
Search by job, company or skills
Role - Application Security Engineer
Experience - 4-7 yrs
Location - Bangalore
Qualifications & Experience
● Education: Bachelor's degree in Computer Science, Cybersecurity, Information Security, or equivalent practical experience.
● Experience: 3–5+ years in application security, product security, or penetration testing with strong hands-on skills.
● Technical Testing: Demonstrated experience in web application and API security testing; mobile security experience is strongly preferred.
● Tooling: Proficiency with at least two of the following: Accunetix, Burp Suite, OWASP ZAP SonarQube (or other SAST tools), dependency scanning, or secrets scanning
tools.
Technical Knowledge & Skills
● Deep understanding of OWASP Top 10 and API security risks (BOLA/IDOR, mass assignment, rate-limit abuse).
● Strong grasp of authentication and authorization models, including JWT, OIDC, and session handling.
● Working knowledge of DevSecOps practices and embedding security testing into CI workflows (GitHub Actions).
● Ability to build reproducible proofs and utilize scripting (Python/Node) for light automation.
● Familiarity with Cloudflare WAF/API Shield and API gateway architectures (Kong/AWS API Gateway) is a plus.
Job ID: 148483413
Skills:
DevSecOps, Application Security, PowerShell, Bash, Coverity, Python, Azure Cloud Security, Polaris, Wiz, BlackDuck, Jfrog Xray
Skills:
DAST, Config, Bash, Burp Suite, Kms, Iam, Waf, Kubernetes, Python, AWS, OPA, Gatekeeper, Aqua, Go, Security Hub, Kyverno, ZAP, SAST, Falco, GuardDuty, Prisma
Skills:
barracuda , DAST, Cyber Security, Fortify, Penetration Testing, Jenkins, Burp Suite, Gcp, Sonarqube, Owasp Top 10, Appscan, Azure, AWS, Offensive Security, akamai, Snyk, SANS 25, GitHub Actions, OWASP ZAP, SAST, Black Duck, Checkmarx
Skills:
threat modeling , Oauth2, Node.js, Jwt, Django, React, Burp Suite, Gcp, Docker, Sonarqube, Owasp Top 10, FastAPI, Azure, Kubernetes, AWS, SANS CWE Top 25, Zap, Trivy, Semgrep, OIDC
Skills:
Oauth, Java, Saml, Jwt, Typescript, Burp Suite, Gcp, Javascript, Azure, Python, AWS, OpenID Connect, Go, Jadx, Frida, Semgrep, Ghidra
We don’t charge any money for job offers