We are looking for an Application Security Engineer to help us build, test, and harden secure systems across our products and infrastructure. If you think like an attacker but build like a defender, this role is for you.
Role: Application Security Engineer
Experience Required: 3–5 years
Location: Pune (Work from Office)
Work Days: Monday–Friday + Alternate Saturdays | 10:00 AM – 7:00 PM
Qualifications:
✔ Bachelor's degree in Computer Science, Information Technology, Cyber Security, or a related field
✔ 3–5 years of experience in Application Security / Ethical Hacking / Penetration Testing
✔ Relevant certifications preferred: CEH, OSCP, CompTIA Security+, or equivalent
✔ Solid understanding of OWASP Top 10, secure coding principles, and common application vulnerabilities
✔ Prior experience working closely with development teams in a Secure SDLC environment
Key Responsibilities:
✔ Perform penetration testing and vulnerability assessments on web applications, APIs, and mobile platforms
✔ Conduct secure code reviews and work with developers to fix vulnerabilities early in the SDLC
✔ Define and enforce application security standards, hardening guidelines, and secure configuration baselines
✔ Carry out threat modeling for new features and major architectural changes
✔ Manage vulnerability disclosure, patching cycles, and risk remediation timelines
✔ Monitor for emerging threats, CVEs, and attack techniques relevant to our tech stack
✔ Collaborate with DevOps/Cloud teams to secure CI/CD pipelines and cloud infrastructure
✔ Support incident response efforts when security issues are identified
✔ Document findings, risk ratings, and remediation guidance clearly for both technical and non-technical stakeholders
Required Skills:
✔ Strong hands-on experience in Ethical Hacking / Penetration Testing (OWASP Top 10, API security, authentication/authorization flaws)
✔ Practical knowledge of secure coding practices across at least one major stack (e.g., Node.js, Java, Python, .NET)
✔ Experience with security tools: Burp Suite, OWASP ZAP, Nmap, Metasploit, or similar
✔ Understanding of Secure SDLC and how to embed security checkpoints into development workflows
✔ Vulnerability Assessment & Risk Management experience
✔ Familiarity with cloud security fundamentals (AWS, Azure, or GCP)
Good to Have:
✔ Exposure to ISO 27001 or other compliance/governance frameworks
✔ Experience securing CI/CD pipelines or container environments (Docker/Kubernetes)
Interested candidates can share their resumes at [email protected] or connect with us at 8421142637
Pay: ₹300,000.00 - ₹600,000.00 per year
Benefits:
- Flexible schedule
- Provident Fund
Work Location: In person