| Pune, MaharashtraBengaluru, Karnataka
Job Summary
Years of Experience
14+ years of experience in Application Security, secure SDLC, DevSecOps, application-security architecture, and vulnerability management.
General Description
Serve as AppSec L3 SME, providing advanced finding validation, remediation advisory, secure-SDLC guidance, technical governance, and operating-model improvement.
Lead complex vulnerability analysis, application onboarding patterns, policy-driven security gates, exception analysis, and developer enablement.
Mentor L2 engineers and coordinate with security architecture, engineering, risk, external testing providers, and application owners.
Key Responsibilities
Years of Experience
14+ years of experience in Application Security, secure SDLC, DevSecOps, application-security architecture, and vulnerability management.
General Description
Serve as AppSec L3 SME, providing advanced finding validation, remediation advisory, secure-SDLC guidance, technical governance, and operating-model improvement.
Lead complex vulnerability analysis, application onboarding patterns, policy-driven security gates, exception analysis, and developer enablement.
Mentor L2 engineers and coordinate with security architecture, engineering, risk, external testing providers, and application owners.
Skill Requirements
Technical Requirements
Hands-on experience with SAST, SCA, DAST, API security testing, secrets scanning, container/image scanning, and cloud-code security tools such as Wiz Code or equivalent.
Strong understanding of OWASP Top 10, CWE, CVSS, secure coding practices, vulnerability lifecycle, and risk-based prioritization.
Experience triaging application-security findings, validating false positives, assigning severity, and providing remediation guidance.
Experience supporting application onboarding into AppSec tools and secure-SDLC workflows.
Knowledge of Java, JavaScript, Angular, APIs, cloud services, containers, and open-source dependency risks.
Experience with Jira/ServiceNow, finding backlogs, exception workflows, evidence preparation, and AppSec reporting.
Understanding of CI/CD security integration and policy-driven security gates.
Deep expertise in advanced web, API, cloud-native, container, microservices, authentication, authorization, cryptography, and business-logic vulnerabilities.
Experience defining AppSec standards, threat-modeling approaches, secure-design reviews, testing strategies, and risk-based remediation models.
Ability to review complex Java/Spring Boot, Angular, Python, API, AWS, and Kubernetes/EKS application architectures.
Experience designing and integrating AppSec controls into CI/CD pipelines, including policy-as-code and release-security gates.
Ability to lead tool tuning, false-positive reduction, coverage analysis, AppSec metrics, exception governance, and maturity improvement.
Experience supporting regulatory/audit evidence and communicating application risk to senior stakeholders.
Soft Skills
Excellent communication and presentation skills.
Strong problem-solving and critical thinking skills.
Exceptional project management and organizational abilities.
Team collaboration and leadership skills.
Client-focused approach with a commitment to delivering exceptional customer service.
Certifications (Good to have)
Good to have relevant certificates like (any of the below):
CSSLP, OSWE, GWAPT, GWEB, CISSP, or equivalent advanced application-security certification.
Cloud-security or DevSecOps certification is preferred.
Educational Qualifications
University degree in IT or/and IT Security.
Bachelor’s degree in computer science/ IT or any relevant fields.
Other Requirements
#body.unify div.unify-button-container .unify-apply-now: focus, #body.unify div.unify-button-container .unify-apply-#body.unify div.unify-button-container .unify-apply-now: focus, #body.unify div.unify-button-container .unify-apply-