Senior Application Security Engineer
Team: Digital & Digital Commerce
Location: Ahmedabad, Gujarat, India - Remote
Commitment: Full Time
Workplace Type: hybrid
Responsibilities
- Perform manual and automated security assessments of web, mobile, and cloud applications
- Collaborate with development and engineering teams to embed security into SDLC (DevSecOps)
- Conduct secure code reviews, threat modeling exercises, and risk assessments to identify security weaknesses in application design.
- Implement and manage application security tools (SAST, DAST, SCA, IAST)
- Design and enforce security policies, standards, and procedures for application development
- Monitor, triage, and respond to application-layer vulnerabilities and incidents
- Work closely with QA and engineering teams to drive security testing and fix validation
- Lead the Incident Response effort for application-related security events.
- Stay current on the latest security threats, vulnerabilities, and industry's best practices
- Conduct developer training and promote a security-first culture within engineering
- Cross-train team members on Application Security principles.
- Actively participate in the broader corporate security efforts, including infrastructure security, end-user training, and vulnerability management.
Requirements
- Bachelor's degree in Computer Science, Cybersecurity, or related field (or equivalent experience).
- 8+ years in application security, secure software development, and penetration testing.
- Strong understanding of web technologies (HTML, JavaScript, Python, REST APIs, etc.).
- Experience with security tools for code security, bug bounty programs, and the ability to integrate them into CI/DC pipelines for automated security testing.
- Familiarity with OWASP Top 10, SANS Top 25, CWE, CVE, and secure coding practices.
- Knowledge of cloud environments (AWS, Azure, GCP) and their security features.
- Strong communication and interpersonal skills, with the ability to collaborate effectively with technical and non-technical stakeholders.
Preferred Qualifications
- Industry certifications such as CSSLP, GWAPT, OSCP, or CEH
- Experience with container security and CI/CD pipeline integration
- Familiarity with regulatory and compliance frameworks (e.g., SOC 2, ISO 27001, PCI DSS)
- Prior experience working in agile, DevOps, or fast-paced development environments
There are more than 50,000 engineering jobs:
Subscribe to membership and unlock all jobs
Engineering Jobs
60,000+ jobs from 4,500+ well-funded companies
Updated Daily
New jobs are added every day as companies post them
Refined Search
Use filters like skill, location, etc to narrow results
Become a member
🥳🥳🥳 452 happy customers and counting...
Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.
To try it out
For active job seekers
For those who are passive looking
Cancel anytime
Frequently Asked Questions
- We prioritize job seekers as our customers, unlike bigger job sites, by charging a small fee to provide them with curated access to the best companies and up-to-date jobs. This focus allows us to deliver a more personalized and effective job search experience.
- We've got over 200,000 jobs from 15,000+ vetted companies. No fake or sleazy jobs here!
- We aggregate jobs from 15,000+ companies' career pages, so you can be sure that you're getting the most up-to-date and relevant jobs.
- We're the only job board *for* software engineers, *by* software engineers… in case you needed a reminder! We add thousands of new jobs daily and offer powerful search filters just for you. 🛠️
- Every single hour! We add 2,000-3,000 new jobs daily, so you'll always have fresh opportunities. 🚀
- Typically, job searches take 3-6 months. EchoJobs helps you spend more time applying and less time hunting. 🎯
- Check daily! We're always updating with new jobs. Set up job alerts for even quicker access. 📅
What Fellow Engineers Say
