Application Security Engineer

Posted 1 day ago

This is a fully remote position, open to applicants in India.

📋 Description

• Implement, configure, administer, and optimize enterprise SAST capabilities.

• Onboard applications and repositories using documented, repeatable patterns.

• Configure scanning profiles, policies, presets, exclusions, and application-specific settings.

• Analyze findings across various languages and frameworks.

• Validate false positives, duplicate findings, and vulnerability classifications through secure code reviews.

• Provide guidance for remediation and examples of secure coding practices.

• Investigate issues related to failed or incomplete scans, performance, and integration.

• Enhance scan quality through query tuning, configuration optimization, and operational metrics.

• Support initiatives for tool migration, consolidation, or rationalization.

• Design and implement application security controls within CI/CD pipelines.

• Integrate SAST with source code repositories, pull requests, build pipelines, and developer workflows.

• Define risk-based security gates for builds, releases, and production deployments.

• Create and maintain reusable pipeline templates and security components.

• Troubleshoot issues related to authentication, API, repositories, build orchestration, and scan execution.

• Collaborate with DevOps and platform engineering teams to enhance reliability, scalability, and maintainability.

• Develop AppSec automation solutions using Python, PowerShell, Bash, or other suitable programming languages.

• Build integrations using REST APIs, webhooks, command-line interfaces, and supported SDKs.

• Automate processes for onboarding, scanning, result retrieval, triage, reporting, and workflow updates.

• Automate finding normalization, deduplication, enrichment, prioritization, and assignment.

• Integrate AppSec platforms with ticketing systems, reporting tools, source control, and collaboration systems.

• Implement logging, error handling, retries, monitoring, and maintain auditable execution records.

• Maintain automation code through version control, testing, documentation, and peer review.

• Prioritize, validate, and track vulnerabilities through remediation, retesting, risk acceptance, or closure.

• Identify recurring vulnerability patterns and recommend systemic preventive controls.

• Apply cloud security governance principles to application workloads, services, and delivery pipelines.

• Translate cloud control requirements into technical guardrails in collaboration with cloud security, architecture, engineering, risk, and compliance teams.

• Assess applications and pipelines against cloud security standards, configuration baselines, and policy requirements.

• Support governance for cloud identities, roles, service accounts, secrets, encryption, logging, and workload access controls.

• Assist with cloud control assessments, evidence collection, exception management, remediation tracking, and audit readiness across AWS, Microsoft Azure, and Google Cloud.

• Map AppSec and CI/CD controls to enterprise policies, regulatory obligations, and recognized security frameworks.

• Embed application security requirements throughout the design, development, testing, and release processes.

• Support threat modeling and security reviews for high-risk applications or significant changes.

• Create standards, checklists, onboarding guides, runbooks, and technical documentation.

• Deliver technical enablement for developers, DevOps engineers, and security champions.

• Maintain program records, coverage metrics, remediation data, and audit evidence.

• Support control assessments, risk reviews, exception governance, and continuous improvement.


⛳️ Requirements

• Bachelor's or Master's degree in Computer Science, Information Security, Engineering, or a related field, or equivalent practical experience.

• Five or more years of relevant experience in Application Security, Product Security, DevSecOps, or software security engineering.

• Strong hands-on experience with enterprise SAST platforms, secure code analysis, and vulnerability validation.

• Practical experience in integrating security scanning into CI/CD pipelines and source control workflows.

• Experience with GitHub, GitHub Actions, Azure DevOps, Jenkins, GitLab CI, or equivalent technologies.

• Strong scripting or development skills using Python, PowerShell, Bash, Java, C#, JavaScript, or similar programming languages.

• Experience building integrations using REST APIs, webhooks, service accounts, and modern authentication mechanisms.

• Strong understanding of OWASP Top 10, CWE classifications, secure coding practices, and vulnerability remediation.

• Ability to review source code and validate findings in at least one major programming language.

• Understanding of web applications, APIs, microservices, containers, and cloud-native architectures.

• Working knowledge of cloud security governance, security control implementation, compliance evidence, and exception management.

• Understanding of cloud IAM, encryption, secrets management, logging, monitoring, and secure configuration principles.

• Strong analytical, troubleshooting, documentation, and stakeholder communication skills.

• Hands-on administration or integration experience with leading SAST platforms.

• Current or recent vendor certification focused on SAST administration, implementation, query development, scanning, or secure code analysis.

• Knowledge of or certifications in penetration testing, application security, cloud security, DevSecOps, or secure software development are preferred or beneficial.

• Experience integrating SCA, secrets scanning, API security, Infrastructure as Code scanning, or container security is preferred.

• Experience developing reusable CI/CD components is preferred.

• Knowledge of software supply chain security, dependency risk management, and cloud security is preferred.

• Experience producing AppSec dashboards, control evidence, and program metrics is preferred.


🏝️ Benefits

• Health care coverage tailored for both mental and physical well-being.

• Generous time-off policy.

• Continuous learning resources and opportunities for career development.

• Competitive salary.

• Retirement planning options.

• Continuing education program with company-matched contributions for student loans.

• Financial wellness initiatives.

• Family-friendly benefits and perks.

• Retail discounts.

• Referral incentive awards.

People also viewed

Ontrac Solutions1 day ago

Full-Stack AI Application Engineer

US flagUnited States OnlyFreelanceApplication Engineer$90 – $100/hour
ApplyView job
Nebius Group1 day ago

Senior Enterprise Applications Engineer

US flagUnited States OnlyFull-timeApplication Engineer$147.2k – $183.9k/year
ApplyView job
Xcellent Technology Solutions (XTS)1 day ago

JavaScript Applications Engineer

US flagUnited States OnlyFull-timeApplication Engineer$65k – $75k/year
ApplyView job
S&P Global1 day ago

Application Security Engineer

IN flagIndia OnlyFull-timeApplication Engineer
ApplyView job
Alight Solutions1 day ago

ETL, Informatica Application Support Engineer

US flagIllinois OnlyFull-timeApplication Engineer$110k – $130k/year
ApplyView job
Harris Computer1 day ago

Application Support Engineer

GB flagUnited Kingdom OnlyFull-timeApplication Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers