
Application Security Engineer
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in India.
• Implement, configure, manage, and enhance enterprise SAST capabilities.
• Onboard applications and repositories utilizing repeatable, well-documented patterns.
• Configure scanning profiles, policies, presets, exclusions, and application-specific settings.
• Analyze findings across various languages and frameworks; validate false positives, duplicates, and classifications of vulnerabilities.
• Provide guidance for remediation and examples of secure coding practices.
• Investigate issues with failed or incomplete scans, performance challenges, and integration obstacles.
• Design and implement application security controls within CI/CD pipelines.
• Integrate SAST with repositories, pull requests, build pipelines, and developer workflows.
• Establish risk-based security gates for builds, releases, and production deployments.
• Create reusable pipeline templates and security components.
• Develop AppSec automation using Python, PowerShell, Bash, or other suitable programming languages.
• Build integrations for REST APIs, webhooks, CLI, and SDKs.
• Automate onboarding, scanning, result retrieval, triage, reporting, and workflow updates.
• Automate finding normalization, deduplication, enrichment, prioritization, and assignment.
• Integrate AppSec platforms with ticketing, reporting, source-control, and collaboration systems.
• Prioritize, validate, track, and remediate vulnerabilities until closure or risk acceptance.
• Apply cloud security governance principles to application workloads, services, and delivery pipelines.
• Support cloud control assessments, evidence gathering, exception management, remediation tracking, and audit readiness.
• Map AppSec and CI/CD controls to enterprise policies, regulatory requirements, and recognized security frameworks.
• Embed security requirements throughout the design, development, testing, and release processes.
• Support threat modeling and security reviews for high-risk applications.
• Create standards, checklists, onboarding guides, runbooks, and technical documentation.
• Deliver technical enablement for developers, DevOps engineers, and security champions.
• Maintain program records, coverage metrics, remediation data, and audit evidence.
• Collaborate with teams in application development, DevOps, platform engineering, security architecture, risk, cloud, and compliance.
• Bachelor’s or Master’s degree in Computer Science, Information Security, Engineering, or a related field, or equivalent practical experience.
• At least five years of relevant experience in Application Security, Product Security, DevSecOps, or software security engineering.
• Hands-on experience with enterprise SAST platforms, secure code analysis, and vulnerability validation.
• Experience in integrating security scanning into CI/CD pipelines and source-control workflows.
• Familiarity with GitHub, GitHub Actions, Azure DevOps, Jenkins, GitLab CI, or equivalent technologies.
• Strong scripting or development skills in Python, PowerShell, Bash, Java, C#, JavaScript, or similar languages.
• Experience building integrations with REST APIs, webhooks, service accounts, and modern authentication methods.
• Strong understanding of OWASP Top 10, CWE classifications, secure coding practices, and vulnerability remediation.
• Ability to review source code and validate findings in at least one major programming language.
• Understanding of web applications, APIs, microservices, containers, and cloud-native architectures.
• Working knowledge of cloud security governance, security control implementation, compliance evidence, and exception management.
• Understanding of cloud IAM, encryption, secrets management, logging, monitoring, and secure configuration principles.
• Strong analytical, troubleshooting, documentation, and stakeholder communication skills.
• Preferred or current vendor certifications such as OSCP, CSSLP, CASE, GWAPT, OSWE, eWPTX, or relevant cloud security certifications are advantageous.
• Knowledge of NIST CSF, NIST SP 800-53, ISO/IEC 27001, SOC 2, or PCI DSS is beneficial.
• Experience with SCA, secrets scanning, API security, Infrastructure as Code scanning, or container security is beneficial.
• Experience developing reusable CI/CD components and producing AppSec dashboards and metrics is beneficial.
• Comprehensive health care coverage designed for both mental and physical well-being.
• Generous time off policies.
• Access to continuous learning resources and career development opportunities.
• Competitive compensation package.
• Retirement planning assistance.
• Continuing education programs.
• Company-matched contributions for student loans.
• Financial wellness initiatives.
• Family benefits and perks.
• Discounts at retail partners.
• Referral incentive awards.
Ontrac Solutions
Nebius Group
Xcellent Technology Solutions (XTS)
S&P Global
Get handpicked remote jobs straight to your inbox weekly.