience 5 years of coding experience in one or more general purpose languages 5 years of experience with...


  • Bangalore, India Slice Full time

    About Us slice the way you bank slice’s purpose is to make the world better at using money and time, with a major focus on building the best consumer experience for your money. We’ve all felt how slow, confusing, and complicated banking can be. So, we’re reimagining it. We’re building every product from scratch to be fast, transparent, and feel...