Application Security Engineer

18 hours ago


Ahmedabad, Gujarat, India E.L.F. BEAUTY Full time ₹ 12,00,000 - ₹ 36,00,000 per year

About The Company
e.l.f. Beauty, Inc. stands with every eye, lip, face and paw. Our deep commitment to clean, cruelty free beauty at an incredible value has fueled the success of our flagship brand e.l.f. Cosmetics since 2004 and driven our portfolio expansion. Today, our multi-brand portfolio includes e.l.f. Cosmetics, e.l.f. SKIN, pioneering clean beauty brand Well People, Keys Soulcare, a groundbreaking lifestyle beauty brand created with Alicia Keys and Naturium, high-performance, biocompatible, clinically-effective and accessible skincare.

In our Fiscal year 25, we had net sales of $1 Billion and our business performance has been nothing short of extraordinary with 26 consecutive quarters of net sales growth. We are the #2 mass cosmetics brand in the US and are the fastest growing mass cosmetics brand among the top 5. Our total compensation philosophy offers every full-time new hire competitive pay and benefits, bonus eligibility (200% of target over the last four fiscal years), equity, and a hybrid 3 day in office, 2 day at home work environment. We believe the combination of our unique culture, total compensation, workplace flexibility and care for the team is unmatched across not just beauty but any industry.

Visit our Career Page to learn more about our team:

Position Summary
We are seeking a highly skilled and proactive Application Security Engineer to join our growing security team. You will be responsible for securing our applications throughout the software development lifecycle (SDLC). This includes identifying vulnerabilities, working with development teams to remediate risks, and implementing security best practices and tools to ensure our applications are robust, secure, and compliant with relevant standards.

Responsibilities

  • Perform manual and automated security assessments of web, mobile, and cloud applications
  • Collaborate with development and engineering teams to embed security into SDLC (DevSecOps)
  • Conduct secure code reviews, threat modeling exercises, and risk assessments to identify security weaknesses in application design.
  • Implement and manage application security tools (SAST, DAST, SCA, IAST)
  • Design and enforce security policies, standards, and procedures for application development
  • Monitor, triage, and respond to application-layer vulnerabilities and incidents
  • Work closely with QA and engineering teams to drive security testing and fix validation
  • Lead the Incident Response effort for application-related security events.
  • Stay current on the latest security threats, vulnerabilities, and industry's best practices
  • Conduct developer training and promote a security-first culture within engineering
  • Cross-train team members on Application Security principles.
  • Actively participate in the broader corporate security efforts, including infrastructure security, end-user training, and vulnerability management.

Requirements

  • Bachelor's degree in Computer Science, Cybersecurity, or related field (or equivalent experience).
  • 3+ years in application security, secure software development, and penetration testing.
  • Strong understanding of web technologies (HTML, JavaScript, Python, REST APIs, etc.).
  • Experience with security tools for code security, bug bounty programs, and the ability to integrate them into CI/DC pipelines for automated security testing.
  • Familiarity with OWASP Top 10, SANS Top 25, CWE, CVE, and secure coding practices.
  • Knowledge of cloud environments (AWS, Azure, GCP) and their security features.
  • Strong communication and interpersonal skills, with the ability to collaborate effectively with technical and non-technical stakeholders.

Preferred Qualifications

  • Industry certifications such as CSSLP, GWAPT, OSCP, or CEH
  • Experience with container security and CI/CD pipeline integration
  • Familiarity with regulatory and compliance frameworks (e.g., SOC 2, ISO 27001, PCI DSS)
  • Prior experience working in agile, DevOps, or fast-paced development environments

Minimum Work Experience

  • 4

Maximum Work Experience

  • 10

This job description is intended to describe the general nature and level of work being performed in this position. It also reflects the general details considered necessary to describe the principal functions of the job identified, and shall not be considered, as detailed description of all the work required inherent in the job. It is not an exhaustive list of responsibilities, and it is subject to changes and exceptions at the supervisors' discretion.
e.l.f. Beauty respects your privacy. Please see our Job Applicant Privacy Notice ) for how your personal information is used and shared.



  • Ahmedabad, Gujarat, India adani capital pvt ltd Full time ₹ 20,00,000 - ₹ 25,00,000 per year

    Application Security Head Responsibilities 1.Vulnerability Assessment: Conduct regular security assessments of applications to identify and prioritize vulnerabilities.2. Penetration Testing: Perform penetration testing on web and mobile applications to simulate real-world cyber-attacks and uncover potential weaknesses.3. Code Review: Review application...


  • Ahmedabad, Gujarat, India Adani Enterprises Ltd Full time ₹ 20,00,000 - ₹ 25,00,000 per year

    Application Security Head 1.Vulnerability Assessment: Conduct regular security assessments of applications to identify and prioritize vulnerabilities.2. Penetration Testing: Perform penetration testing on web and mobile applications to simulate real-world cyber-attacks and uncover potential weaknesses.3. Code Review: Review application code to identify and...

  • Sr. Security Analyst

    4 weeks ago


    Ahmedabad, Gujarat, India Eventus Security Full time

    Position Title: Sr. Security Analyst Experience: 3yrs +Location: Ahmedabad (candidate based out at Gujarat preferred)Qualifications:BE/ B.Tech/ M.Tech/ MSc/ MCA qualification or equivalentAt least one of the following certifications - GCFA, GCFE, CISP, CISSP, CCNP, CCIE Security, CEH, CSA.Responsibilities:• Should have minimum of 3 years of experience in...

  • Sr. Security Analyst

    4 weeks ago


    Ahmedabad, Gujarat, India Eventus Security Full time

    Position Title: Sr. Security Analyst Experience: 3yrs + Location: Ahmedabad (candidate based out at Gujarat preferred) Qualifications: BE/ B.Tech/ M.Tech/ MSc/ MCA qualification or equivalent At least one of the following certifications - GCFA, GCFE, CISP, CISSP, CCNP, CCIE Security, CEH, CSA. Responsibilities: • Should have minimum of 3 years of...


  • Ahmedabad, Gujarat, India Adani Enterprises Ltd Full time ₹ 6,00,000 - ₹ 18,00,000 per year

    Manager - Application Security Strategic Roles and Responsibilities Conduct regular security assessments of applications to identify and prioritize vulnerabilities. Perform penetration testing on web and mobile applications to simulate real-world cyber-attacks and uncover potential weaknesses. Review application code to identify and remediate...


  • Ahmedabad, Gujarat, India Adani Enterprises Limited Full time ₹ 20,00,000 - ₹ 25,00,000 per year

    ResponsibilitiesStrategic Roles and ResponsibilitiesConduct regular security assessments of applications to identify and prioritize vulnerabilities.Perform penetration testing on web and mobile applications to simulate real-world cyber-attacks and uncover potential weaknesses.Review application code to identify and remediate security flaws, ensuring...


  • Ahmedabad, Gujarat, India NMT Security | Simplifying Cybersecurity Full time ₹ 15,00,000 - ₹ 20,00,000 per year

    AWS Security Specialist Location: Noida | Type: Full-time | Experience: 5+ years NMT Security is building a next-gen cybersecurity platform. We're looking for an AWS Security Specialist to ensure our serverless application is built and maintained using the highest security standards aligned with AWS best practices and compliance frameworks like NIST. What...


  • Ahmedabad, Gujarat, India Enlighten Schola Full time ₹ 15,00,000 - ₹ 25,00,000 per year

    Position :- Infrastructure Security EngineerType :- OnsiteLocation :- AhmedabadPosition Overview:We are looking for a skilled Infrastructure Security Engineer to join our cybersecurity team. The ideal candidatewill bring deep technical expertise across cloud security (especially AWS), vulnerability management, patchmanagement, endpoint protection, and...


  • Ahmedabad, Gujarat, India WELTEC Institute Full time ₹ 1,04,000 - ₹ 1,30,878 per year

    Position :- Infrastructure Security EngineerType :- OnsiteLocation :- AhmedabadPosition OverviewWe are looking for a skilled Infrastructure Security Engineer to join our cybersecurity team. The ideal candidatewill bring deep technical expertise across cloud security (especially AWS), vulnerability management, patchmanagement, endpoint protection, and...


  • Ahmedabad, Gujarat, India eInfochips (An Arrow Company) Full time

    eInfochips (An Arrow Company):eInfochips, an Arrow company (A $27.9 B, NASDAQ listed (ARW); Ranked #154 on the Fortune List), is a leading global provider of product engineering and semiconductor design services. 25+ years of proven track record, with a team of over 2500+ engineers, the team has been instrumental in developing over 500+ products and 40M...