Application Security Engineer

Posted 1 day ago

This is a fully remote position, open to applicants in India.

📋 Description

• Implement, configure, manage, and enhance enterprise SAST capabilities.

• Onboard applications and repositories utilizing repeatable, well-documented patterns.

• Configure scanning profiles, policies, presets, exclusions, and application-specific settings.

• Analyze findings across various languages and frameworks; validate false positives, duplicates, and classifications of vulnerabilities.

• Provide guidance for remediation and examples of secure coding practices.

• Investigate issues with failed or incomplete scans, performance challenges, and integration obstacles.

• Design and implement application security controls within CI/CD pipelines.

• Integrate SAST with repositories, pull requests, build pipelines, and developer workflows.

• Establish risk-based security gates for builds, releases, and production deployments.

• Create reusable pipeline templates and security components.

• Develop AppSec automation using Python, PowerShell, Bash, or other suitable programming languages.

• Build integrations for REST APIs, webhooks, CLI, and SDKs.

• Automate onboarding, scanning, result retrieval, triage, reporting, and workflow updates.

• Automate finding normalization, deduplication, enrichment, prioritization, and assignment.

• Integrate AppSec platforms with ticketing, reporting, source-control, and collaboration systems.

• Prioritize, validate, track, and remediate vulnerabilities until closure or risk acceptance.

• Apply cloud security governance principles to application workloads, services, and delivery pipelines.

• Support cloud control assessments, evidence gathering, exception management, remediation tracking, and audit readiness.

• Map AppSec and CI/CD controls to enterprise policies, regulatory requirements, and recognized security frameworks.

• Embed security requirements throughout the design, development, testing, and release processes.

• Support threat modeling and security reviews for high-risk applications.

• Create standards, checklists, onboarding guides, runbooks, and technical documentation.

• Deliver technical enablement for developers, DevOps engineers, and security champions.

• Maintain program records, coverage metrics, remediation data, and audit evidence.

• Collaborate with teams in application development, DevOps, platform engineering, security architecture, risk, cloud, and compliance.


⛳️ Requirements

• Bachelor’s or Master’s degree in Computer Science, Information Security, Engineering, or a related field, or equivalent practical experience.

• At least five years of relevant experience in Application Security, Product Security, DevSecOps, or software security engineering.

• Hands-on experience with enterprise SAST platforms, secure code analysis, and vulnerability validation.

• Experience in integrating security scanning into CI/CD pipelines and source-control workflows.

• Familiarity with GitHub, GitHub Actions, Azure DevOps, Jenkins, GitLab CI, or equivalent technologies.

• Strong scripting or development skills in Python, PowerShell, Bash, Java, C#, JavaScript, or similar languages.

• Experience building integrations with REST APIs, webhooks, service accounts, and modern authentication methods.

• Strong understanding of OWASP Top 10, CWE classifications, secure coding practices, and vulnerability remediation.

• Ability to review source code and validate findings in at least one major programming language.

• Understanding of web applications, APIs, microservices, containers, and cloud-native architectures.

• Working knowledge of cloud security governance, security control implementation, compliance evidence, and exception management.

• Understanding of cloud IAM, encryption, secrets management, logging, monitoring, and secure configuration principles.

• Strong analytical, troubleshooting, documentation, and stakeholder communication skills.

• Preferred or current vendor certifications such as OSCP, CSSLP, CASE, GWAPT, OSWE, eWPTX, or relevant cloud security certifications are advantageous.

• Knowledge of NIST CSF, NIST SP 800-53, ISO/IEC 27001, SOC 2, or PCI DSS is beneficial.

• Experience with SCA, secrets scanning, API security, Infrastructure as Code scanning, or container security is beneficial.

• Experience developing reusable CI/CD components and producing AppSec dashboards and metrics is beneficial.


🏝️ Benefits

• Comprehensive health care coverage designed for both mental and physical well-being.

• Generous time off policies.

• Access to continuous learning resources and career development opportunities.

• Competitive compensation package.

• Retirement planning assistance.

• Continuing education programs.

• Company-matched contributions for student loans.

• Financial wellness initiatives.

• Family benefits and perks.

• Discounts at retail partners.

• Referral incentive awards.

People also viewed

Ontrac Solutions1 day ago

Full-Stack AI Application Engineer

US flagUnited States OnlyFreelanceApplication Engineer$90 – $100/hour
ApplyView job
Nebius Group1 day ago

Senior Enterprise Applications Engineer

US flagUnited States OnlyFull-timeApplication Engineer$147.2k – $183.9k/year
ApplyView job
Xcellent Technology Solutions (XTS)1 day ago

JavaScript Applications Engineer

US flagUnited States OnlyFull-timeApplication Engineer$65k – $75k/year
ApplyView job
S&P Global1 day ago

Application Security Engineer

IN flagIndia OnlyFull-timeApplication Engineer
ApplyView job
Alight Solutions1 day ago

ETL, Informatica Application Support Engineer

US flagIllinois OnlyFull-timeApplication Engineer$110k – $130k/year
ApplyView job
Harris Computer1 day ago

Application Support Engineer

GB flagUnited Kingdom OnlyFull-timeApplication Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers