
Application Security Engineer
Posted Sep 8

Posted Sep 8
This is a fully remote position, open to applicants in India.
• Take ownership of application security for designated business functions through threat modeling, architectural evaluations, penetration testing, secure coding initiatives, and vulnerability management.
• Conduct manual penetration testing and vulnerability assessments on web applications, APIs, and Android mobile applications.
• Execute security assessments for AI-native products, models, pipelines, and inference services.
• Integrate applications into the SSDLC program and act as the primary security liaison for application products.
• Manage security incident responses for product-layer issues, develop remediation plans, and monitor resolutions until completion.
• Incorporate and optimize SAST, DAST, IAST, and SCA tools in CI/CD, create customized rules as necessary, and address false positives.
• Review and strengthen cloud infrastructure, including Kubernetes RBAC, pod security measures, network policies, Istio service mesh, Keycloak/OIDC configurations, and IAM across AWS, DigitalOcean, GCP, and Firebase.
• Clearly communicate vulnerabilities and risks to developers, product managers, and leadership in a manner that prompts actionable results.
• Facilitate application security training sessions for engineers and product managers.
• A Bachelor’s degree in Computer Science, Cyber Security, or a related field.
• Minimum of 2 years of practical application security experience, preferably in product-based or SaaS companies working closely with engineering teams.
• Strong understanding of OWASP Top 10, API Security Top 10, and common authorization vulnerabilities including BOLA, BFLA, and privilege escalation.
• Experience in manual testing of web applications, APIs, and Android apps, including conducting manual code reviews beyond simply utilizing tools.
• Familiarity with OAuth2, OIDC, JWT, and common misconfigurations in providers like Keycloak and Firebase.
• Experience with integrating and fine-tuning SAST/DAST and optionally SCA/IAST tools within CI/CD pipelines.
• Knowledge of cloud-native security: Kubernetes, containers, service mesh, Istio mTLS and policies, and IAM concepts across at least one major cloud provider.
• Awareness of AI/LLM security risks, including the OWASP LLM Top 10.
• Hands-on experience implementing guardrails, prompt validation, output filtering, or other safety controls in production AI features, or evaluating insecure usage of third-party AI APIs.
• Proficiency in scripting/automation using tools such as Python or Bash to enhance testing, data collection, and reporting processes.
• Interest in or experience with developing AI-based security tools that enhance coverage or decrease manual workload.
• Familiarity with Cloudflare WAF, perimeter security scanning, and/or red-team testing is a plus.
• Opportunities for professional development in a fast-paced, rapidly growing industry with a significant social impact.
• A collaborative and open-minded culture composed of passionate colleagues motivated by the challenge of innovation to create a profound impact on people and the planet.
• A genuinely multicultural environment: you will have the opportunity to work with and learn from individuals from various geographies, nationalities, and backgrounds.
• Structured, customized learning and development programs designed to enhance your capabilities as a leader, manager, and professional through the Sun King Center for Leadership.
3M
Lenze
Compose.ly
GE Vernova
Get handpicked remote jobs straight to your inbox weekly.