Application Security Analyst - Vulnerability Management
Team: Information Security
Location: Hyderabad, India
Commitment: Full-time
Workplace Type: hybrid
Responsibilities
- Own the day-to-day triage and lifecycle management of application security findings across multiple tools
- Analyze and triage findings from: SAST, SCA to identify dependency risk, exploitability, upgrade paths, secrets scanning and Microsoft Defender – application, container, and cloud workload findings
- Validate findings for false positives, duplicates, environmental relevance, actual exploitability and impact
- Prioritize vulnerabilities based on risk, asset criticality, and business context
- Track remediation progress and enforce agreed-upon SLAs
- Leverage an Application Security Posture Management (ASPM) platform to:
- Correlate findings across application security tool set (SAST, DAST, SCA etc.)
- Reduce noise and improve prioritization accuracy
- Help maintain and improve risk scoring logic, findings normalization, exception and suppression workflows
- Identify gaps in coverage, data quality, or process and propose improvements
- Create and maintain reports and dashboards for different personas: developers (actionable, repo-level views), security leadership (risk posture, trends, SLA compliance) engineering leadership (program health, recurring issues)
- Track and communicate metrics such as: Open vs. closed vulnerabilities, mean time to remediate (MTTR), recurring vulnerability patterns, tool signal-to-noise ratio
- Provide clear, practical remediation guidance for developers, including:
- What the issue is and why it matters
- How to fix it (secure coding patterns, dependency upgrades, config changes)
- When compensating controls or risk acceptance may be appropriate
- Partner directly with development teams to:
- Answer follow-up questions
- Validate fixes
- Reduce repeat findings through education and pattern identification
- Serve as a security point of contact who is helpful, pragmatic, and technically credible
- Communication & Influence
- Communicate risk clearly and professionally to both technical and non-technical stakeholders
- Confidently defend triage decisions and prioritization logic
- Maintain composure and effectiveness when working with strong personalities
- Push back respectfully when security risk is being underestimated or deprioritized
Qualifications
- 3+ years of experience in Application Security, Vulnerability Management
- Hands-on experience with appsec tool chain SAST, SCA, DAST (Appcheck, Mend.IO, SonorQube, Veracode, Snyk etc.)
- Working knowledge of application security fundamentals:
- OWASP Top 10
- Common CWEs and CVEs
- Strong organizational skills with the ability to manage and prioritize large vulnerability backlogs
- Ability to translate technical findings into clear remediation guidance
- Experience using or operating within an ASPM platform
- Familiarity with CI/CD pipelines and GitHub-based workflows
- Experience reducing false positives and tuning AppSec tools
- Exposure to containerized or microservices-based architectures
- Comfort working in fast-paced engineering environments
- Experience operating in AWS-based environments
- Strong written and verbal communication skills
Working Conditions
- This position is a hybrid, based in the Hyderabad, India. Requiring 2 days a week in the office.
- The Information Security Engineer may be required to work flexible hours to accommodate different time zones or urgent situations.
There are more than 50,000 engineering jobs:
Subscribe to membership and unlock all jobs
Engineering Jobs
60,000+ jobs from 4,500+ well-funded companies
Updated Daily
New jobs are added every day as companies post them
Refined Search
Use filters like skill, location, etc to narrow results
Become a member
🥳🥳🥳 452 happy customers and counting...
Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.
To try it out
For active job seekers
For those who are passive looking
Cancel anytime
Frequently Asked Questions
- We prioritize job seekers as our customers, unlike bigger job sites, by charging a small fee to provide them with curated access to the best companies and up-to-date jobs. This focus allows us to deliver a more personalized and effective job search experience.
- We've got over 200,000 jobs from 15,000+ vetted companies. No fake or sleazy jobs here!
- We aggregate jobs from 15,000+ companies' career pages, so you can be sure that you're getting the most up-to-date and relevant jobs.
- We're the only job board *for* software engineers, *by* software engineers… in case you needed a reminder! We add thousands of new jobs daily and offer powerful search filters just for you. 🛠️
- Every single hour! We add 2,000-3,000 new jobs daily, so you'll always have fresh opportunities. 🚀
- Typically, job searches take 3-6 months. EchoJobs helps you spend more time applying and less time hunting. 🎯
- Check daily! We're always updating with new jobs. Set up job alerts for even quicker access. 📅
What Fellow Engineers Say
