Application Security Engineer
2 days ago
In this role, as an Application Security Engineer, you will work as a part of our security engineering team and you will collaborate with other IT professionals to ensure that data is protected. You will be responsible for suggesting and implementing with best security practices within software development lifecycle (SDLC). You will responsible for setting up security controls and design requirements during the software creation and development stage of the software lifecycle. You will also participate in related business and security projects. You will work closely with leadership and staff to extract data to support recommendations for new security-related procedures and/or revisions. This role will guide the organization on standard security methodologies.This position will also play a meaningful role in leading and responding to client security surveys and internal 3rd party audits. What you will be doing:- · Developing and maintaining software application security policies and procedures · Developing and maintaining documentation of application security controls · Implementing software application security controls · Designing technical solutions to address security weaknesses· Analyzing system services, spotting issues in code, networks and applications · Following security best practices in performing tasks · Providing technical leadership, guidance, and direction to the application security team · Participate in and support application security reviews and threat modeling, including code reviewand dynamic testing. · Support and consult with product and development teams in the area of application security.· Assist in development of automated security testing to validate that secure coding best practices are being used · Assist in creation of security training · Provide leadership for application vulnerability scanning and penetration testing remediation· Manage integration with vulnerability check tools such as Static Code Analysis and Dynamic Code Analysis tools · Prepare security reports for benchmarking security efficiency. · Act as a technical point of contact during escalated security events. · Responsible to manage Cybersecurity incident response. · Participate in the change management board, ensuring security is a consideration in all changes. · Provide support to the Information Security Manager on all application security activities · Determines security violations and inefficiencies by conducting periodic audits. · Provide evidence to the auditee for the Information Systems audits when needed. Essential Functions · Work closely with cross-functional teams (Engineering, DevOps, Product) while carrying out daily tasks · Security code reviews: Identify security vulnerabilities in source code before an application is deployed to production · Exploit security flaws and vulnerabilities with attack simulations on network as well as multiple application platforms like Web, iOS, Android and cloud platform. · Support the bug bounty program. · Perform application security vulnerability management using tools like (Acunetix, Veracode etc.)· Manage integration with vulnerability check tools such as Static Code Analysis and Dynamic Code Analysis tools · Understanding of patch management. Working the patch management team to analyze the risk of the breaking the environment with installing the patch. And also ensure deployment of patches in a timely manner while understanding business impact. · Investigate security breaches and other cybersecurity incidents. · Stay up to date on information technology trends and security standards. Skills needed to be successful. · Excellent analytical skills, with an ability to translate business needs into practical security posture. · Familiarity with common security libraries, security controls, and common security flaws · Strong analytical and problem-solving skills · Automation enablement to reduce testing workloads · Rapid decision-making to prevent delayed releases due to security issues · Basic development or scripting experience and skills · A good understanding of network and web related protocols (such as TCP/IP, UDP, HTTP, HTTPS, protocols). · Experience working with development team. · Knowledgeable with Anti-Virus, HIPS, ID/PS, Full Packet Capture, RSA Security · Familiarity with ISO 27001, SOC 2, NIST or other security frameworks · Ability to prioritize more than one task at a time · Assist in root cause analysis for incident management · Must have excellent written and spoken communication skills with the ability to explain technical information to non-technical people. · Willing to work non-standard hours and be on-call. Required Experience & Education · Bachelor's degree in Information Technology, Computer Science · 2 years of experience in information security industry · Experience with vulnerability scanning tool and solutions. ·Experience with OWASP, static/dynamic analysis, and common security tools ·Experience with Microsoft Windows, Linux, and macOS. Supervisory Responsibilities -NAOnboardingAs part of our onboarding process, all new employees will be required to attend / travel to the office on their first day of employment. This requirement is essential for onboarding activities, including the identity verification, completion of necessary documentation, receiving your IT equipment, introductions to key team members, and orientation to Clinisys policies and procedures.
-
Senior Security Engineer – Cloud, AI
5 days ago
bangalore, India Symosis Security Full timeLocation: Remote (India)Type: Full-TimeCompany: Symosis SecurityAbout Symosis SecuritySymosis Security is a fast-growing cybersecurity and technology firm helping global organizations strengthen their cloud, application, and AI security posture. We combine deep technical expertise with practical execution—supporting clients across threat modeling,...
-
Senior Security Engineer
5 days ago
bangalore, India Symosis Security Full timeLocation : Remote (India) Type : Full-Time Company : Symosis Security About Symosis Security Symosis Security is a fast-growing cybersecurity and technology firm helping global organizations strengthen their cloud, application, and AI security posture. We combine deep technical expertise with practical execution—supporting clients across threat modeling,...
-
Senior Security Engineer – AI, Cloud
7 days ago
bangalore, India Symosis Security Full timeLocation: Remote (India)Type: Full-TimeCompany: Symosis SecurityAbout Symosis SecuritySymosis is a cybersecurity consulting firm purpose-built for the AI-native, cloud-first era. We help public-sector and enterprise clients mature their security operations through managed services, offensive testing, governance, and automation. We’re expanding our MSSP...
-
Application Security Engineers
1 day ago
bangalore, India NETSACH GLOBAL Full timeGreetings from Netsach - A Cyber Security Company.We are looking for Application security Engineers (2 resources) with 8+ yrs of strong experience who would be responsible for providing technical expertise on secure software development and support of all associated activities, processes, and tools for protecting technology-based informationJob Titlle:...
-
Application Security Engineer
3 days ago
Bangalore, India Jobted IN C2 Full timeRole Description: As an Application Security Engineer at Booking.com, you will play a critical role in safeguarding one of the world's largest online travel platforms. This position sits at the intersection of security and software development, focusing on identifying, preventing, and mitigating security vulnerabilities throughout the application development...
-
Application Security Engineer
2 days ago
bangalore, India Dezerv Full timeDezerv is a house of investing solutions for high-net-worth and affluent Indians. Dezerv is co-founded by Sandeep Jethwani, Vaibhav Porwal, and Sahil Contractor. They have led successful wealth management businesses and managed over USD 7 billion in assets. The Dezerv team brings together decades of investing expertise from leading global financial...
-
Application Security Engineer
5 hours ago
Bangalore, India Dezerv Full timeDezerv is a house of investing solutions for high-net-worth and affluent Indians. Dezerv is co-founded by Sandeep Jethwani, Vaibhav Porwal, and Sahil Contractor. They have led successful wealth management businesses and managed over USD 7 billion in assets. The Dezerv team brings together decades of investing expertise from leading global financial...
-
Application Security Engineer
2 days ago
bangalore, India Dezerv Full timeDezerv is a house of investing solutions for high-net-worth and affluent Indians. Dezerv is co-founded by Sandeep Jethwani, Vaibhav Porwal, and Sahil Contractor. They have led successful wealth management businesses and managed over USD 7 billion in assets. The Dezerv team brings together decades of investing expertise from leading global financial...
-
Enterprise Applications Security Engineer
1 week ago
Bangalore, India Aviatrix Full timeWHO WE ARE: For enterprises struggling to secure cloud workloads, Aviatrix® offers a single solution for pervasive cloud security. Where current cybersecurity approaches focus on securing entry points to a trusted space, Aviatrix Cloud Native Security Fabric (CNSF) delivers runtime security and enforcement within the cloud application infrastructure itself...
-
Enterprise Applications Security Engineer
2 weeks ago
Bangalore, India Aviatrix Full timeWHO WE ARE: For enterprises struggling to secure cloud workloads, Aviatrix® offers a single solution for pervasive cloud security. Where current cybersecurity approaches focus on securing entry points to a trusted space, Aviatrix Cloud Native Security Fabric (CNSF) delivers runtime security and enforcement within the cloud application infrastructure itself...