HamburgerMenu
hirist

Senior Application Security Engineer - DevSecOps

Winning Edge
6 - 10 Years
Gurgaon/Gurugram

Posted on: 04/08/2026

Job Description

Role:

We are looking for a Senior Application Security Engineer with strong DevSecOps experience to secure enterprise applications throughout the Software Development Lifecycle. The ideal candidate should have hands-on experience implementing SAST, DAST and SCA within CI/CD pipelines, working with GitHub/GitLab, and collaborating with development teams to remediate security vulnerabilities.

Description:

1. Monitor and Analyze Vulnerabilities:

- Use established scanning tools and processes to identify security issues in mobile and web applications.

- Review scan results, verify risk levels, and recommend remediation strategies to application or engineering teams.

2. Contribute to Security Assessments:

- Participate in ongoing risk-based discussions with product owners, third-party engineers, and other stakeholders about application vulnerabilities.

- Help track and prioritize vulnerabilities according to established timelines and business impact.

3. Maintain Scanning Profiles & Policies:

- Follow and apply existing application security scan profiles and policies (containers, SAST, DAST, and crowd-sourced pen testing).

- Onboard new applications into scanning services and ensure adherence to brand-wide security standards.

4. Collaborate on Awareness & Best Practices:

- Support awareness campaigns and training programs to ensure application development teams follow existing security standards.

- Provide input to engineering teams on secure coding and design principles, referencing frameworks like the OWASP Top 10.

5. Vulnerability Monitoring & Remediation Support:

- Continuously monitor published vulnerabilities across various applications, operating systems, and databases.

- Assist in determining remediation priorities, coordinate with stakeholders, and re-scan to verify fixes.

- Collaborate with engineers for threat modeling and incident response, offering analytic support in root cause analysis.

6. Incident Response Collaboration:

- Work with incident response teams to investigate security incidents affecting applications.

- Help document findings, track remediation progress, and apply lessons learned to future prevention activities.

Basic Qualifications:

- Bachelors degree and at least 7 years of combined experience in cybersecurity and/or software development. (Equivalent experience may be considered in lieu of a degree.)

- Practical understanding of application cybersecurity vulnerabilities, the ability to assess their relevance, and experience planning remediation efforts.

- Strong communication skills to collaborate with technical personnel and third parties on vulnerability findings.

- Familiarity with continuous integration/continuous delivery (CI/CD) platforms.

- Awareness of compliance and data privacy regulations (e.g., PCI DSS, GDPR, CCPA) and their impact on application security.

- General knowledge of common programming languages and paradigms (OOP, functional, concurrent, etc.).

Technical Qualifications:

- Understanding of cloud environment security concepts (secrets management, infrastructure as code, serverless).

- Familiarity with CI/CD build/deployment pipeline technologies.

- Experience with application scanning tools (dynamic and static techniques) to interpret vulnerabilities and support remediation.

- Basic knowledge of containers and container management tools (e.g., Docker, Kubernetes), with the ability to recognize security findings and escalate them to engineering for remediation.

- Knowledge of HTTP communication fundamentals.

- Awareness of package management tools (npm, pip, apt) for operating systems or development languages.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...