HamburgerMenu
hirist

Spigot Software - Application Security Engineer - DevSecOps

Spigot Software
5 - 9 Years
Bangalore

Posted on: 05/06/2026

Job Description

Role : Application Security Engineer

Location : Bangalore

Experience : 5 to 9 Years

Function :

Software Engineering/Backend Development, Frontend Development

Key Skills :

- DevSecOps

- AWS

- Vulnerability Assessment

- Remediation

- Application Security

Job Description :

We are looking for an experienced Application Security Engineer with strong expertise in Application Security, DevSecOps, and secure CI/CD implementations.

The ideal candidate should have hands-on experience in identifying vulnerabilities, implementing security best practices, and strengthening application security across cloud and modern application environments.

Key Responsibilities :

Perform application security assessments by identifying vulnerabilities, attack techniques, and secure coding gaps across applications.

Conduct and support security testing activities, including:

1. SAST (Static Application Security Testing)

2. DAST (Dynamic Application Security Testing)

3. SCA (Software Composition Analysis)

4. Vulnerability Assessment

5. Remediation Validation

Implement and support DevSecOps practices and secure CI/CD integrations to embed security controls into development workflows.

Apply OWASP guidance and frameworks, including :

1. OWASP Top 10

2. API Security

3. Mobile Security

4. CI/CD Security

5. LLM/Application AI Security considerations

- Support cloud security and vulnerability management initiatives across AWS and/or Azure environments.

Work with AWS security tools, services, and processes, including :

1. Identity and Access Management (IAM)

2. Logging & Monitoring

3. Configuration Review

4. Security Best Practices

- Integrate security tools into CI/CD platforms such as Jenkins, GitLab CI, or similar platforms.

- Review code and understand application logic to identify security weaknesses and control gaps.

- Support implementation of security policies, standards, compliance, and risk management practices.

- Work on secrets management, cloud posture management, API security testing, and software supply chain security initiatives.

Support security testing and controls for modern architectures, including :

1. Microservices

2. Containers

3. Serverless Architectures

4. APIs

- Stay updated with evolving threats, vulnerabilities, and emerging security technologies.

Requirements :

- Minimum 5 years of hands-on experience in Application Security, with at least 2 years of experience in DevSecOps or secure CI/CD implementations.

Strong understanding of application security, including :

1. Common vulnerabilities

2. Attack techniques

3. Secure coding practices

- Working knowledge of cloud security principles and Vulnerability Management, particularly in AWS and/or Azure environments.

- Strong understanding of security policies, standards, compliance, and risk management practices.

- Proficiency in at least one object-oriented programming language, with the ability to review code and understand application logic.

- Strong analytical, research, and problem-solving skills to identify control gaps and security weaknesses.

- Demonstrated commitment to staying current with evolving threats, vulnerabilities, and security technologies.

Educational Qualification :

- Bachelors degree or higher in Computer Science, Computer Engineering, Information Security, or a related technical discipline

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...