Lead Application Security Engineer

4 weeks ago


India Housing.com Full time

REA India is a part of REA Group Ltd. of Australia (ASX: REA) ("REA Group"). It is the country's leading full stack real estate technology platform that owns Housing.com and PropTiger.com.

REA India is the only player in India that offers a full range of services in the real estate space, assisting consumers through their entire home seeking journey all the way from initial search and discovery to financing to the final step of transaction closure.

It offers advertising and listings products to real estate developers, agents; homeowners, exclusive sales and marketing solutions to builders, data and content services, and personalized search, virtual viewing, site visits, negotiations, home loans and post- sales services to consumers for both buying and renting.

With a 1600+ strong team, REA India has a national presence with 25+ offices across India with its corporate office located in Gurugram, Haryana.

Housing.com :

Founded in 2012 and acquired by REA India in 2017, Housing.com is India's most innovative real estate advertising platform for homeowners, landlords, developers, and real estate brokers.

The company offers listings for new homes, resale homes, rentals, plots and co-living spaces in India.

Backed by strong research and analytics, the company's experts provide comprehensive real estate services that cover advertising and marketing, sales solutions for real estate developers, personalized search, virtual viewing, AR& VR content, home loans, end-to-end transaction services, and post-transaction services to consumers for both buying and renting.

PropTiger.com :

PropTiger.com is among India's leading digital real estate advisory firm offering a one-stop platform for buying residential real estate. Founded in 2011 with the goal to help people buy their dream homes, PropTiger.com leverages the power of information and the organisation's deep-rooted understanding of the real estate sector to bring simplicity, transparency and trust in the home buying process.

PropTiger.com helps home-buyers through the entire home-buying process through a mix of technology-enabled tools as well as on-ground support. The company offers researched information about various localities and properties and provides guidance on matters pertaining to legal paperwork and loan assistance to successfully fulfil a transaction.

Key Responsibilities :

- Lead and manage the application security program, focusing on secure development, testing, and deployment of applications.

- Conduct security code reviews, vulnerability assessments, and penetration testing to identify and mitigate risks in applications.

- Collaborate with development and DevOps teams to integrate security into the CI/CD pipeline, ensuring secure coding practices and automated security testing.

- Develop and enforce application security policies, standards, and guidelines across the organization.

- Provide guidance and training to development teams on secure coding practices, threat modeling, and application security best practices.

- Work closely with the cloud security team to ensure that applications deployed in AWS are secure and compliant with industry standards.

- Design and implement security controls for applications hosted in AWS, VPC, encryption, and security monitoring.

- Monitor application security trends, emerging threats, and new security technologies to keep the organization's security posture up to date.)

- Respond to security incidents, perform root cause analysis, and drive remediation efforts to prevent recurrence.

- Work with product management and engineering teams to ensure that security is considered at every stage of the application lifecycle.

Required Qualifications :

- 6-8 years of experience in application security, with a proven track record of securing applications in complex environments.

- In-depth knowledge of secure software development practices, including OWASP Top 10, SANS/CWE Top 25, and threat modeling.

- Experience with security tools such as static and dynamic application security testing (SAST/DAST), dependency scanning, and vulnerability management platforms.

- Strong understanding of cloud security principles and best practices, specifically in AWS environments.

- Hands-on experience with AWS security services such as IAM, Security Groups, VPC, CloudTrail, KMS, and WAF.

- Familiarity with infrastructure-as-code (IaC) tools such as Terraform or AWS CloudFormation for securing cloud environments.

- Strong programming and scripting skills (e.g., Python, Java, JavaScript) to automate security tasks and enhance security testing.

- Excellent problem-solving skills and the ability to work independently and as part of a team.

- Strong communication and collaboration skills, with the ability to convey complex security concepts to both technical and non-technical stakeholders.

- Having certification likes OSCP, OSCE a plus



  • India GXS Bank Full time

    About the Team We are the bank's security engineering team - our mission is simple - we make sure that we build and leverage secure systems and operate them at production scale in a secure way. Our engineering teams move fast and are constantly innovating, and our security engineers need to ensure we provide the right tools and processes to help them...


  • India Astra Security Full time

    About UsAstra Security is a pioneering cyber security SaaS company that empowers businesses to fortify their defenses against increasingly sophisticated threats. Our flagship Pentest Platform revolutionizes the vulnerability management landscape, delivering unparalleled accuracy and efficiency in identifying and addressing potential security risks.With a...


  • india Housing.com Full time

    REA India is a part of REA Group Ltd. of Australia (ASX: REA) ("REA Group"). It is the country's leading full stack real estate technology platform that owns Housing.com and PropTiger.com. REA India is the only player in India that offers a full range of services in the real estate space, assisting consumers through their entire home seeking journey all the...


  • India Vimeo Full time

    As a Sr. Application Security Engineer at Vimeo, you will engage in a variety of activities, either offensive, defensive, or some combination thereof, ultimately aimed at safeguarding our users who entrust Vimeo with their content every day. You’ll plan, carry out, and lead security initiatives to monitor and protect sensitive data and systems from...


  • india RSI Security Full time

    Location: 100% Remote Type: Contractor - Part Time, Project based Pay: Based on experience, education, geographic location, and market rates. Travel: None *** Please ensure you read through the entire job posting and you also understand the work model, expectations, requirements, location, and qualification requirements for this role. *** About Us: RSI...


  • india RSI Security Full time

    Location: 100% RemoteType: Contractor - Part Time, Project basedPay: Based on experience, education, geographic location, and market rates.Travel: None*** Please ensure you read through the entire job posting and you also understand the work model, expectations, requirements, location, and qualification requirements for this role. ***About Us:RSI Security is...


  • india Soffit Infrastructure Services (P) Ltd Full time

    Job Overview: We are looking for a talented and experienced Application Security Engineer to join our team. The ideal candidate will have a strong understanding of application security standards, tools, and methodologies and will be responsible for conducting security assessments, penetration testing, and vulnerability analysis for web and mobile...


  • India KMM Technologies, Inc. Full time

    Senior Application Security Engineer JD Work Hours: M-F 9am-1pm US EST(7:30PM to 12AM IST) Remaining hours can be worked during India daytime, but 40 hours/week had to be put in. Some of the tools used: Microsoft Security Tool Suite Exabeam AWS GuardDuty Applications: OnBase Logs MuleSoft - SASS Salesforce - SASS Workday - SASS ...


  • India KMM Technologies, Inc. Full time

    Senior Application Security Engineer JDWork Hours: M-F 9am-1pm US EST(7:30PM to 12AM IST)Remaining hours can be worked during India daytime, but 40 hours/week had to be put in.Some of the tools used:Microsoft Security Tool SuiteExabeamAWS GuardDutyApplications:OnBase LogsMuleSoft - SASSSalesforce - SASSWorkday - SASSPeopleSoft Hosted on AWS


  • India Vimeo Full time

    As a Sr. Application Security Engineer at Vimeo, you will engage in a variety of activities, either offensive, defensive, or some combination thereof, ultimately aimed at safeguarding our users who entrust Vimeo with their content every day. You’ll plan, carry out, and lead security initiatives to monitor and protect sensitive data and systems from...


  • india Astra Security Full time

    About Astra: Astra is a cyber security SaaS company that makes otherwise chaotic pentests a breeze with its one of a kind Pentest Platform. Astra's continuous vulnerability scanner emulates hacker behaviour to scan applications for 9300+ security tests. CTOs & CISOs love Astra because it helps them fix vulnerabilities in record time and move from DevOps to...


  • india Astra Security Full time

    About Astra: Astra is a cyber security SaaS company that makes otherwise chaotic pentests a breeze with its one of a kind Pentest Platform. Astra's continuous vulnerability scanner emulates hacker behaviour to scan applications for 9300+ security tests. CTOs & CISOs love Astra because it helps them fix vulnerabilities in record time and move from DevOps to...


  • india TAC Security Full time

    We are seeking a highly experienced and strategic Director of Presales for Cybersecurity to lead our presales team, driving the technical aspects of our sales cycle. This leadership role is responsible for guiding presales engineers, collaborating closely with sales, product management, and other stakeholders to create tailored cybersecurity solutions for...


  • india TAC Security Full time

    We are seeking a highly experienced and strategic Director of Presales for Cybersecurity to lead our presales team, driving the technical aspects of our sales cycle. This leadership role is responsible for guiding presales engineers, collaborating closely with sales, product management, and other stakeholders to create tailored cybersecurity solutions for...


  • india TAC Security Full time

    As a Full Stack Developer specializing in security products, you will play a key role in the development and enhancement of our cybersecurity solutions. Based in Aerocity Delhi, India, you will work closely with cross-functional teams to design, develop, and maintain secure and scalable software applications. Your expertise in full stack development,...


  • india OpSec Security Full time

    Location - Gurugram or CoimbatoreAbout Us:OpSec Security are the world leader in brand protection, with over 4 decades of history and an integral part of Crane NXT, a $1.5 billion dollar business with over 4,750 associates worldwide. We safeguard the revenues and reputations of more than half of the Fortune 100. We effectively address Brand, Piracy, and...


  • India KMM Technologies, Inc. Full time

    This is Sekhar from KMM Technologies . We have an urgent requirement for the following, if you are comfortable send your latest resume to // Call 240-800-1958/ 9985243226.. Position: Senior Application Security Engineer Location: Remote Work Hours: M-F 9am-1pm US EST (7.30 pm to11.30pm IST) Remaining hours can be worked during India daytime,...


  • India Zepto Full time

    About Zepto Zepto is India's fastest-growing startup and the leader in quick-commerce grocery delivery. We're revolutionizing the industry with our groundbreaking platform and lightning-fast delivery promise. As a Senior Application Security Engineer at Zepto, you'll play a crucial role in securing the technology that powers our innovative...


  • India Aira Security Full time

    About Aira SecurityWe are a pioneering cybersecurity company specializing in the unique risks and security concerns within the AI ecosystem. Our innovative AI Security Scanner empowers organizations to identify, monitor, and mitigate AI-specific security risks.Our mission-driven team is dedicated to safeguarding the future of AI.Role OverviewWe are seeking...


  • india TAC Security Full time

    Job Summary:TAC Security is looking for an experienced Product Manager to lead and drive product strategy, development, and execution. In this role, you will be responsible for guiding the success of our security products and collaborating with cross-functional teams to ensure we meet our business and user needs. You will work closely with engineering,...