Search Jobs

Search by job, company or skills

Application Security Engineer

Application Security Engineer

Ola
  • Posted 3 months ago
  • Over 100 applicants have applied

Job Description

Job Title: Application Security Engineer

Job Summary:

A Security Engineer will be responsible for ensuring the security and privacy of the company's products and services. This role will be vital in shaping the company's security strategy by working closely with development teams to identify, evaluate, and mitigate potential security risks and ensuring that all products are designed, built, and deployed with security as a critical consideration.

Roles and Responsibilities:

  1. Embed security in all products and services, including architecture, development, deployment, and maintenance, through the SSDLC program.
  2. Perform threat modeling, security reviews, code assessments, penetration testing, and overall application security evaluations.
  3. Develop and implement security policies, standards, and guidelines to secure product development processes.
  4. Identify and mitigate security risks across the product life cycle with practical solutions.
  5. Continuously enhance the organization's security posture through technical improvements and process optimization.
  6. Assist in incident response and support vulnerability remediation efforts with technical expertise.
  7. Stay informed on emerging security threats and technologies, integrating improvements into the security strategy.
  8. Drive the adoption of shift-left security practices, ensuring security is considered early in development.
  9. Collaborate with DevOps and IT teams to integrate security into the CI/CD pipeline and drive security automation initiatives such as SAST, DAST, and IAST.
  10. Measure and improve security maturity using different frameworks like the DevSecOps Maturity Model.
  11. Ensure compliance with industry standards and regulations such as ISO 27001, GDPR, and PCI DSS.
  12. Promote security awareness across development teams and establish secure coding practices through continuous education.

Experience & Skills:

  1. Strong understanding of security principles and methodologies, with experience securing systems at scale.
  2. Proficiency in application security engineering, vulnerability assessments, and incident response.
  3. Expertise in web, mobile, and cloud security and familiarity with tools like OWASP and SANS frameworks.
  4. Mobile Application Testing, API Security Testing, Web Application Testing, Cloud Security (AWS, GCP, OpenStack etc)
  5. Strong problem-solving skills with the ability to address complex security issues.
  6. Excellent communication and collaboration skills, with experience working across development and operations teams.
  7. Expertise in ISO/IEC 27001, ISO 27017, ISO 27018, SOC 2, and PCI DSS is highly desirable.

More Info

Job Type:
Industry:
Employment Type:

Key Skills

SOC 2

ISO 27017

application security engineering

API Security Testing

ISO IEC 27001

SANS frameworks

ISO 27018

About Company

Similar Jobs

Bengaluru, India
Skills:
Tcp, Dns, Https, Tls, Code Review, Python, AWS, Java, Sql Injection, Sql, Jenkins, Linux, Owasp Top 10, Kubernetes, cross-site scripting, static analysis tools, penetration testing tools, REST architecture framework, non-SQL databases, code injection, cryptographic related weakness, Github actions, proxying, CI CD products, ArgoCD, CSRF
2-4 yrs
Bengaluru, India
Skills:
Ml, DAST, Java, Ceh, Sdlc, Cism, Python, Csslp, code-level security controls, CycloneDX, Ai, BSIMM, NIST SSDF, SCA, OWASP SAMM, SPDX, SAST, Cissp, secure software development practices
Bengaluru, India
Skills:
secure sdlc , Java, DAST, Cloud security, Vulnerability Assessment, Penetration Testing, Security Vulnerabilities, Burp Suite, Gcp, DevSecOps, Application Security, Authentication, Azure, Python, AWS, Automation scripts, Automating security testing processes, SCA, Authorization, OWASP ZAP, SAST
2-7 yrs
Bengaluru
Skills:
secure coding , Penetration Testing, DevSecOps, Cloud Security, Vulnerability Assessment, Incident Response, Security Auditing
2-4 yrs
Bengaluru, India
Skills:
threat modeling , Application Security, Vulnerability Assessments, Owasp Top 10, Penetration Testing, security policies and procedures, risk management, secure coding principles