Search by job, company or skills

TECHNICAL LEAD - Application Security

  • Posted 6 hours ago
  • Be among the first 10 applicants

Job Description

Principal Security Engineer

Location: Bengaluru, India

Years of Experience: 12+ years

Job Summary: We are seeking a highly skilled Principal Security Engineer with extensive experience in Application Security, Cloud Security, and DevSecOps. The ideal candidate will have a proven track record in enterprise and regulated environments, demonstrating expertise in vulnerability assessment and penetration testing (VAPT), threat modeling, and secure software development lifecycle (SDLC) implementation. This role requires a hands-on approach to integrating security into CI/CD pipelines and collaborating with cross-functional teams to ensure secure application deployments.

Responsibilities

  • Conduct comprehensive vulnerability assessments and penetration testing across applications, APIs, web, mobile, and thick-client environments.
  • Implement secure SDLC practices aligned with industry standards such as OWASP Top 10, NIST, ISO 27001, PTES, and ASVS.
  • Perform threat modeling using STRIDE methodology to identify and mitigate potential security risks.
  • Manage the vulnerability lifecycle, including identification, remediation, and reporting of security issues.
  • Conduct architecture security reviews to ensure compliance with security best practices.
  • Integrate security tools (SAST/DAST) into CI/CD pipelines using GitHub Actions and DevSecOps methodologies.
  • Provide guidance on cloud and container security, specifically with Docker and Kubernetes.
  • Collaborate with engineering, infrastructure, and business stakeholders to develop secure, scalable, and compliant enterprise solutions.

Mandatory Skills

  • Strong knowledge and experience in Application Security.
  • 12+ years of experience in Application Security, Cloud Security, and DevSecOps.
  • Hands-on experience with SAST/DAST tools such as Fortify SCA/SSC, Checkmarx, Burp Suite, Invicti (Netsparker), Qualys, and Nessus.
  • Proven ability to manage vulnerability lifecycle and perform architecture security reviews.
  • Experience in integrating security into CI/CD pipelines.
  • Strong background in cloud and container security.

Preferred Skills

  • Experience with compliance and risk management frameworks.
  • Familiarity with secure application deployment practices.
  • Excellent communication and leadership skills.

Qualifications

  • Bachelor's degree in Computer Science, Information Security, or a related field.
  • Relevant security certifications (e.g., CISSP, CISM, CEH) are a plus.

If you are a proactive and experienced security professional looking to make a significant impact in a dynamic environment, we encourage you to apply.

Application Security

More Info

Job Type:
Industry:
Employment Type:

Job ID: 152041757

Beware of Scammers

We don’t charge money for job offers