
Senior Application Security Engineer
2 days ago
Job Description
Who we are
We&aposre a leading, global security authority that&aposs disrupting our own category. Our encryption is trusted by the major ecommerce brands, the world&aposs largest companies, the major cloud providers, entire country financial systems, entire internets of things and even down to the little things like surgically embedded pacemakers. We help companies put trust - an abstract idea - to work. That&aposs digital trust for the real world.
Job summary
As a Senior Application Security Engineer specializing in application security and DevSecOps within our cybersecurity team, you will play a crucial role in safeguarding our company&aposs web applications by integrating security practices into the Software Development Life Cycle (SDLC). You will be responsible for the proactive identification, assessment, and mitigation of security vulnerabilities, developing and driving the adoption of DevSecOps practices, and ensuring that security is embedded in all phases of software development.
What you will do
- Lead the integration of security measures into the SDLC, ensuring that all aspects of web application development are secure by design.
- Conduct thorough security assessments and penetration testing for web applications to identify vulnerabilities and security gaps.
- Play an advisory role with software engineering teams in the architectural design of new applications, emphasizing secure architectural patterns and best practices.
- Perform and coordinate manual and automated code reviews.
- Lead threat modeling exercises across engineering teams.
- Collaborate with software development teams to implement DevSecOps practices, providing guidance on secure coding, automated security testing, and continuous monitoring.
- Contribute to internal security tooling development or integration.
- Develop and maintain a secure framework for code deployment, automating security processes where possible to streamline the development workflow.
- Work cross-functionally with various teams, including IT, engineering, operations, and business units, to communicate security policies and procedures effectively.
- Establish and maintain strong relationships with stakeholders, presenting complex security concepts in an accessible manner.
- Stay abreast of the latest security threats, trends, and technologies in web application security and incorporate this knowledge into company practices.
- Assist in the development and enforcement of security policies and procedures, ensuring compliance with industry standards and regulations.
- Assist with managing bug bounty program.
- Develop program documentation to promote operational stability and scalability.
- Support Leadership in defining and executing the roadmap for DevSecOps maturity and secure SDLC initiatives.
- Support governance and compliance teams on secure engineering practices for aligning security policies related to SDLC
- Drive and support security identified remediation efforts.
- Foster and promote a security-forward culture.
- Mentor junior team members.
- Other duties and responsibilities, as assigned.
What you will have
- Minimum of 5 years of experience in cybersecurity, with a focus on web application security and secure SDLC.
- Proficiency with programming/scripting languages such as JavaScript, Python, Java, Bash, PowerShell
- Experience in penetration testing
- Bachelors or masters degree in computer science, cybersecurity, or a related field.
- Proven track record of working with DevSecOps tools (such as SAST/DAST/SCA) and methodologies.
- Strong understanding of security protocols, cryptography, authentication, authorization, and security vulnerabilities.
- Excellent communication skills with the ability to engage technical and non-technical stakeholders.
- Strong analytical and problem-solving abilities, with a meticulous attention to detail.
- Advanced level of knowledge of Information Security design concepts and principles
Nice to have
- Master&aposs degree in a technical discipline
- Professional security certifications such as CISSP, OSCP, CEH, or equivalent are highly desirable.
- Experience working in highly regulated environments.
- Advanced level of knowledge of IT frameworks and standards (NIST, OWASP Top Ten, COBIT, ITIL, ISO, PCI-PIN, GDPR, WebTrust, FedRAMP)
- Certified Information Systems Auditor (CISA)
- AWS Solutions Architect
Benefits
- Generous time off policies
- Top shelf benefits
- Education, wellness and lifestyle support
-
Senior Security Engineer
2 weeks ago
Bengaluru, Karnataka, India Skyhigh Security Full time US$ 1,25,000 - US$ 1,75,000 per yearJob Title:Senior Security EngineerAbout Skyhigh Security:Skyhigh Security is a dynamic, fast-paced, cloud company that is a leader in the security industry. Our mission is to protect the world's data, and because of this, we live and breathe security. We value learning at our core, underpinned by openness and transparency.Since 2011, organizations have...
-
Senior Application Security Engineer
2 weeks ago
Remote - India Twilio Full time ₹ 15,00,000 - ₹ 20,00,000 per yearSee yourself at Twilio Join the team as Twilio's next Senior Application Security Engineer(L3). About the job The Cloud and Application Security team enables delivery of secure by default products to reduce our attack surface against an evolving threat landscape. This position is needed to enhance Twilio's Application Security capabilities to improve...
-
Security Engineer
2 days ago
india Altered Security Full timeWe are looking for talentedSecurity Engineersto join our team!Altered Security is an information security startup with focus on edtech, hands-on learning and focused security assessments. It has offices in India and Singapore.We are experts in information security training, cyber ranges, online labs and security assessments. We have trained more than 40000+...
-
Security Engineer
2 weeks ago
India Altered Security Full timeWe are looking for talentedSecurity Engineersto join our teamAltered Security is an information security startup with focus on edtech, hands-on learning and focused security assessments. It has offices in India and Singapore.We are experts in information security training, cyber ranges, online labs and security assessments. We have trained more than 40000+...
-
Senior Application Security Engineer
2 weeks ago
India BitGo Full time US$ 1,50,000 - US$ 2,00,000 per yearBitGo is the leading infrastructure provider of digital asset solutions, delivering custody, wallets, staking, trading, financing, and settlement services from regulated cold storage. Since our founding in 2013, we have focused on enabling our clients to securely navigate the digital asset space. With a global presence and multiple Trust companies, BitGo...
-
Senior Application Security Engineer
2 weeks ago
Bengaluru, Karnataka, India DigiCert Full timeJob DescriptionWho we areWe&aposre a leading, global security authority that&aposs disrupting our own category. Our encryption is trusted by the major ecommerce brands, the world&aposs largest companies, the major cloud providers, entire country financial systems, entire internets of things and even down to the little things like surgically embedded...
-
Senior / Lead Security Engineer
2 weeks ago
India Protonlogics IT Solutions Full timeJob Title: Senior / Lead Security EngineerCompany: ConfidentialLocation: RemoteExp. Required- 5+ yearsEmployment Type: Full-time, PermanentAbout the RoleOur client is seeking a highly skilled Senior/Lead Security Engineer to join their growing Information Security & Compliance team. This role plays a key part in building and embedding a Secure Systems...
-
Senior / Lead Security Engineer
1 week ago
India Protonlogics IT Solutions Full timeJob Title: Senior / Lead Security Engineer Company: Confidential Location: Remote Exp. Required - 5+ years Employment Type: Full-time, Permanent About the Role Our client is seeking a highly skilled Senior/Lead Security Engineer to join their growing Information Security & Compliance team. This role plays a key part in building and...
-
Application Security Engineer
2 weeks ago
Bengaluru, Karnataka, India Uplers Full time ₹ 9,00,000 - ₹ 12,00,000 per yearSenior Security and Compliance EngineerExperience: 3 - 6 Years ExpSalary : competitivePreferred Notice Period: Within 30 DaysOpportunity Type: Hybrid (Bengaluru)Placement Type: Permanent(*Note: This is a requirement for one of Uplers' Clients)Must have skills required :Information Security OR Statutory Compliance, Cloud SecurityHiver (One of Uplers' Clients)...
-
Application Security Engineers
2 weeks ago
Bengaluru, Karnataka, India NETSACH GLOBAL Full time ₹ 15,00,000 - ₹ 20,00,000 per yearGreetings from Netsach - A Cyber Security Company.We are looking for Application security Engineers (2 resources) with 8+ yrs of strong experience who would be responsible for providing technical expertise on secure software development and support of all associated activities, processes, and tools for protecting technology-based informationJob Titlle:...