thehirehub.ai demo
See all jobs at thehirehub.ai demoSenior Application Security Engineer
Posted 2 days ago
- Pay
- Not shared
- Location
- Hybrid · Bengaluru
- Experience
- 7–10 yrs · Senior
- Type
- Full-time
Location: Bangalore, India | Experience: Senior Level (7-10 years)
About the Company
We are a technology-led organization building and operating products where trust, resilience, and secure customer experiences are essential to business growth. Our teams work across engineering, product, infrastructure, and operations to solve complex problems at meaningful scale. Security is treated as a business enabler: it strengthens product quality, protects customer and company data, and supports responsible innovation. We value engineers who combine technical depth with practical judgment, communicate clearly, and improve systems rather than simply identify issues. As the company continues to grow, application security will play a central role in embedding secure design, development, testing, and deployment practices across the product lifecycle. This is an opportunity to shape how security is practiced across engineering, influence decisions early, and create durable controls that help teams move quickly with confidence. You will join a collaborative environment where ownership, measurable risk reduction, and continuous learning matter.
About the Role
As Senior Application Security Engineer, you will own the application security program across the software development lifecycle. You will partner with engineering and product teams to identify, prioritize, and reduce material risk through secure architecture, developer enablement, testing, and vulnerability management. The role combines hands-on technical work with influence: you will establish practical standards, improve security tooling and feedback loops, and help teams resolve issues at the right stage of delivery. Success means fewer repeat vulnerabilities, faster remediation of meaningful findings, stronger security decisions in design reviews, and a development culture that treats security as part of product quality. You will also help mature application security measurement and communicate risk clearly to technical and business stakeholders.
Key Responsibilities
- Own application security strategy and execution across design, development, testing, deployment, and production, creating measurable reductions in exploitable risk and recurring security weaknesses.
- Lead threat modeling and secure architecture reviews for critical products, translating business and technical context into prioritized controls that improve resilience without unnecessarily slowing delivery.
- Build and mature SAST, DAST, SCA, secrets detection, API security, and software supply-chain controls, improving signal quality, developer adoption, and remediation outcomes.
- Partner with engineers through secure design consultations, code reviews, and enablement programs, turning recurring findings into reusable patterns, guardrails, and better engineering practices.
- Manage vulnerability triage and remediation workflows, defining severity, ownership, service levels, and escalation paths so material risks receive timely and accountable treatment.
- Support incident investigation and security response for application-layer events, using lessons learned to strengthen detection, prevention, architecture, and operational readiness.
- Establish application security metrics and reporting for engineering and leadership, connecting control performance and remediation trends to customer trust, delivery confidence, and business risk.
Essential Skills & Technologies
- Strong expertise in application security, secure software development, threat modeling, OWASP risks, vulnerability assessment, and security architecture across modern web, mobile, API, and distributed systems.
- Hands-on experience with SAST, DAST, SCA, secrets scanning, container or infrastructure security, API testing, CI/CD integrations, and security automation using relevant commercial or open-source tools.
- Ability to influence engineering teams, assess risk pragmatically, communicate clearly with technical and non-technical stakeholders, and drive remediation from discovery through verified closure.
Additional Plus
- Experience securing cloud-native platforms, microservices, Kubernetes, service-to-service authentication, identity systems, and software supply-chain processes in complex production environments.
- Relevant security certifications such as CISSP, CSSLP, OSCP, or equivalent demonstrated expertise, along with experience developing internal standards, training, or developer security communities.
- Familiarity with regulatory expectations, privacy principles, secure SDLC governance, and quantitative security metrics that support prioritization and executive decision-making.
What You'll Bring
- 7–10 years of progressive experience in application security, product security, software engineering, security engineering, or a closely related discipline, with substantial ownership of production-facing security outcomes.
- Strong understanding of modern application architectures and the ability to review code, APIs, cloud deployments, authentication flows, data handling, and third-party dependencies for meaningful security risks.
- A balanced approach to risk: you can distinguish exploitable business impact from theoretical weakness, prioritize effectively, and recommend controls that engineering teams can adopt sustainably.
- Demonstrated ability to build trusted partnerships with developers, architects, product managers, platform teams, and leadership while maintaining clear security accountability.
- Experience designing security programs and operating mechanisms, not only conducting point-in-time assessments; you measure adoption, remediation quality, and residual risk over time.
- Excellent written and verbal communication, including the ability to explain complex vulnerabilities, document decisions, facilitate reviews, and present actionable risk narratives to varied audiences.
- A hands-on mindset and curiosity to investigate unfamiliar systems, automate repetitive work, learn continuously, and improve security outcomes through practical engineering.
- A relevant bachelor’s degree or equivalent practical experience, with professional security certifications or demonstrable expertise considered valuable.
Why Join Us
- Shape application security at a growing technology organization by embedding secure engineering into products, platforms, and delivery systems rather than operating as a late-stage review function.
- Work with experienced cross-functional teams on high-impact security problems where your technical judgment, systems thinking, and ability to influence will directly improve resilience and customer trust.
- Build durable security capabilities, metrics, and developer practices that scale with the organization and create visible business value through reduced risk and more confident delivery.
What We Offer
- A senior, high-ownership role with the scope to define application security priorities, influence engineering standards, and build mechanisms that scale across the organization.
- A hybrid working model that supports focused individual work, effective collaboration, and meaningful connection with colleagues in Bangalore and across relevant teams.
- The opportunity to work on technically challenging security problems, expand your influence across the product lifecycle, and grow alongside a technology-led organization.
Skills
- Application Security
- Scrum (Software Development)
- Threat Modeling
- OWASP
- AI Security Architect
- Vulnerability Assessment
- Static Application Security Testing (SAST)
- Dynamic Application Security Testing (DAST)
- Software Composition Analysis (SCA)
- Secret Scanning
- API security
- CCNP Security
- UI Automation
- Vulnerability Management