Overview
The Application Security Engineer improves the security posture of Omnissa products and platforms through end-to-end security testing, secure development practices, threat modelling, code reviews, automation and vulnerability root cause analysis. This is an individual contributor role requiring technical expertise, leadership in security initiatives and a proactive approach to process improvement.
What you'll do
- Conduct in-depth manual and automated security testing of Web, Mobile (Android/iOS), and Thick Client applications.
- Perform secure code reviews using manual techniques and tools like Semgrep integrated into CI/CD pipelines.
- Review product features for potential security issues early in the development lifecycle and provide risk-based recommendations.
- Facilitate threat modelling and architecture reviews with product and engineering teams.
- Provide guidance on secure design patterns, attack surface reduction and defense-in-depth strategies.
- Lead initiatives to improve the overall security posture of products and development practices.
- Define and implement scalable security controls and development guardrails.
- Work with Incident Response and Bug Bounty teams to evaluate researcher-submitted and customer-reported issues.
- Conduct variant and root cause analysis for high-severity (P0/P1) bugs and provide long-term remediation guidance.
- Collaborate with Product BU leaders and engineering stakeholders to align on security goals and assist in their execution.
- Act as a trusted security advisor to cross-functional teams across the organization.
- Create, update and maintain threat models.
- Triage and validate externally reported issues against products.
- Provide guidance and education to developers.
- Develop ways to help identify and prevent systematic issues.
What you'll need
- 2 to 8 years of experience in the security domain, specifically in Application/Product Security.
- Penetration testing along with Manual source code review is mandatory.
- Demonstrated expertise in Web, Mobile and Thick Client security testing.
- Demonstrated expertise in threat modelling and secure design review.
- Demonstrated expertise in manual code reviews across multiple languages and frameworks.
- Demonstrated expertise in the use and automation of security tools such as Semgrep, SAST/DAST tools and custom scripts.
- Proficiency with languages such as Java, Kotlin, Swift, JavaScript, Python and C#/.NET.
- Strong understanding of security principles including authentication, authorization, secure storage and cryptographic best practices.
- Excellent communication skills, including the ability to present security issues and recommendations to technical and non-technical stakeholders.
Nice to have
- Hands-on experience with CI/CD security automation, container security and cloud environments (AWS/GCP/Azure).
- Certifications such as OSWE, OSCP, OSEP, GWAPT, GMOB or equivalent.
- Experience working with bug bounty programs, VDPs or vulnerability triage.
- Track record of contributions to the security community, such as blogs, talks, open-source tools or CVEs.
Details
- Location: Bengaluru, India.
Read the full description and apply on the company’s own careers page.