Search Jobs

Search by job, company or skills

Application Security Engineer

Application Security Engineer

Hcl Comnet
  • Posted 8 hours ago
  • Be among the first 10 applicants

Job Description

Please share CV to [Confidential Information] with the below details:

Total Experience- Should be 6+ years

Current CTC-

Expected CTC-

Notice period-

Location-

Mandatory skills- hands-on experience in penetration testing,SAST,DAST,SCA and threat modelling.

Application Security Engineer/Lead-

Requirement-

  • Hands-on experience in Threat Modelling using STRIDE for identifying attack vectors, trust boundaries, and mitigation strategies.
  • Strong practical experience in secure code review, vulnerability remediation, and security testing across modern applications.
  • Hands-on experience identifying and exploiting OWASP Top 10 vulnerabilities across Web, API, and LLM-based applications.
  • Practical implementation experience with OAuth 2.0, OpenID Connect (OIDC), JWT security, and cryptographic controls.
  • Hands-on exposure to Responsible AI, AI/ML threat modelling, prompt injection testing, and LLM security controls.
  • Experience securing software supply chains, CI/CD pipelines, containers, and cloud-native platforms.
  • Practical experience performing penetration testing, vulnerability assessments, and remediation validation.
  • Hands-on experience with SAST, DAST, SCA/Open Source scanning, and code quality/code smell management tools.
  • Strong working knowledge of AWS, Azure, and GCP native security services and cloud security best practices.
  • Hands-on experience securing Kubernetes and container platforms, including image security, cluster hardening, admission controls, and runtime threat detection/response.
  • Hands-on experience managing the PSIRT lifecycle, including vulnerability intake, triage, impact assessment, remediation coordination, disclosure and customer communication.

Responsibilities-

  • Lead and Manage Secure Design review and Thread modelling for Applications ( On premise and SaaS based Applications)
  • Develop and implement comprehensive security strategies to safeguard application systems.
  • Define security best practices and standards and Lead Secure Software Development Lifecycle best practices and standards.
  • Oversee security incident response and mitigation efforts, ensuring quick and efficient handling of security breaches or threats.
  • Conduct regular penetration testing, Red team exercise, security assessments and audits to identify vulnerabilities and implement corrective measures.
  • Collaborate with application stakeholders to develop security roadmaps and participate in daily standups to align security initiatives with organizational goals.
  • Foster a culture of continuous improvement in Application security including Development,Supply chain security and AI/ML
  • Experience in managing Business Continuity and Crisis management
  • Staying up-to-date on the latest Application security technologies, trends, and best practices.
  • A strong understanding of cloud computing technologies, including Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS).
  • Knowledge of security frameworks such as SANS,OWASP, NIST and ISO Framework.
  • Certifications such as Certified Secure Software Lifecycle Professional (CSSLP), Certified Information Systems Security Professional (CISSP), or Certified Cloud Architect (CCA) are preferred.
  • Extensive knowledge and experience with developing Cloud Security Frameworks using industry best practices such as those from the Cloud Security Alliance (CSA) and NIST CSF and regulatory requirements such as HIPAA, HITrust and PCI or closely related.
  • Understanding of industry regulatory and compliance requirements (i.e., FedRAMP, PCI-DSS, NIST, HIPAA) and skilled at interpreting the compliance and security requirements into implementable and repeatable control
  • Proven ability to proactively perform security assessments, identify potential risks early, and recommend preventive security controls across applications and infrastructure
  • Hands-on experience in software supply chain risk management, including zero-day exposure analysis, vulnerability tracking and remediation follow-up, and open-source license compliance assessment for allow/deny decisions
  • Hands-on experience performing GenAI and Agentic AI security assessments, including prompt injection testing, model abuse validation, data leakage analysis, insecure tool usage, and agent workflow security review

More Info

Job Type:
Industry:
Employment Type:

Key Skills

software supply chains

OWASP Top 10 vulnerabilities

OAuth 2.0

JWT security

threat modelling

AI ML threat modelling

cloud-native platforms

OpenID Connect

prompt injection testing

cloud security best practices

cryptographic controls

CI CD pipelines

vulnerability remediation

Responsible AI

OIDC

Containers

About Company

Similar Jobs

3-6 yrs
Bengaluru, India
Skills:
Dynamic Application Security Testing (DAST), Vulnerability Management, Swagger, Webinspect, Restful Apis, Postman, Azure, Python, AWS, Risk-based prioritization
8-10 yrs
Bengaluru, India
Skills:
.NET, DAST, Java, Vulnerability Management, Typescript, Javascript, Containers, Python, Kubernetes, AWS, container scanning, SCA, SAST, secret scanning
7-9 yrs
Bengaluru, India
Skills:
threat modeling , secure sdlc , DAST, Vulnerability Management, DevSecOps, Application Security, AI Security, LLM Security, SBOM, Agentic AI Security, SCA, SAST, CI CD security
5-8 yrs
Bengaluru, India
Skills:
.NET, security automation , DAST, C#, Javascript, Python, Java, Kotlin, Authentication, Swift, Secure Storage, Bug Bounty Programs, Authorization, SAST, Thick Client Security Testing, CI/CD Security Automation, Threat Modelling, Cryptographic Best Practices, Manual Code Reviews, Vulnerability Triage, Secure Design Review, Container Security, Application Product Security, Semgrep
6-8 yrs
Bengaluru, India
Skills:
Kubernetes, PowerShell, Bash, Penetration Testing, Burpsuite, DevSecOps, Sqlmap, Docker, Application Security, Kali, Owasp Top 10, Python, Open-source Security Software, SANS Top 25, OWASP ZAP, Security Fundamentals, Checkmarx, Manual Security Code Review