Senior Application Security Engineer

3 hours ago


bangalore, India DigiCert Full time

Who we areWe're a leading, global security authority that's disrupting our own category.  Our encryption is trusted by the major ecommerce brands, the world's largest companies, the major cloud providers, entire country financial systems, entire internets of things and even down to the little things like surgically embedded pacemakers.  We help companies put trust - an abstract idea - to work. That's digital trust for the real world.Job summaryAs a Senior Application Security Engineer specializing in application security and DevSecOps within our cybersecurity team, you will play a crucial role in safeguarding our company's web applications by integrating security practices into the Software Development Life Cycle (SDLC). You will be responsible for the proactive identification, assessment, and mitigation of security vulnerabilities, developing and driving the adoption of DevSecOps practices, and ensuring that security is embedded in all phases of software development.What you will doLead the integration of security measures into the SDLC, ensuring that all aspects of web application development are secure by design.Conduct thorough security assessments and penetration testing for web applications to identify vulnerabilities and security gaps.Play an advisory role with software engineering teams in the architectural design of new applications, emphasizing secure architectural patterns and best practices.Perform and coordinate manual and automated code reviews.Lead threat modeling exercises across engineering teams.Collaborate with software development teams to implement DevSecOps practices, providing guidance on secure coding, automated security testing, and continuous monitoring.Contribute to internal security tooling development or integration.Develop and maintain a secure framework for code deployment, automating security processes where possible to streamline the development workflow.Work cross-functionally with various teams, including IT, engineering, operations, and business units, to communicate security policies and procedures effectively.Establish and maintain strong relationships with stakeholders, presenting complex security concepts in an accessible manner.Stay abreast of the latest security threats, trends, and technologies in web application security and incorporate this knowledge into company practices.Assist in the development and enforcement of security policies and procedures, ensuring compliance with industry standards and regulations.Assist with managing bug bounty program.Develop program documentation to promote operational stability and scalability.Support Leadership in defining and executing the roadmap for DevSecOps maturity and secure SDLC initiatives.Support governance and compliance teams on secure engineering practices for aligning security policies related to SDLCDrive and support security identified remediation efforts.Foster and promote a security-forward culture.Mentor junior team members.Other duties and responsibilities, as assigned.What you will have5+ years of experience in cybersecurity, with a focus on web application security and secure SDLC.Proficiency with programming/scripting languages such as JavaScript, Python, Java, Bash, PowerShell.Experience in penetration testing.Bachelor's or master's degree in computer science, cybersecurity, or a related field.Proven track record of working with DevSecOps tools (such as SAST/DAST/SCA) and methodologies.Strong understanding of security protocols, cryptography, authentication, authorization, and security vulnerabilities.Excellent communication skills with the ability to engage technical and non-technical stakeholders.Strong analytical and problem-solving abilities, with a meticulous attention to detail.Advanced level of knowledge of Information Security design concepts and principles.Nice to haveMaster's degree in a technical disciplineProfessional security certifications such as CISSP, OSCP, CEH, or equivalent are highly desirable.Experience working in highly regulated environments.Advanced level of knowledge of IT frameworks and standards (NIST, OWASP Top Ten, COBIT, ITIL, ISO, PCI-PIN, GDPR, WebTrust, FedRAMP)Certified Information Systems Auditor (CISA)AWS Solutions ArchitectBenefitsGenerous time off policiesTop shelf benefitsEducation, wellness and lifestyle support#LI-GA1



  • bangalore, India Symosis Security Full time

    Location: Remote (India)Type: Full-TimeCompany: Symosis SecurityAbout Symosis SecuritySymosis Security is a fast-growing cybersecurity and technology firm helping global organizations strengthen their cloud, application, and AI security posture. We combine deep technical expertise with practical execution—supporting clients across threat modeling,...


  • bangalore, India Symosis Security Full time

    Location : Remote (India) Type : Full-Time Company : Symosis Security About Symosis Security Symosis Security is a fast-growing cybersecurity and technology firm helping global organizations strengthen their cloud, application, and AI security posture. We combine deep technical expertise with practical execution—supporting clients across threat modeling,...


  • bangalore, India Symosis Security Full time

    Location: Remote (India)Type: Full-TimeCompany: Symosis SecurityAbout Symosis SecuritySymosis is a cybersecurity consulting firm purpose-built for the AI-native, cloud-first era. We help public-sector and enterprise clients mature their security operations through managed services, offensive testing, governance, and automation. We’re expanding our MSSP...


  • bangalore, India Zeta Global Full time

    We're seeking a Senior Application Security Engineer to help strengthen Zeta's application and platform security posture. You'll play a critical role in embedding security throughout the software development lifecycle, ensuring our systems, applications, and AI-driven platforms are built securely from the ground up.Zeta operates at massive scale, powering...


  • Bangalore, India Atomicwork Full time

    About Atomicwork Atomicwork is reimagining IT and workplace operations by putting employees at the center of the experience. With a strong emphasis on automation, integration, and security, Atomicwork helps organizations streamline workflows, improve productivity, and reduce friction across employee and IT interactions. Role Overview We are looking for a...


  • bangalore, India NETSACH GLOBAL Full time

    Greetings from Netsach - A Cyber Security Company.We are looking for Application security Engineers (2 resources) with 8+ yrs of strong experience who would be responsible for providing technical expertise on secure software development and support of all associated activities, processes, and tools for protecting technology-based informationJob Titlle:...


  • bangalore district, India Atomicwork Full time

    About Atomicwork Atomicwork is reimagining IT and workplace operations by putting employees at the center of the experience. With a strong emphasis on automation, integration, and security, Atomicwork helps organizations streamline workflows, improve productivity, and reduce friction across employee and IT interactions. Role Overview We are looking for a...


  • bangalore, India Sphera Full time

    Sphera is a leading global provider of enterprise software and services that enables companies to manage and optimize their environmental, health, safety and sustainability. Our mission is to create a safer, more sustainable and productive world.Sphera is a portfolio company of Blackstone, a U.S.-based alternative asset investment company that focuses on...


  • bangalore, India Clinisys Full time

    In this role, as an Application Security Engineer, you will work as a part of our security engineering team and you will collaborate with other IT professionals to ensure that data is protected. You will be responsible for suggesting and implementing with best security practices within software development lifecycle (SDLC). You will responsible for setting...


  • bangalore, India Deep Armor Full time

    Years of Experience: 6-10 yearsAbout the RoleWe’re looking for a Senior Security Engineer to lead and support product security efforts for cloud-hosted web applications. You will be responsible for deep-tech product security design reviews, code reviews, threat modeling, and other technical activities in software security development life cycle.Key...