Omnissa logo

Application Security Engineer (Appsec) - Bengaluru

Omnissa
NewPosted yesterday

LOCATION

Bengaluru · Onsite

EXPERIENCE

2 - 8 Years

TYPE

FullTime

SKILLS REQUIRED

Application SecuritySecure Coding PracticesThreat ModelingPenetration TestingMobile App Security

Job description

Overview

The Application Security Engineer improves the security posture of Omnissa products and platforms through end-to-end security testing, secure development practices, threat modelling, code reviews, automation and vulnerability root cause analysis. This is an individual contributor role requiring technical expertise, leadership in security initiatives and a proactive approach to process improvement.

What you'll do

  • Conduct in-depth manual and automated security testing of Web, Mobile (Android/iOS), and Thick Client applications.
  • Perform secure code reviews using manual techniques and tools like Semgrep integrated into CI/CD pipelines.
  • Review product features for potential security issues early in the development lifecycle and provide risk-based recommendations.
  • Facilitate threat modelling and architecture reviews with product and engineering teams.
  • Provide guidance on secure design patterns, attack surface reduction and defense-in-depth strategies.
  • Lead initiatives to improve the overall security posture of products and development practices.
  • Define and implement scalable security controls and development guardrails.
  • Work with Incident Response and Bug Bounty teams to evaluate researcher-submitted and customer-reported issues.
  • Conduct variant and root cause analysis for high-severity (P0/P1) bugs and provide long-term remediation guidance.
  • Collaborate with Product BU leaders and engineering stakeholders to align on security goals and assist in their execution.
  • Act as a trusted security advisor to cross-functional teams across the organization.
  • Create, update and maintain threat models.
  • Triage and validate externally reported issues against products.
  • Provide guidance and education to developers.
  • Develop ways to help identify and prevent systematic issues.

What you'll need

  • 2 to 8 years of experience in the security domain, specifically in Application/Product Security.
  • Penetration testing along with Manual source code review is mandatory.
  • Demonstrated expertise in Web, Mobile and Thick Client security testing.
  • Demonstrated expertise in threat modelling and secure design review.
  • Demonstrated expertise in manual code reviews across multiple languages and frameworks.
  • Demonstrated expertise in the use and automation of security tools such as Semgrep, SAST/DAST tools and custom scripts.
  • Proficiency with languages such as Java, Kotlin, Swift, JavaScript, Python and C#/.NET.
  • Strong understanding of security principles including authentication, authorization, secure storage and cryptographic best practices.
  • Excellent communication skills, including the ability to present security issues and recommendations to technical and non-technical stakeholders.

Nice to have

  • Hands-on experience with CI/CD security automation, container security and cloud environments (AWS/GCP/Azure).
  • Certifications such as OSWE, OSCP, OSEP, GWAPT, GMOB or equivalent.
  • Experience working with bug bounty programs, VDPs or vulnerability triage.
  • Track record of contributions to the security community, such as blogs, talks, open-source tools or CVEs.

Details

  • Location: Bengaluru, India.

Read the full description and apply on the company’s own careers page.

Stay safe

Hiring on Abekus is free for applicants

We never charge a fee, and employers are prohibited from doing so. If a recruiter asks for payment, please report them right away.

Application Security Engineer (Appsec) - Bengaluru