Application Security Engineer

17 hours ago


Pune Maharashtra, India BMC Software Full time

Description and RequirementsHybrid LI-Hybrid At BMC trust is not just a word - it s a way of life We are an award-winning equal opportunity culturally diverse fun place to be Giving back to the community drives us to be better every single day Our work environment allows you to balance your priorities because we know you will bring your best every day We will champion your wins and shout them from the rooftops Your peers will inspire drive support you and make you laugh out loud We help our customers free up time and space to become an Autonomous Digital Enterprise that conquers the opportunities ahead - and are relentless in the pursuit of innovation The IZOT product line includes BMC s Intelligent Z Optimization Transformation products which help the world s largest companies to monitor and manage their mainframe systems The modernization of mainframe is the beating heart of our product line and we achieve this goal by developing products that improve the developer experience the mainframe integration the speed of application development the quality of the code and the applications security while reducing operational costs and risks We acquired several companies along the way and we continue to grow innovate and perfect our solutions on an ongoing basis We are looking for Application Security Engineer to take ownership of security testing for enterprise products deployed on mainframe environments In this role you will assess application-layer security risks identify vulnerabilities in product implementations and lead secure architecture reviews The ideal candidate brings deep offensive security skills along with familiarity in testing applications running on or integrated with IBM mainframe systems Primary Roles and Responsibilities Conduct penetration testing and red teaming exercises targeting mainframe environments and the surrounding application ecosystem Perform code-assisted and black-box penetration testing against enterprise applications systems interacting with RACF DB2 CICS MQ and related subsystems Identify risks in authentication authorization data handling and communications within mainframe-integrated products Create threat models and guide product teams in mitigating high-impact vulnerabilities early in the SDLC Drive remediation efforts through hands-on collaboration and secure design guidance Author technical reports and deliver executive summaries tailored to various audiences Stay current on vulnerabilities exploits and testing techniques relevant to legacy enterprise technologies and mainframe ecosystems Assess common integration patterns SOA REST JSON MQ for security risks To ensure you re set up for success you will bring the following skillset experience 5 years of experience in penetration testing with a specialization in systems applications integrating with mainframe environments Deep knowledge of mainframe communication protocols and security mechanisms Demonstrated experience conducting red team-style assessments or advanced threat emulation on mainframe systems Proficient in tools such as Mainframe utilities REXX ISPF panels NetView Security tools Nmap Burp Suite Wireshark custom scripts Strong scripting and automation skills Python REXX Bash or similar Strong communication and leadership skills with a proven ability to lead technical teams or projects Experience producing board-level reports and presenting findings to senior stakeholders Exposure to hybrid environments mainframe to cloud integrations modernization efforts Familiarity with modern enterprise integration methods REST SOAP MQ FTP that interface with mainframe services Whilst these are nice to have our team can help you develop in the following skills Industry certifications such as OSCP OSCE CRTP GIAC GPEN GXPN or CISSP Background in regulated industries such as banking insurance or government where mainframes are core infrastructure Knowledge of COBOL PL I or other mainframe-centric programming languages Experience with compliance standards like PCI-DSS NIST or SOX as they apply to mainframes CA-DNPOur commitment to you BMC s culture is built around its people We have 6000 brilliant minds working together across the globe You won t be known just by your employee number but for your true authentic self BMC lets you be YOU If after reading the above You re unsure if you meet the qualifications of this role but are deeply excited about BMC and this team we still encourage you to apply We want to attract talents from diverse backgrounds and experience to ensure we face the world together with the best ideas BMC is committed to equal opportunity employment regardless of race age sex creed color religion citizenship status sexual orientation gender gender expression gender identity national origin disability marital status pregnancy disabled veteran or status as a protected veteran If you need a reasonable accommodation for any part of the application and hiring process visit the accommodation request page



  • Pune, India Symosis Security Full time

    Location : Remote (India) Type : Full-Time Company : Symosis Security About Symosis Security Symosis Security is a fast-growing cybersecurity and technology firm helping global organizations strengthen their cloud, application, and AI security posture. We combine deep technical expertise with practical execution—supporting clients across threat modeling,...


  • Pune, India TAC Security Full time

    Job Description Key Responsibilities - Conduct security assessments by scanning applications and networks, performing penetration tests for further exploitation. - Execute Web Application SAST, DAST, Mobile Application Security testing, and API security testing. - Establish and maintain a Vulnerability Management framework including assessment, treatment,...


  • Pune, Maharashtra, India Princeton IT America Full time ₹ 20,00,000 - ₹ 40,00,000 per year

    Job Title: Security Application EngineerLocation: PuneExperience: 5–8 yearsNotice Period: Immediate Joiners PreferredJob Overview:We are seeking an experienced Security Application Engineer to strengthen our product security posture across the software development lifecycle. The ideal candidate will have strong expertise in product security and application...


  • Pune, Maharashtra, India Domo Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Company OverviewDomo's AI and Data Products Platform lets people channel AI and data into innovative uses that deliver a measurable impact. Anyone can use Domo to prepare, analyze, visualize, automate, and build data products that are amplified by AI.Domo is a native cloud-native data experiences innovator that puts data to work for everyone. Underpinned by...


  • Pune, Maharashtra, India Princeton IT America Full time ₹ 20,00,000 - ₹ 25,00,000 per year

    Here are the mandatory skill set.Job Tittle: Security Application EngineerLocation: PuneNP: ImmediateCyber security -- umbrella- product security - main skill- application security - it will work- network security - basic knowledge is needed- infrastructure security - not neededTools to considerCoverityNessusblackduckthreat modeleririus riskskills to...


  • Pune, India Microstrategy Full time

    Job Description - Security Architecture:Design and implement application security architecture and processes, ensuring they align with industry best practices and regulatory requirements. - Secure SDLC:Manage a risk-balanced SDLC by integrating threat modeling, secure code reviews, and security testing. - Vulnerability Management:Identify, triage, and...


  • Pune, Maharashtra, India Verto Full time ₹ 1,00,00,000 - ₹ 2,00,00,000 per year

    About VertoAt Verto, we're on a mission to democratise global finance and empower businesses in Emerging Markets to reach the world. Founded by British-Nigerian entrepreneurs Ola Oyetayo and Anthony Oduu, our roots in Africa provided a firsthand understanding of the significant challenges businesses face with cross-border payments, ranging from illiquid...


  • Pune, Maharashtra, India BMC Software Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    We are looking for Application Security Engineer to take ownership of security testing for enterprise products deployed on mainframe environments. In this role, you will assess application-layer security risks, identify vulnerabilities in product implementations, and lead secure architecture reviews. The ideal candidate brings deep offensive security skills...


  • Bhandup, Mumbai, Maharashtra, India PageNTRA Infosec PVT LTD Full time ₹ 4,50,000 - ₹ 10,00,000 per year

    Role SummaryApplication Security Engineer (VAPT & API Security) will be responsible for protecting our clients' web applications and APIs by serving as the subject matter expert (SME) for our Web Application Firewall (WAF) service. This role requires a strong offensive security mindset to conduct comprehensive vulnerability assessments, translate findings...


  • Pune, India Copeland Full time

    In this Role, Your Responsibilities Will Be: Analysis of UML diagrams and DFDs/Threat Models for security flaws and detailing specific recommendations in software and system setup to address them Mentoring of developers on security topics and coding Develop and deliver trainings to developers and management on security topics Analyzing requirements and...