
Senior Application Security Engineer
3 days ago
Who We Are:
Hewlett Packard Enterprise is the global edge-to-cloud company advancing the way people live and work. We help companies connect, protect, analyze, and act on their data and applications wherever they live, from edge to cloud, so they can turn insights into outcomes at the speed required to thrive in today's complex world. Our culture thrives on finding new and better ways to accelerate what's next. We know varied backgrounds are valued and succeed here. We have the flexibility to manage our work and personal needs. We make bold moves, together, and are a force for good. If you are looking to stretch and grow your career our culture will embrace you. Open up opportunities with HPE.
Job Description:
About our Cybersecurity team:
Are you ready to make an impact at one of the world's leading tech companies? HPE's Cybersecurity team is where you can do just that We're looking for an Expert level Cybersecurity Incident Response Analyst to join our Incident Command team in Bangalore.
As an expert you will be responsible for leading the detection, analysis, containment, and remediation of cybersecurity incidents across the organization. This role demands a deep technical understanding of cyber threats, advanced incident handling skills, and the ability to act decisively in high-pressure situations. You will work closely with other cybersecurity teams to ensure a coordinated and effective response to security incidents, helping to minimize the impact on the organization. Within the scope of the role will be mentoring junior team members and contributing to the continuous improvement of the organization's incident response capabilities.
What you'll do:
Key Responsibilities
- Secure SDLC & DevSecOps Integration – Partner with engineering and DevOps teams to embed security into the entire software delivery process.
- Software Delivery Pipeline (CI/CD) Security –
- Design and implement security controls for build and release pipelines (GitHub Actions, Jenkins, GitLab, Azure DevOps, etc.).
- Ensure code integrity via signing, artifact scanning, and build provenance.
- Automate SAST, DAST, SCA, and container image scanning as part of the software delivery pipeline.
- Identify and remediate misconfigurations in pipeline environments and access control.
- Web & API Security – Design, implement, and monitor WAF rules and API protections, perform API risk assessments, and champion secure design patterns.
- Code Review & Testing – Conduct secure code reviews and support automation of testing pipelines.
- Vulnerability Management – Triage, prioritize, and track security issues identified in code, pipelines, and deployed environments.
- Threat Modeling & Risk Assessment – Facilitate threat modeling sessions for applications, APIs, and pipeline workflows.
- Tooling & Automation – Expand security automation coverage, including API discovery, dependency scanning, SBOM generation, and secrets detection.
- Security Champion Enablement – Mentor developers and DevOps engineers on secure pipeline and coding practices.
- Collaboration & Advisory – Act as a trusted partner to product, platform engineering, and DevOps leaders, translating security risk into business impact.
- Incident Support – Collaborate with SOC/IR teams in response to software supply chain or pipeline compromises.
What you need to bring:
Qualifications Required:- 5–8+ years of experience in Application Security, Product Security, or Secure Software Development.
- Hands-on experience securing software delivery pipelines (CI/CD) and source code repositories (GitHub, GitLab, Jenkins).
- Knowledge of supply chain security frameworks and controls (e.g., SLSA, NIST SSDF).
- Familiarity with secrets management, artifact signing (Sigstore, Cosign), and build integrity practices.
- Hands-on experience with WAF tuning, API security controls, and vulnerability remediation.
- Proficiency with one or more programming languages (Python, Java, Go, ).
- Experience with SAST, DAST, SCA, and container image scanning tools.
- Cloud security experience with AWS, Azure, or GCP.
- Deep understanding of OWASP Top 10 (Web + API), CWE, and secure coding practices.
Preferred:
- Experience integrating SBOM generation and software composition analysis into software delivery pipelines.
- Knowledge of runtime protection tools (API security, RASP, EDR for containers).
- Familiarity with GitOps, Infrastructure as Code (IaC) scanning (Terraform, CloudFormation), and policy-as-code solutions.
- Experience responding to pipeline compromises or dependency poisoning incidents.
- Relevant certifications: OSWE, CSSLP, GPCS, GIAC GWEB, GIAC Cloud Security Automation (GCSA).
Soft Skills
- Excellent communication skills with the ability to influence developers, DevOps engineers, and leadership.
- Strong problem solving mindset with an automation first approach.
- Collaborative, outcome oriented, and able to balance security with speed of delivery.
#cybersecurity
Additional Skills:
Accountability, Accountability, Action Planning, Active Learning, Active Listening, Agile Methodology, Bias, Business, Coaching, Creativity, Critical Thinking, Cybersecurity, Data Analysis Management, Data Collection Management (Inactive), Data Controls, Design Thinking, Development Methodologies, Empathy, Follow-Through, Growth Mindset, Implementation Methodologies, Infrastructure Design, Intellectual Curiosity (Inactive), Long Term Planning, Managing Ambiguity {+ 4 more}What We Can Offer You:
Health & Wellbeing
We strive to provide our team members and their loved ones with a comprehensive suite of benefits that supports their physical, financial and emotional wellbeing.
Personal & Professional Development
We also invest in your career because the better you are, the better we all are. We have specific programs catered to helping you reach any career goals you have — whether you want to become a knowledge expert in your field or apply your skills to another division.
Unconditional Inclusion
We are unconditionally inclusive in the way we work and celebrate individual uniqueness. We know varied backgrounds are valued and succeed here. We have the flexibility to manage our work and personal needs. We make bold moves, together, and are a force for good.
Let's Stay Connected:
Follow @HPECareers on Instagram to see the latest on people, culture and tech at HPE.
#indiaJob:
Information TechnologyJob Level:
TCP_HPE is an Equal Employment Opportunity/ Veterans/Disabled/LGBT employer. We do not discriminate on the basis of race, gender, or any other protected category, and all decisions we make are made on the basis of qualifications, merit, and business need. Our goal is to be one global team that is representative of our customers, in an inclusive environment where we can continue to innovate and grow together. Please click here: Equal Employment Opportunity.
Hewlett Packard Enterprise is EEO Protected Veteran/ Individual with Disabilities.
HPE will comply with all applicable laws related to employer use of arrest and conviction records, including laws requiring employers to consider for employment qualified applicants with criminal histories.
-
Senior Security Engineer
2 days ago
Bengaluru, Karnataka, India Skyhigh Security Full time US$ 1,25,000 - US$ 1,75,000 per yearJob Title:Senior Security EngineerAbout Skyhigh Security:Skyhigh Security is a dynamic, fast-paced, cloud company that is a leader in the security industry. Our mission is to protect the world's data, and because of this, we live and breathe security. We value learning at our core, underpinned by openness and transparency.Since 2011, organizations have...
-
Senior Application Security Engineer
4 weeks ago
Bengaluru, Karnataka, India DigiCert Full timeJob DescriptionWho we areWe&aposre a leading, global security authority that&aposs disrupting our own category. Our encryption is trusted by the major ecommerce brands, the world&aposs largest companies, the major cloud providers, entire country financial systems, entire internets of things and even down to the little things like surgically embedded...
-
Security Engineer II
6 days ago
Bengaluru, Karnataka, India Safe Security Full time ₹ 12,00,000 - ₹ 36,00,000 per yearAt SAFE Security, our mission is bold and ambitious: We Will Build CyberAGI — a super-specialized system of intelligence that autonomously predicts, detects, and remediates threats. This isn't just a vision—it's the future we're building every day, with the best minds in AI, cybersecurity, and risk. At SAFE, we empower individuals and teams with the...
-
Security Engineer II
6 days ago
Bengaluru, Karnataka, India Safe Security Full time ₹ 5,00,000 - ₹ 15,00,000 per yearAt SAFE Security, our mission is bold and ambitious: We Will Build CyberAGI — a super-specialized system of intelligence that autonomously predicts, detects, and remediates threats. This isn't just a vision—it's the future we're building every day, with the best minds in AI, cybersecurity, and risk. At SAFE, we empower individuals and teams with the...
-
Security Engineer II
6 days ago
Bengaluru, Karnataka, India Safe Security Full time ₹ 6,00,000 - ₹ 18,00,000 per yearAt SAFE Security, our mission is bold and ambitious:We Will Build CyberAGI— a super-specialized system of intelligence that autonomously predicts, detects, and remediates threats. This isn't just a vision—it's the future we're building every day, with the best minds in AI, cybersecurity, and risk. At SAFE, we empower individuals and teams with the...
-
Senior Application Security Engineer
4 days ago
Bengaluru, Karnataka, India Narayana Health (NH) Full time ₹ 10,00,000 - ₹ 25,00,000 per yearAbout Narayana Health:Narayana Health is headquartered in Bengaluru, India, and operates a network of hospitals in India and Overseas. Our mission is to deliver high-quality, affordable healthcare services to the broader population. Narayana Health Group is Indias leading healthcare provider and one of the largest hospital groups in the country with a...
-
Application Security Engineer
24 hours ago
Bengaluru, Karnataka, India Uplers Full time ₹ 12,00,000 - ₹ 36,00,000 per yearSenior Security and Compliance EngineerExperience: 3 - 6 Years ExpSalary : competitivePreferred Notice Period: Within 30 DaysOpportunity Type: Hybrid (Bengaluru)Placement Type: Permanent(*Note: This is a requirement for one of Uplers' Clients)Must have skills required :Information Security OR Statutory Compliance, Cloud SecurityHiver (One of Uplers' Clients)...
-
Senior Security Engineer, Applications
2 weeks ago
Bengaluru, Karnataka, India Postman Full time ₹ 12,00,000 - ₹ 36,00,000 per yearWho Are We?Postman is the world's leading API platform, used by more than 40 million developers and 500,000 organizations, including 98% of the Fortune 500. Postman is helping developers and professionals across the globe build the API-first world by simplifying each step of the API lifecycle and streamlining collaboration—enabling users to create better...
-
Senior Application Security Engineer
1 day ago
Bengaluru, Karnataka, India Hewlett Packard Enterprise | HPE Full time ₹ 12,00,000 - ₹ 36,00,000 per yearSenior Application Security EngineerThis role has been designed as 'Hybrid' with an expectation that you will work on average 2 days per week from an HPE office.Who We Are:Hewlett Packard Enterprise is the global edge-to-cloud company advancing the way people live and work. We help companies connect, protect, analyze, and act on their data and applications...
-
Application Security Engineer
21 hours ago
Bengaluru, Karnataka, India Ola Electric Full time ₹ 15,00,000 - ₹ 25,00,000 per yearJob Title: Application Security EngineerJob Summary:A Security Engineer will be responsible for ensuring the security and privacy of the company's products and services. This role will be vital in shaping the company's security strategy by working closely with development teams to identify, evaluate, and mitigate potential security risks and ensuring that...