Application Security Engineer

6 days ago


Pune Maharashtra, India BMC Software Full time

Description and RequirementsHybrid LI-Hybrid At BMC trust is not just a word - it s a way of life We are an award-winning equal opportunity culturally diverse fun place to be Giving back to the community drives us to be better every single day Our work environment allows you to balance your priorities because we know you will bring your best every day We will champion your wins and shout them from the rooftops Your peers will inspire drive support you and make you laugh out loud We help our customers free up time and space to become an Autonomous Digital Enterprise that conquers the opportunities ahead - and are relentless in the pursuit of innovation The IZOT product line includes BMC s Intelligent Z Optimization Transformation products which help the world s largest companies to monitor and manage their mainframe systems The modernization of mainframe is the beating heart of our product line and we achieve this goal by developing products that improve the developer experience the mainframe integration the speed of application development the quality of the code and the applications security while reducing operational costs and risks We acquired several companies along the way and we continue to grow innovate and perfect our solutions on an ongoing basis We are looking for Application Security Engineer to take ownership of security testing for enterprise products deployed on mainframe environments In this role you will assess application-layer security risks identify vulnerabilities in product implementations and lead secure architecture reviews The ideal candidate brings deep offensive security skills along with familiarity in testing applications running on or integrated with IBM mainframe systems Primary Roles and Responsibilities Conduct penetration testing and red teaming exercises targeting mainframe environments and the surrounding application ecosystem Perform code-assisted and black-box penetration testing against enterprise applications systems interacting with RACF DB2 CICS MQ and related subsystems Identify risks in authentication authorization data handling and communications within mainframe-integrated products Create threat models and guide product teams in mitigating high-impact vulnerabilities early in the SDLC Drive remediation efforts through hands-on collaboration and secure design guidance Author technical reports and deliver executive summaries tailored to various audiences Stay current on vulnerabilities exploits and testing techniques relevant to legacy enterprise technologies and mainframe ecosystems Assess common integration patterns SOA REST JSON MQ for security risks To ensure you re set up for success you will bring the following skillset experience 5 years of experience in penetration testing with a specialization in systems applications integrating with mainframe environments Deep knowledge of mainframe communication protocols and security mechanisms Demonstrated experience conducting red team-style assessments or advanced threat emulation on mainframe systems Proficient in tools such as Mainframe utilities REXX ISPF panels NetView Security tools Nmap Burp Suite Wireshark custom scripts Strong scripting and automation skills Python REXX Bash or similar Strong communication and leadership skills with a proven ability to lead technical teams or projects Experience producing board-level reports and presenting findings to senior stakeholders Exposure to hybrid environments mainframe to cloud integrations modernization efforts Familiarity with modern enterprise integration methods REST SOAP MQ FTP that interface with mainframe services Whilst these are nice to have our team can help you develop in the following skills Industry certifications such as OSCP OSCE CRTP GIAC GPEN GXPN or CISSP Background in regulated industries such as banking insurance or government where mainframes are core infrastructure Knowledge of COBOL PL I or other mainframe-centric programming languages Experience with compliance standards like PCI-DSS NIST or SOX as they apply to mainframes CA-DNPOur commitment to you BMC s culture is built around its people We have 6000 brilliant minds working together across the globe You won t be known just by your employee number but for your true authentic self BMC lets you be YOU If after reading the above You re unsure if you meet the qualifications of this role but are deeply excited about BMC and this team we still encourage you to apply We want to attract talents from diverse backgrounds and experience to ensure we face the world together with the best ideas BMC is committed to equal opportunity employment regardless of race age sex creed color religion citizenship status sexual orientation gender gender expression gender identity national origin disability marital status pregnancy disabled veteran or status as a protected veteran If you need a reasonable accommodation for any part of the application and hiring process visit the accommodation request page



  • Pune, Maharashtra, India Princenton software services pvt ltd Full time ₹ 5,14,000 - ₹ 22,47,318 per year

    Job Summary:Do you love software and system security? Do you have a strong background in software development? Want to exercise your skills across many OS and hardware platforms in a critical function in a growing team? Want the stability of a Fortune 500 company and the challenges of a multi-site, international development group serving a world-wide,...


  • Pune, Maharashtra, India Urbint Full time

    Job Summary :We are seeking an Application Security Engineer-II to help embed security within Urbints software development lifecycle and scale our product security practices. This role focuses on enabling developers with the right tools, patterns, and guidance, while collaborating with engineering, CloudOps, and InfoSec to proactively identify, assess, and...


  • Pune, Maharashtra, India TripleLift Full time

    About TripleLift : We're TripleLift, an advertising platform on a mission to elevate digital advertising through beautiful creative, quality publishers, actionable data and smart targeting. Through over 1 trillion monthly ad transactions, we help publishers and platforms monetize their businesses. Our technology is where the world's leading brands find...


  • Pune, India Apex One Full time

    Key Responsibilities:Conduct comprehensive application security assessments, focusing on the OWASP Top 10 for web and mobile applications.Utilize vulnerability assessment tools to identify and analyze security risks within applications and systems.Collaborate with development teams to integrate security practices into the software development lifecycle...


  • Pune, India TripleLift Full time

    About TripleLiftWe're TripleLift, an advertising platform on a mission to elevate digital advertising through beautiful creative, quality publishers, actionable data and smart targeting. Through over 1 trillion monthly ad transactions, we help publishers and platforms monetize their businesses. Our technology is where the world's leading brands find...


  • pune, India Randstad Full time

     Work within an agile development team and lead at an engineering level the design, development, deployment, and maintenance of software security tooling. Collaborate with development teams to integrate software security into the software development lifecycle (SDLC).  Develop and maintain software security policies, standards, and...


  • Pune, India Urbint Full time

    Job Summary :We are seeking an Application Security Engineer-II to help embed security within Urbints software development lifecycle and scale our product security practices. This role focuses on enabling developers with the right tools, patterns, and guidance, while collaborating with engineering, CloudOps, and InfoSec to proactively identify, assess, and...


  • Pune, Maharashtra, India NPG Consultants Full time

    Lead secure-by-design initiatives for AWS-hosted applications. Combine AppSec expertise with hands-on development and cloud-native architecture to enable scalable security design patterns, proactive threat modeling, and secure SDLC practices for microservices, APIs, and serverless workloads.Key Responsibilities : - Design and implement application security...


  • Pune, India Aera Technology Full time

    Job Description Aera Technology is the Decision Intelligence company. We deliver innovation and services that enable enterprises to operate sustainably, intelligently, and efficiently. Our platform, Aera Decision Cloud, integrates with your existing systems to digitize, augment, and automate decisions in real time. Aera helps enterprises around the world...


  • Bengaluru, Hyderabad, Pune, India Infosys Full time ₹ 15,00,000 - ₹ 25,00,000 per year

    About the Role:We are looking for experienced and passionate Application Security Automation Engineers to join our team. This role involves securing web applications, automating security processes, and integrating security into the software development lifecycle. The ideal candidate will have strong programming skills, a deep understanding of application...