
Application Security Engineer
4 days ago
Hybrid: #LI-Hybrid
"At BMC trust is not just a word - it's a way of life"
We are an award-winning, equal opportunity, culturally diverse, fun place to be. Giving back to the community drives us to be better every single day. Our work environment allows you to balance your priorities, because we know you will bring your best every day. We will champion your wins and shout them from the rooftops. Your peers will inspire, drive, support you, and make you laugh out loud
We help our customers free up time and space to become an Autonomo
us Digital Enterprise that conquers the opportunities ahead - and are relentless in the pursuit of innovationThe IZOT product line includes BMC's Intelligent Z Optimization & Transformation products, which help the world's largest companies to monitor and manage their mainframe systems. The modernization of mainframe is the beating heart of our product line, and we achieve this goal by developing products that improve the developer experience, the mainframe integration, the speed of application development, the quality of the code and the applications' security, while reducing operational costs and risks. We acquired several companies along the way, and we continue to grow, innovate, and perfect our solutions on an ongoing basis.
We are looking for Application Security Engineer to take ownership of security testing for enterprise products deployed on mainframe environments. In this role, you will assess application-layer security risks, identify vulnerabilities in product implementations, and lead secure architecture reviews. The ideal candidate brings deep offensive security skills along with familiarity in testing applications running on or integrated with IBM mainframe systems.Primary Roles and Responsibilities:
• Conduct penetration testing and red teaming exercises targeting mainframe environments and the surrounding application ecosystem.
• Perform code-assisted and black-box penetration testing against enterprise applications/systems interacting with RACF, DB2, CICS, MQ, and related subsystems.
• Identify risks in authentication, authorization, data handling, and communications within mainframe-integrated products.
• Create threat models and guide product teams in mitigating high-impact vulnerabilities early in the SDLC.
• Drive remediation efforts through hands-on collaboration and secure design guidance.
• Author technical reports and deliver executive summaries tailored to various audiences.
• Stay current on vulnerabilities, exploits, and testing techniques relevant to legacy enterprise technologies and mainframe ecosystems.
• Assess common integration patterns (SOA, REST/JSON, MQ) for security risks.
• 5 years of experience in penetration testing, with a specialization in systems/applications integrating with mainframe environments.
• Deep knowledge of mainframe communication protocols and security mechanisms.
• Demonstrated experience conducting red team-style assessments or advanced threat emulation on mainframe systems.
• Proficient in tools such as:
• Mainframe utilities: REXX, ISPF panels, NetView
• Security tools: Nmap, Burp Suite, Wireshark, custom scripts
• Strong scripting and automation skills (Python, REXX, Bash, or similar).
• Strong communication and leadership skills, with a proven ability to lead technical teams or projects.
• Experience producing board-level reports and presenting findings to senior stakeholders.
• Exposure to hybrid environments (mainframe to cloud integrations, modernization efforts).
• Familiarity with modern enterprise integration methods (REST, SOAP, MQ, FTP) that interface with mainframe services
Whilst these are nice to have, our team can help you develop in the following skills:
• Industry certifications such as OSCP, OSCE, CRTP, GIAC GPEN, GXPN, or CISSP.
• Background in regulated industries such as banking, insurance, or government, where mainframes are core infrastructure.
• Knowledge of COBOL, PL/I, or other mainframe-centric programming languages.
• Experience with compliance standards like PCI-DSS, NIST, or SOX as they apply to mainframes.
CA-DNP
Our commitment to you
BMC's culture is built around its people. We have 6000 brilliant minds working together across the globe. You won't be known just by your employee number, but for your true authentic self. BMC lets you be YOU
If after reading the above, You're unsure if you meet the qualifications of this role but are deeply excited about BMC and this team, we still encourage you to apply We want to attract talents from diverse backgrounds and experience to ensure we face the world together with the best ideas
BMC is committed to equal opportunity employment regardless of race, age, sex, creed, color, religion, citizenship status, sexual orientation, gender, gender expression, gender identity, national origin, disability, marital status, pregnancy, disabled veteran or status as a protected veteran. If you need a reasonable accommodation for any part of the application and hiring process, visit the accommodation request page.
BMC Software maintains a strict policy of not requesting any form of payment in exchange for employment opportunities, upholding a fair and ethical hiring process.
At BMC we believe in pay transparency and have set the midpoint of the salary band for this role at 2,117,800 INR. Actual salaries depend on a wide range of factors that are considered in making compensation decisions, including but not limited to skill sets; experience and training, licensure, and certifications; and other business and organizational needs.
The salary listed is just one component of BMC's employee compensation package. Other rewards may include a variable plan and country specific benefits.
We are committed to ensuring that our employees are paid fairly and equitably, and that we are transparent about our compensation practices.
()
Had a break in your career? No worries. This role is eligible for candidates who have taken a break in their career and want to re-enter the workforce. If your expertise matches the above job, visit to know more and how to apply.
Min salary
1,588,350
Mid point salary
2,117,800
Max salary
2,647,250
-
Application Security Engineer
4 days ago
Mumbai, Maharashtra, India Strategy Full timeJob Location : Pune, IndiaFull-time in person from Strategy Office a minimum of 4 days per weekJob Description :Join Strategys IT Security group as an Application Security Engineer and play a crucial role in safeguarding Strategys software applications while using modern security and AI tooling.In this position, you will be responsible for integrating...
-
Application Security Engineer
1 week ago
Mumbai, Maharashtra, India Lxme Full timeAbout Us:At LXME, we're building India's first full-stack financial platform designed exclusively for women. Trust, security, and reliability are at the heart of our mission to empower millions of women to confidently save, manage, and invest their money. As we scale, we're looking for an App Security Engineer to lead our application security efforts across...
-
Application Security Engineer
2 weeks ago
Mumbai, Maharashtra, India Lxme Full timeAbout Us:At LXME, we're building India's first full-stack financial platform designed exclusively for women. Trust, security, and reliability are at the heart of our mission to empower millions of women to confidently save, manage, and invest their money. As we scale, we're looking for an App Security Engineer to lead our application security efforts across...
-
Application Security Engineer
3 days ago
Mumbai, Maharashtra, India Leaders Access Full time ₹ 9,00,000 - ₹ 12,00,000 per yearRole Summary:We are looking for an experienced and technically skilled Application Security Engineer to strengthen our cybersecurity posture. The ideal candidate should possess a solid understanding of application-level vulnerabilities, secure code practices, and vulnerability management tools. You will be responsible for conducting in-depth assessments,...
-
Applications Security Engineer
4 days ago
Mumbai, Maharashtra, India Employee Forums Full timeRole Summary : We are looking for an experienced and technically skilled Application Security Engineer to strengthen our cybersecurity posture. The ideal candidate should possess a solid understanding of application-level vulnerabilities, secure code practices, and vulnerability management tools. You will be responsible for conducting in-depth assessments,...
-
Senior Security Engineer
3 days ago
Navi Mumbai, Maharashtra, India Eventus Security Full time ₹ 9,00,000 - ₹ 12,00,000 per yearJob Summary : We are seeking a highly motivated and experienced Senior Security Engineer to join our dynamic team. The ideal candidate will possess a strong background in server, data center, and endpoint security, with a specialized focus on Trend Micro products. This role requires a proactive individual capable of providing L2 support, conducting product...
-
Senior Security Engineer
3 days ago
Navi Mumbai, Maharashtra, India Eventus Security Full time ₹ 9,00,000 - ₹ 12,00,000 per yearJob Title: Senior Security EngineerJob Location: Navi MumbaiExperience: 3+yrsKey Responsibilities:Provide Tier 1 and Tier 2 technical support for Trend Micro products, including but not limited to:Trend Micro Apex One and Vision One.Deep Security and Vision One Pro.Cloud App Security and Email Security for Exchange.DDI/DDAN/Tipping Point/SMS/DDEI...
-
Senior Security Engineer
6 days ago
Navi Mumbai, Maharashtra, India Eventus Security Full timeJob Title: Senior Security Engineer Job Location: Navi Mumbai Experience: 3+yrs Key Responsibilities: Provide Tier 1 and Tier 2 technical support for Trend Micro products, including but not limited to: Trend Micro Apex One and Vision One. Deep Security and Vision One Pro. Cloud App Security and Email Security for Exchange. DDI/DDAN/Tipping Point/SMS/DDEI...
-
Security Researcher
3 days ago
Mumbai, Maharashtra, India Security Brigade Full time US$ 80,000 - US$ 1,20,000 per yearJob DescriptionSecurity Brigade is looking for a Security Researcher who will be working with ShadowMap tool which is an internal security tool & manage on-site clients for long-term.Objective of this RoleAnalyze attack surface management tool which contains web & mobile application alerts, data leaks, dark web & exposed code repositories.Assist clients by...
-
Application Security
1 week ago
Mumbai, Maharashtra, India ServQual Full timeCompany DescriptionServQual Security specializes in Cyber Security Discovery Workshops, Enterprise Security Transformations, and GRC automation through our AI-powered platform, SUSAN. SUSAN is designed to bridge the gap between cybersecurity leadership and engineering teams, enabling continuous GRC, automated risk assessments, and real-time control...