Application Security Engineer
3 days ago
Role Description: As an Application Security Engineer at Booking.com, you will play a critical role in safeguarding one of the world's largest online travel platforms. This position sits at the intersection of security and software development, focusing on identifying, preventing, and mitigating security vulnerabilities throughout the application development lifecycle. In this role, you will collaborate with development teams to implement secure coding practices, conduct security assessments of applications, and develop automated security testing solutions. You'll leverage your expertise in vulnerability assessment, and secure software development to protect Booking.com's extensive digital infrastructure and the sensitive data of millions of users worldwide. The ideal candidate combines strong technical security knowledge with excellent communication skills to effectively partner with cross-functional teams in Booking.com's dynamic, global environment. This position offers the opportunity to make a significant impact on the security posture of a technology leader in the travel industry. Key Responsibilities - Manage and triage vulnerability reports from HackerOne and internal assessments, conduct validation and impact analysis, and maintain comprehensive tracking dashboards for security posture visibility - Partner with development teams to communicate vulnerability details, provide remediation guidance, review proposed fixes, and facilitate security design reviews and threat modeling sessions - Conduct manual security testing, code reviews, and penetration testing of applications and APIs while developing automated vulnerability scanning processes for CI/CD integration - Coordinate with bug bounty platforms to optimize program scopes and researcher engagement, manage responsible disclosure processes, and maintain relationships with external security researchers - Lead security incident response for critical vulnerabilities, prepare executive reports on security risk posture, and develop security training materials and workshops for development teams - Collaborate with development teams to implement secure coding practices and review application architectures for security considerations - Provide guidance and training to development teams on application security best practices - Stay current on emerging threats and vulnerabilities to proactively enhance security controls What We Are Looking For - Bachelor's degree in Computer Science, Cybersecurity, or a related field, or equivalent experience - 3-5 years years of experience in application security or information security roles with at least 1 years fulltime and exclusive experience in the given area of vulnerability management. - Demonstrated experience configuring and managing Web Application Firewall solutions (e.g., AWS WAF, Cloudflare, F5, Imperva) - Strong understanding of OWASP Top 10 vulnerabilities and mitigation strategies - Knowledge of secure coding practices and common web application vulnerabilities - Scripting and automation skills using Python, or similar languages - Knowledge of DevSecOps practices and tools for integrating security into CI/CD pipelines - Excellent communication skills to explain technical security concepts to non-technical stakeholders - Knowledge of compliance requirements related to application security (e.g., PCI DSS, GDPR) Nice to Have - Security certifications such as OSCP, OSWA and OSWE. - Experience with cloud security and securing applications in AWS, Azure, or GCP environments - Experience with API security and securing microservices architectures - Experience with threat modeling and risk assessment methodologies - Contributions to the security community through research, blog posts, or open-source projects
-
Senior Security Engineer – Cloud, AI
5 days ago
bangalore, India Symosis Security Full timeLocation: Remote (India)Type: Full-TimeCompany: Symosis SecurityAbout Symosis SecuritySymosis Security is a fast-growing cybersecurity and technology firm helping global organizations strengthen their cloud, application, and AI security posture. We combine deep technical expertise with practical execution—supporting clients across threat modeling,...
-
Senior Security Engineer
5 days ago
bangalore, India Symosis Security Full timeLocation : Remote (India) Type : Full-Time Company : Symosis Security About Symosis Security Symosis Security is a fast-growing cybersecurity and technology firm helping global organizations strengthen their cloud, application, and AI security posture. We combine deep technical expertise with practical execution—supporting clients across threat modeling,...
-
Senior Security Engineer – AI, Cloud
7 days ago
bangalore, India Symosis Security Full timeLocation: Remote (India)Type: Full-TimeCompany: Symosis SecurityAbout Symosis SecuritySymosis is a cybersecurity consulting firm purpose-built for the AI-native, cloud-first era. We help public-sector and enterprise clients mature their security operations through managed services, offensive testing, governance, and automation. We’re expanding our MSSP...
-
Application Security Engineer
2 days ago
bangalore, India Clinisys Full timeIn this role, as an Application Security Engineer, you will work as a part of our security engineering team and you will collaborate with other IT professionals to ensure that data is protected. You will be responsible for suggesting and implementing with best security practices within software development lifecycle (SDLC). You will responsible for setting...
-
Application Security Engineers
2 days ago
bangalore, India NETSACH GLOBAL Full timeGreetings from Netsach - A Cyber Security Company.We are looking for Application security Engineers (2 resources) with 8+ yrs of strong experience who would be responsible for providing technical expertise on secure software development and support of all associated activities, processes, and tools for protecting technology-based informationJob Titlle:...
-
Application Security Engineer
2 days ago
bangalore, India Dezerv Full timeDezerv is a house of investing solutions for high-net-worth and affluent Indians. Dezerv is co-founded by Sandeep Jethwani, Vaibhav Porwal, and Sahil Contractor. They have led successful wealth management businesses and managed over USD 7 billion in assets. The Dezerv team brings together decades of investing expertise from leading global financial...
-
Application Security Engineer
7 hours ago
Bangalore, India Dezerv Full timeDezerv is a house of investing solutions for high-net-worth and affluent Indians. Dezerv is co-founded by Sandeep Jethwani, Vaibhav Porwal, and Sahil Contractor. They have led successful wealth management businesses and managed over USD 7 billion in assets. The Dezerv team brings together decades of investing expertise from leading global financial...
-
Application Security Engineer
2 days ago
bangalore, India Dezerv Full timeDezerv is a house of investing solutions for high-net-worth and affluent Indians. Dezerv is co-founded by Sandeep Jethwani, Vaibhav Porwal, and Sahil Contractor. They have led successful wealth management businesses and managed over USD 7 billion in assets. The Dezerv team brings together decades of investing expertise from leading global financial...
-
Enterprise Applications Security Engineer
1 week ago
Bangalore, India Aviatrix Full timeWHO WE ARE: For enterprises struggling to secure cloud workloads, Aviatrix® offers a single solution for pervasive cloud security. Where current cybersecurity approaches focus on securing entry points to a trusted space, Aviatrix Cloud Native Security Fabric (CNSF) delivers runtime security and enforcement within the cloud application infrastructure itself...
-
Enterprise Applications Security Engineer
2 weeks ago
Bangalore, India Aviatrix Full timeWHO WE ARE: For enterprises struggling to secure cloud workloads, Aviatrix® offers a single solution for pervasive cloud security. Where current cybersecurity approaches focus on securing entry points to a trusted space, Aviatrix Cloud Native Security Fabric (CNSF) delivers runtime security and enforcement within the cloud application infrastructure itself...