Overview
As a Security Engineer-II in Application Security, identify and help remediate application security vulnerabilities across software development and delivery workflows. Partner with engineering and product teams to embed secure-by-design practices throughout the software development lifecycle.
What you'll do
- Identify, assess, and help remediate application security vulnerabilities across software development and delivery workflows.
- Partner with engineering and product teams to embed secure-by-design practices throughout the software development lifecycle.
- Perform security reviews, threat modeling, and risk analysis for applications, services, APIs, and data flows.
- Integrate, maintain, and continuously improve security tooling and automation across CI/CD pipelines, including SAST, DAST, SCA, dependency scanning, and software supply chain protections.
- Participate in security design reviews alongside senior engineers.
- Identify risks in API design, data models, and system architecture, and recommend fixes based on application security principles.
- Safely integrate and operate AI/ML-enabled solutions that improve application security outcomes.
- Apply AI/ML concepts to real-world products and workflows.
What you'll need
- Bachelor’s degree in computer science, information security, engineering, or a related technical field, or equivalent practical experience.
- 2+ Experience in application security, software engineering, cybersecurity, or a related technical discipline.
- Familiarity with how vulnerabilities are identified, assessed, and fixed in applications, such as priority based triaging or verifying a fix.
- Working knowledge of common web and API vulnerabilities, such as OWASP Top 10, and how to prevent them.
- Ability to read code, identify security issues, and explain them clearly to developers.
Nice to have
- Hands-on experience identifying vulnerabilities in web applications or APIs through code review, testing tools such as Burp Suite, CTFs, bug bounty programs, or personal projects.
- Experience writing scripts or small tools to automate an application security task, such as running a scanner in CI/CD, parsing and triaging scan results, or writing a custom SAST rule, such as Semgrep or CodeQL.
- Exposure to threat modeling or secure design concepts, such as authentication, authorisation, input validation, and data protection.
- Familiarity with triaging SAST, SCA, or secrets-scanning findings, including telling true positives from false positives.
- Hands-on experience building AI-powered applications, such as LLM-based tools, agents, or automation workflows, through work, internships, personal projects, or open source.
Details
- Location: Gurgaon, India.
Read the full description and apply on the company’s own careers page.