Senior Application Security Engineer

3 weeks ago


Bangalore Karnataka, India Hewlett Packard Enterprise Full time

Senior Application Security Engineer This role has been designed as Hybrid with an expectation that you will work on average 2 days per week from an HPE office Who We Are Hewlett Packard Enterprise is the global edge-to-cloud company advancing the way people live and work We help companies connect protect analyze and act on their data and applications wherever they live from edge to cloud so they can turn insights into outcomes at the speed required to thrive in today s complex world Our culture thrives on finding new and better ways to accelerate what s next We know varied backgrounds are valued and succeed here We have the flexibility to manage our work and personal needs We make bold moves together and are a force for good If you are looking to stretch and grow your career our culture will embrace you Open up opportunities with HPE About our Cybersecurity team Are you ready to make an impact at one of the world s leading tech companies HPE s Cybersecurity team is where you can do just that We re looking for an Expert level Cybersecurity Incident Response Analyst to join our Incident Command team in Bangalore As an expert you will be responsible for leading the detection analysis containment and remediation of cybersecurity incidents across the organization This role demands a deep technical understanding of cyber threats advanced incident handling skills and the ability to act decisively in high-pressure situations You will work closely with other cybersecurity teams to ensure a coordinated and effective response to security incidents helping to minimize the impact on the organization Within the scope of the role will be mentoring junior team members and contributing to the continuous improvement of the organization s incident response capabilities What you ll do Key Responsibilities Secure SDLC DevSecOps Integration - Partner with engineering and DevOps teams to embed security into the entire software delivery process Software Delivery Pipeline CI CD Security - Design and implement security controls for build and release pipelines GitHub Actions Jenkins GitLab Azure DevOps etc Ensure code integrity via signing artifact scanning and build provenance Automate SAST DAST SCA and container image scanning as part of the software delivery pipeline Identify and remediate misconfigurations in pipeline environments and access control Web API Security - Design implement and monitor WAF rules and API protections perform API risk assessments and champion secure design patterns Code Review Testing - Conduct secure code reviews and support automation of testing pipelines Vulnerability Management - Triage prioritize and track security issues identified in code pipelines and deployed environments Threat Modeling Risk Assessment - Facilitate threat modeling sessions for applications APIs and pipeline workflows Tooling Automation - Expand security automation coverage including API discovery dependency scanning SBOM generation and secrets detection Security Champion Enablement - Mentor developers and DevOps engineers on secure pipeline and coding practices Collaboration Advisory - Act as a trusted partner to product platform engineering and DevOps leaders translating security risk into business impact Incident Support - Collaborate with SOC IR teams in response to software supply chain or pipeline compromises What you need to bring Qualifications Required 5-8 years of experience in Application Security Product Security or Secure Software Development Hands-on experience securing software delivery pipelines CI CD and source code repositories GitHub GitLab Jenkins Knowledge of supply chain security frameworks and controls e g SLSA NIST SSDF Familiarity with secrets management artifact signing Sigstore Cosign and build integrity practices Hands-on experience with WAF tuning API security controls and vulnerability remediation Proficiency with one or more programming languages Python Java Go JavaScript Node js Experience with SAST DAST SCA and container image scanning tools Cloud security experience with AWS Azure or GCP Deep understanding of OWASP Top 10 Web API CWE and secure coding practices Preferred Experience integrating SBOM generation and software composition analysis into software delivery pipelines Knowledge of runtime protection tools API security RASP EDR for containers Familiarity with GitOps Infrastructure as Code IaC scanning Terraform CloudFormation and policy-as-code solutions Experience responding to pipeline compromises or dependency poisoning incidents Relevant certifications OSWE CSSLP GPCS GIAC GWEB GIAC Cloud Security Automation GCSA Soft Skills Excellent communication skills with the ability to influence developers DevOps engineers and leadership Strong problem solving mindset with an automation first approach Collaborative outcome oriented and able to balance security with speed of delivery cybersecurity Additional Skills Accountability Accountability Action Planning Active Learning Active Listening Agile Methodology Bias Business Coaching Creativity Critical Thinking Cybersecurity Data Analysis Management Data Collection Management Inactive Data Controls Design Thinking Development Methodologies Empathy Follow-Through Growth Mindset Implementation Methodologies Infrastructure Design Intellectual Curiosity Inactive Long Term Planning Managing Ambiguity 4 more What We Can Offer You Health Wellbeing We strive to provide our team members and their loved ones with a comprehensive suite of benefits that supports their physical financial and emotional wellbeing Personal Professional Development We also invest in your career because the better you are the better we all are We have specific programs catered to helping you reach any career goals you have whether you want to become a knowledge expert in your field or apply your skills to another division Unconditional Inclusion We are unconditionally inclusive in the way we work and celebrate individual uniqueness We know varied backgrounds are valued and succeed here We have the flexibility to manage our work and personal needs We make bold moves together and are a force for good Let s Stay Connected Follow on Instagram to see the latest on people culture and tech at HPE india Job Information Technology Job Level TCP 04 HPE is an Equal Employment Opportunity Veterans Disabled LGBT employer We do not discriminate on the basis of race gender or any other protected category and all decisions we make are made on the basis of qualifications merit and business need Our goal is to be one global team that is representative of our customers in an inclusive environment where we can continue to innovate and grow together Please click here Hewlett Packard Enterprise is EEO Protected Veteran Individual with Disabilities HPE will comply with all applicable laws related to employer use of arrest and conviction records including laws requiring employers to consider for employment qualified applicants with criminal histories


  • Senior Engineer

    5 days ago


    Bangalore, Karnataka, India United Airlines Full time

    We are seeking a skilled Engineer Application Security resource to help us develop solutions to automate the security compliance operation improve application security posture management and drive for shift-left security to reduce the vulnerabilities The ideal candidate will have experience with application development and CI CD pipelines sufficient...


  • Bangalore, India Atomicwork Full time

    About Atomicwork Atomicwork is reimagining IT and workplace operations by putting employees at the center of the experience. With a strong emphasis on automation, integration, and security, Atomicwork helps organizations streamline workflows, improve productivity, and reduce friction across employee and IT interactions. Role Overview We are looking for a...


  • Bangalore, India Atomicwork Full time

    About Atomicwork Atomicwork is reimagining IT and workplace operations by putting employees at the center of the experience. With a strong emphasis on automation, integration, and security, Atomicwork helps organizations streamline workflows, improve productivity, and reduce friction across employee and IT interactions. Role Overview We are looking for a ...


  • Bangalore, India Atomicwork Full time

    About Atomicwork Atomicwork is reimagining IT and workplace operations by putting employees at the center of the experience. With a strong emphasis on automation, integration, and security, Atomicwork helps organizations streamline workflows, improve productivity, and reduce friction across employee and IT interactions. We are looking for a Senior...


  • Bangalore, Karnataka, India Michael Page Full time

    As a Senior Engineer on the Application Platform team you ll lead the design and development of secure scalable web platforms that support healthcare innovation You ll also mentor peers and drive architectural excellence to ensure high performance and compliance Design and implement scalable secure and performant application architectures including APIs and...


  • bangalore district, India Atomicwork Full time

    About Atomicwork Atomicwork is reimagining IT and workplace operations by putting employees at the center of the experience. With a strong emphasis on automation, integration, and security, Atomicwork helps organizations streamline workflows, improve productivity, and reduce friction across employee and IT interactions. Role Overview We are looking for a...


  • Bangalore, Karnataka, India Victoria's Secret Full time

    Description Purpose Senior Security Engineer works within global information security function and will be responsible for Infrastructure and Application Pentest that includes Dynamic Application Security Testing API Pentest manual application and infrastructure Pentest Candidate will be responsible for ensuring the security and integrity of...


  • Bengaluru, Karnataka, India, Karnataka Atomicwork Full time

    About AtomicworkAtomicwork is reimagining IT and workplace operations by putting employees at the center of the experience. With a strong emphasis on automation, integration, and security, Atomicwork helps organizations streamline workflows, improve productivity, and reduce friction across employee and IT interactions.Role OverviewWe are looking for a Senior...


  • Bangalore, Karnataka, India Ivanti Full time

    Job Title Staff Security Engineer Location Bangalore EMEA-Remote Are you an experienced Staff Security Engineer driven to deliver cutting-edge security solutions and champion technical excellence At Ivanti you will play a pivotal role in shaping the future of secure digital work by designing and enhancing world-class products used across the globe Join our...


  • Bangalore, Karnataka, India Amazon Full time

    DESCRIPTIONIn Amazon Stores we ship some of the widest arrays of technology found at any company From amazon com to world class machine learning pipelines from Innovative digital healthcare to no-checkout retail we push the boundaries of technology in every direction using the globe s largest AWS deployment As an AppSec engineer you will collaborate...