Group Company: MarketXpander Services Pvt. Ltd. (LeadSquared)
Designation: Application Security Engineer
Office Location: Cessna Business Park, Bangalore – 4 days WFO
Position Description: The Application Security Engineer will be responsible for securing LeadSquared's SaaS products and infrastructure by conducting security assessments, performing code reviews, managing vulnerabilities, and embedding security practices across the development lifecycle. The role sits at the intersection of engineering and security, requiring both hands-on technical depth and the ability to collaborate with cross-functional teams.
Primary Responsibilities
- Conduct application security assessments across web, API, and mobile platforms
- Perform secure code reviews to identify and remediate vulnerabilities early in the SDLC
- Carry out cloud security assessments for SaaS infrastructure and services (AWS/Azure)
- Manage the vulnerability lifecycle end-to-end — from discovery through to resolution and closure
- Deliver security training and awareness sessions to internal engineering and product teams
- Develop internal tools and frameworks to support security automation and engineering initiatives
Additional Responsibilities
- Integrate security testing into CI/CD pipelines in alignment with DevSecOps practices
- Support compliance-related assessments and audits (ISO 27001, HIPAA)
- Assist in threat modeling exercises and risk assessments for new product features
- Contribute to documentation of security standards, guidelines, and best practices
Reporting Team
- Reporting Designation: Head of Security / VP Engineering (inferred)
- Reporting Department: Information Security / Engineering
Educational Qualifications Preferred
- Category: Full-time
- Field Specialization: Computer Science, Information Security, Cybersecurity, or related field
- Degree: B.Tech / B.E. / B.Sc. in relevant discipline
Required Certification/s: Certifications such as CEH, OSCP, CompTIA Security+, or equivalent are preferred (not mandatory)
Required Training/s: Familiarity with OWASP testing methodologies; hands-on training in SAST/DAST/SCA tooling
Required Work Experience
- Industry: SaaS / Software Product / IT
- Role: Application Security, Product Security, or Penetration Testing
- Years of Experience: 1–3 years in product/application security; minimum 1 year of hands-on software development experience preferred
Key Performance Indicators
- Number and severity of vulnerabilities identified and remediated per quarter
- Coverage of applications assessed (web, API, mobile)
- Time-to-resolution for critical/high vulnerabilities
- Security training sessions delivered and participation rates
- Automation frameworks built and integrated into CI/CD pipelines
Required Competencies
- Analytical thinking with a security-first mindset
- Ability to work collaboratively with engineering and product teams
- Self-driven with the ability to manage multiple assessments simultaneously
- Strong documentation and communication skills for both technical and non-technical audiences
Required Knowledge
- OWASP Top 10, SANS CWE, and common vulnerability frameworks
- Cryptography, authentication mechanisms, and risk assessment principles
- Cloud security best practices on AWS and/or Azure
- Compliance standards: ISO 27001, HIPAA
- Threat modeling concepts and secure SDLC principles
Required Skills
- Hands-on proficiency with Burp Suite, SonarQube, SQLMap, and similar SAST/DAST/SCA tools
- Secure coding practices with scripting ability in Python and/or JavaScript
- CI/CD pipeline integration and DevSecOps tooling
- Security test automation for improved assessment coverage and efficiency
Required Abilities
- Physical: Standard office environment; no specific physical requirements
- Other: Ability to communicate technical findings clearly to diverse stakeholder groups; capacity to prioritize and manage concurrent security workstreams
Work Environment Details: Office-based at Cessna Business Park, Bangalore; hybrid model with 4 days work-from-office per week
Compliance Related: Role involves handling and auditing compliance with ISO 27001 and HIPAA standards