Revantage logo

Associate, Application Development Security Engineer

Revantage
NewPosted today

LOCATION

Bengaluru · Hybrid

EXPERIENCE

4 - 6 Years

TYPE

FullTime

SALARY

Negotiable

SKILLS REQUIRED

Application SecurityThreat ModelingDevSecOpsCI/CDInfrastructure as CodeAPI SecuritySASTDAST

Job description

Overview

Revantage is seeking a mid-level Application Development Security Engineer based in Bengaluru, India. The role partners with software engineering, DevOps, cloud engineering and product teams to integrate security throughout the Software Development Lifecycle and enable rapid, secure software delivery.

What you'll do

  • Coordinate with the broader Information Security team and perform duties that support its primary mission and priorities.
  • Integrate security throughout the Software Development Lifecycle using DevSecOps and secure-by-design practices.
  • Implement and maintain automated security testing and security controls within CI/CD pipelines.
  • Perform SAST, DAST, SCA, IaC, API, container and secrets-security assessments.
  • Conduct application threat modeling, secure-design reviews and application-security architecture reviews for new applications and cloud services.
  • Identify, prioritize and coordinate remediation of application and software-supply-chain vulnerabilities.
  • Partner with software developers to strengthen secure-coding practices and resolve security findings without unnecessarily slowing delivery.
  • Develop and maintain security guardrails for Azure DevOps, GitHub, GitLab, Jenkins and other CI/CD platforms.
  • Secure Infrastructure as Code deployments using Terraform, ARM/Bicep, CloudFormation and similar technologies.
  • Assess and secure Kubernetes, Docker, serverless, APIs and other cloud-native workloads.
  • Evaluate open-source dependencies and third-party software for supply-chain risk.
  • Develop and maintain security standards, reusable templates, developer guidance and enablement materials.
  • Research emerging application-security threats, assess their relevance to ACC and recommend practical improvements.
  • Participate in incident response with emphasis on application-layer vulnerabilities and coordinate remediation with engineering and operations teams.
  • Support a 24x7 operational environment through scheduled rotation and on-call coverage for US nights and weekends, US and India holidays, incidents, critical production events and business-continuity needs.
  • Perform other projects and responsibilities as assigned.

What you'll need

  • Strong understanding of secure software-development principles and common threat frameworks, including the OWASP Top 10, CWE and MITRE ATT&CK.
  • Experience designing and implementing secure CI/CD pipelines and controls.
  • Working knowledge of Azure DevOps, GitHub Actions, GitLab CI, Jenkins and similar platforms.
  • Hands-on experience with SAST, DAST, SCA, IaC, container, API and secrets-scanning tools, including Burp Suite, SonarQube, GitHub CodeQL, Snyk, Veracode and ShiftLeft.
  • Familiarity with Docker, Kubernetes, Azure Kubernetes Service (AKS) and similar container platforms.
  • Experience with scripting and automation using Python, PowerShell, Bash or JavaScript.
  • Working knowledge of cloud platforms, including Microsoft Azure, Amazon Web Services (AWS) and Google Cloud.
  • Strong understanding of OAuth, OpenID Connect, authentication, authorization and secure API development.
  • Excellent collaboration and communication skills, particularly when working with software-engineering, DevOps, cloud and product teams.
  • Proficiency in the secure and responsible use of generative AI tools such as ChatGPT, Claude, Microsoft Copilot and Google Gemini.
  • Experience integrating AI security into the Secure Software Development Lifecycle, including identifying and mitigating risks involving AI models, APIs, prompt injection, data exposure, insecure model interactions and third-party AI services.
  • Must hold, or be capable of passing within one year of the hire date, Exam AI-901: Microsoft Azure AI Fundamentals.
  • Administrator-level experience with enterprise security tools, including Microsoft Defender; CrowdStrike Falcon Complete/MDR, Identity Threat Protection, Shield, Recon+, Cloud Security and Next-Gen SIEM; Wiz; Zscaler ZIA, ZPA, ZDX and ZTA; and Proofpoint TAP and DLP.
  • Demonstrated ability to extract, validate and communicate operational reports and security metrics from these platforms.
  • Bachelor's degree in computer science, software engineering, cybersecurity or a related field, or equivalent professional experience.
  • Four to six years of application security, DevSecOps, software-engineering or cloud-security experience.
  • Experience integrating security into CI/CD pipelines and applying secure software-development methodologies.
  • Experience performing application-security assessments and secure code reviews.

Nice to have

  • ISC2 Certified Secure Software Lifecycle Professional (CSSLP).
  • GIAC Web Application Penetration Tester (GWAPT).
  • GIAC Certified Web Application Defender (GWEB).
  • Microsoft Certified: Azure Security Engineer Associate.
  • Certified Kubernetes Security Specialist (CKS).
  • Microsoft Certified: DevOps Engineer Expert.

Details

  • Location: Bengaluru, India.
  • Working hours will provide meaningful daily overlap with US Central Time.
  • Participates in rotating on-call coverage for US nights and weekends.
  • Provides coverage on US and India holidays to support uninterrupted operations.
  • Supports a 24x7 operational environment through scheduled rotation and on-call coverage.
  • Reports to the Chief Information Security Officer (CISO).
  • Hired through Revantage India.

Read the full description and apply on the company’s own careers page.

Stay safe

Hiring on Abekus is free for applicants

We never charge a fee, and employers are prohibited from doing so. If a recruiter asks for payment, please report them right away.

Associate, Application Development Security Engineer