Senior Application Security Engineer
1 week ago
Who We Are:
Hewlett Packard Enterprise is the global edge-to-cloud company advancing the way people live and work. We help companies connect, protect, analyze, and act on their data and applications wherever they live, from edge to cloud, so they can turn insights into outcomes at the speed required to thrive in today's complex world. Our culture thrives on finding new and better ways to accelerate what's next. We know varied backgrounds are valued and succeed here. We have the flexibility to manage our work and personal needs. We make bold moves, together, and are a force for good. If you are looking to stretch and grow your career our culture will embrace you. Open up opportunities with HPE.
Job Description:
About our Cybersecurity team:
Are you ready to make an impact at one of the world's leading tech companies? HPE's Cybersecurity team is where you can do just that We're looking for an Expert level Cybersecurity Incident Response Analyst to join our Incident Command team in Bangalore.
As an expert you will be responsible for leading the detection, analysis, containment, and remediation of cybersecurity incidents across the organization. This role demands a deep technical understanding of cyber threats, advanced incident handling skills, and the ability to act decisively in high-pressure situations. You will work closely with other cybersecurity teams to ensure a coordinated and effective response to security incidents, helping to minimize the impact on the organization. Within the scope of the role will be mentoring junior team members and contributing to the continuous improvement of the organization's incident response capabilities.
What you'll do:
Key Responsibilities
- Secure SDLC & DevSecOps Integration – Partner with engineering and DevOps teams to embed security into the entire software delivery process.
- Software Delivery Pipeline (CI/CD) Security –
- Design and implement security controls for build and release pipelines (GitHub Actions, Jenkins, GitLab, Azure DevOps, etc.).
- Ensure code integrity via signing, artifact scanning, and build provenance.
- Automate SAST, DAST, SCA, and container image scanning as part of the software delivery pipeline.
- Identify and remediate misconfigurations in pipeline environments and access control.
- Web & API Security – Design, implement, and monitor WAF rules and API protections, perform API risk assessments, and champion secure design patterns.
- Code Review & Testing – Conduct secure code reviews and support automation of testing pipelines.
- Vulnerability Management – Triage, prioritize, and track security issues identified in code, pipelines, and deployed environments.
- Threat Modeling & Risk Assessment – Facilitate threat modeling sessions for applications, APIs, and pipeline workflows.
- Tooling & Automation – Expand security automation coverage, including API discovery, dependency scanning, SBOM generation, and secrets detection.
- Security Champion Enablement – Mentor developers and DevOps engineers on secure pipeline and coding practices.
- Collaboration & Advisory – Act as a trusted partner to product, platform engineering, and DevOps leaders, translating security risk into business impact.
- Incident Support – Collaborate with SOC/IR teams in response to software supply chain or pipeline compromises.
What you need to bring:
Qualifications Required:- 5–8+ years of experience in Application Security, Product Security, or Secure Software Development.
- Hands-on experience securing software delivery pipelines (CI/CD) and source code repositories (GitHub, GitLab, Jenkins).
- Knowledge of supply chain security frameworks and controls (e.g., SLSA, NIST SSDF).
- Familiarity with secrets management, artifact signing (Sigstore, Cosign), and build integrity practices.
- Hands-on experience with WAF tuning, API security controls, and vulnerability remediation.
- Proficiency with one or more programming languages (Python, Java, Go, ).
- Experience with SAST, DAST, SCA, and container image scanning tools.
- Cloud security experience with AWS, Azure, or GCP.
- Deep understanding of OWASP Top 10 (Web + API), CWE, and secure coding practices.
Preferred:
- Experience integrating SBOM generation and software composition analysis into software delivery pipelines.
- Knowledge of runtime protection tools (API security, RASP, EDR for containers).
- Familiarity with GitOps, Infrastructure as Code (IaC) scanning (Terraform, CloudFormation), and policy-as-code solutions.
- Experience responding to pipeline compromises or dependency poisoning incidents.
- Relevant certifications: OSWE, CSSLP, GPCS, GIAC GWEB, GIAC Cloud Security Automation (GCSA).
Soft Skills
- Excellent communication skills with the ability to influence developers, DevOps engineers, and leadership.
- Strong problem solving mindset with an automation first approach.
- Collaborative, outcome oriented, and able to balance security with speed of delivery.
#cybersecurity
Additional Skills:
Accountability, Accountability, Action Planning, Active Learning, Active Listening, Agile Methodology, Bias, Business, Coaching, Creativity, Critical Thinking, Cybersecurity, Data Analysis Management, Data Collection Management (Inactive), Data Controls, Design Thinking, Development Methodologies, Empathy, Follow-Through, Growth Mindset, Implementation Methodologies, Infrastructure Design, Intellectual Curiosity (Inactive), Long Term Planning, Managing Ambiguity {+ 4 more}What We Can Offer You:
Health & Wellbeing
We strive to provide our team members and their loved ones with a comprehensive suite of benefits that supports their physical, financial and emotional wellbeing.
Personal & Professional Development
We also invest in your career because the better you are, the better we all are. We have specific programs catered to helping you reach any career goals you have — whether you want to become a knowledge expert in your field or apply your skills to another division.
Unconditional Inclusion
We are unconditionally inclusive in the way we work and celebrate individual uniqueness. We know varied backgrounds are valued and succeed here. We have the flexibility to manage our work and personal needs. We make bold moves, together, and are a force for good.
Let's Stay Connected:
Follow @HPECareers on Instagram to see the latest on people, culture and tech at HPE.
#indiaJob:
Information TechnologyJob Level:
TCP_HPE is an Equal Employment Opportunity/ Veterans/Disabled/LGBT employer. We do not discriminate on the basis of race, gender, or any other protected category, and all decisions we make are made on the basis of qualifications, merit, and business need. Our goal is to be one global team that is representative of our customers, in an inclusive environment where we can continue to innovate and grow together. Please click here: Equal Employment Opportunity.
Hewlett Packard Enterprise is EEO Protected Veteran/ Individual with Disabilities.
HPE will comply with all applicable laws related to employer use of arrest and conviction records, including laws requiring employers to consider for employment qualified applicants with criminal histories.
-
Senior Application Security Engineer
1 week ago
Bengaluru, Karnataka, India DigiCert Full time ₹ 12,00,000 - ₹ 36,00,000 per yearWho we areWe're a leading, global security authority that's disrupting our own category. Our encryption is trusted by the major ecommerce brands, the world's largest companies, the major cloud providers, entire country financial systems, entire internets of things and even down to the little things like surgically embedded pacemakers. We help companies...
-
Senior Application Security Engineer
1 week ago
Bengaluru, Karnataka, India Atomicwork Full time ₹ 12,00,000 - ₹ 36,00,000 per yearAbout AtomicworkAtomicwork is reimagining IT and workplace operations by putting employees at the center of the experience. With a strong emphasis on automation, integration, and security, Atomicwork helps organizations streamline workflows, improve productivity, and reduce friction across employee and IT interactions.Role OverviewWe are looking for aSenior...
-
Senior Application Security Engineer
4 days ago
Bengaluru, Karnataka, India Twilio Full time ₹ 6,00,000 - ₹ 18,00,000 per yearWho we areAt Twilio, we're shaping the future of communications, all from the comfort of our homes. We deliver innovative solutions to hundreds of thousands of businesses and empower millions of developers worldwide to craft personalized customer experiences.Our dedication to remote-first work, and strong culture of connection and global inclusion means that...
-
Application Security Engineer
3 days ago
Bengaluru, Karnataka, India ALLEN Digital Full time ₹ 12,00,000 - ₹ 36,00,000 per yearAbout ALLEN Digital:At ALLEN Digital, we spearhead a technology-driven approach to education, leveraging top-tier tech talent from leading technology firms. Through our strategic collaboration with Bodhi Tree Systems, a prominent venture capital firm known for building & scaling tech-first brands, we are revolutionizing education with a tech-first...
-
Application Security Engineer
1 week ago
Bengaluru, Karnataka, India DigiCert Full time ₹ 8,00,000 - ₹ 12,00,000 per yearWho we areWe're a leading, global security authority that's disrupting our own category. Our encryption is trusted by the major ecommerce brands, the world's largest companies, the major cloud providers, entire country financial systems, entire internets of things and even down to the little things like surgically embedded pacemakers. We help companies...
-
Application Security Engineer
1 week ago
Bengaluru, Karnataka, India DigiCert Full time ₹ 12,00,000 - ₹ 36,00,000 per yearWho we areWe're a leading, global security authority that's disrupting our own category. Our encryption is trusted by the major ecommerce brands, the world's largest companies, the major cloud providers, entire country financial systems, entire internets of things and even down to the little things like surgically embedded pacemakers. We help companies...
-
Senior Security Engineer, Applications
2 days ago
Bengaluru, Karnataka, India Postman Full time ₹ 12,00,000 - ₹ 36,00,000 per yearWho Are We?Postman is the world's leading API platform, used by more than 40 million developers and 500,000 organizations, including 98% of the Fortune 500. Postman is helping developers and professionals across the globe build the API-first world by simplifying each step of the API lifecycle and streamlining collaboration—enabling users to create better...
-
Application Security Engineers
1 week ago
Bengaluru, Karnataka, India NETSACH GLOBAL Full time ₹ 12,00,000 - ₹ 36,00,000 per yearGreetings from Netsach - A Cyber Security Company.We are looking for Application security Engineers (2 resources) with 8+ yrs of strong experience who would be responsible for providing technical expertise on secure software development and support of all associated activities, processes, and tools for protecting technology-based informationJob Titlle:...
-
Senior Application Security Engineer
2 weeks ago
Bengaluru, Karnataka, India Hewlett Packard Enterprise | HPE Full time ₹ 12,00,000 - ₹ 36,00,000 per yearSenior Application Security EngineerThis role has been designed as 'Hybrid' with an expectation that you will work on average 2 days per week from an HPE office.Who We Are:Hewlett Packard Enterprise is the global edge-to-cloud company advancing the way people live and work. We help companies connect, protect, analyze, and act on their data and applications...
-
Application Security Engineer
2 weeks ago
Bengaluru, Karnataka, India Procallisto Solutions Full time ₹ 80,00,000 - ₹ 2,00,00,000 per yearCompany Name is looking for an Application Security Engineer to help validate that our services, applications, and websites are designed and implemented to the highest security standards. You will be responsible for analyzing the security of applications and services, discovering and addressing security issues, building security automation, and quickly...