Senior AppSec Engineer Cloud, API & Software Supply Chain (Bengaluru)

Senior AppSec Engineer Cloud, API & Software Supply Chain (Bengaluru)

01 Aug
|
Important Group
|
Bengaluru

01 Aug

Important Group

Bengaluru

Role SummarynnWe are looking for a highly motivated Senior Application Security Engineer to join our Application Security team. This role will focus on securing modern cloud-native applications, with emphasis on API security, Infrastructure as Code (IaC), containerized workloads, and Open-Source Software (OSS) security.nnThe ideal candidate will work closely with engineering, platform, and product teams to embed security into the SDLC and enable secure-by-design development practices on a scale.nnKey ResponsibilitiesnnApplication u0026 API Securitynn * Establish and mature an API security program, including tools, processes, governance, standards, and best practicesn * Define secure API design guidelines aligned with OWASP API Top 10 and industry standardsn * Evaluate and integrate API security tools into the SDLC and CI/CD pipelinesn * Partner with engineering teams to embed secure-by-design API patternsn * Guide implementation of API authentication and authorization controls (OAuth2, OIDC, JWT, mTLS)nnnnInfrastructure as Code (IaC) Securitynn * Review and assess IaC templates (Terraform, ARM, CloudFormation, etc.) for security misconfigurationsn * Define and maintain secure IaC guardrails and policiesn * Integrate IaC security scanning into CI/CD pipelinesn * Partner with cloud and platform teams to remediate infrastructure risks early in the lifecyclennnnContainer u0026 Kubernetes Securitynn * Assess container images for vulnerabilities, misconfigurations, and insecure base imagesn * Review Kubernetes manifests, Helm charts, and deployment configurationsn * Advice on runtime security controls, least privilege, and workload isolationn * Support adoption of container security best practices across development teamsnnnnOpen-Source Software (OSS) Securitynn * Manage open-source risk including vulnerabilities, licensing, and supply-chain threatsn * Support and tune SCA (Software Composition Analysis)



toolsn * Drive remediation of vulnerable dependencies and guide teams on secure OSS usagen * Contribute to OSS security governance, policies, and exception handlingnnnnSecure SDLC u0026 Enablementnn * Embed security checks into CI/CD pipelines (SAST, DAST, SCA, IaC, container scans)n * Provide actionable remediation guidance to developersn * Create security documentation, standards, and secure coding guidelinesn * Deliver security awareness sessions and hands-on enablement for engineering teamsnnnnCollaboration u0026 Reportingnn * Partner with AppSec peers, PSIRT, Cloud Security, and Engineering stakeholdersn * Track findings, risk acceptance, and remediation progressn * Contribute to metrics and reporting for application security posturennnnRequired Qualificationsnn * 4u20137 years of experience in application security, product security, or secure software engineeringn * Strong understanding of web application and API security fundamentalsn * Hands-on experience with cloud-native environments (AWS, Azure, or GCP)n * Practical exposure to:n * API security testing and design reviewsn * IaC tools (Terraform, ARM, CloudFormation, etc.)n * Containers and Kubernetesn * Open-source dependency managementn * Familiarity with OWASP Top 10, OWASP API Top 10, CWE, CVSSn * Experience integrating security tools into CI/CD pipelinesn * Ability to clearly communicate security risks and solutions to engineering teamsnnnnPreferred / Nice-to-Have Skillsnn * Experience with AppSec tooling such as SAST, DAST, SCA, IaC scanning,



container security toolsn * Knowledge of Zero Trust and cloud security architecturesn * Experience with DevSecOps practicesn * Exposure to AI/ML security, including risks related to:n * AI-enabled applications and APIsn * Model and dependency supply chain risksn * Prompt injection, data leakage, and misuse scenariosn * Relevant certifications (e.g., CSSLP, GWAPT, CCSP, Kubernetes security certifications)n * Prior experience working with globally distributed engineering teamsnnnnBehavioral u0026 Leadership Expectations nn * Demonstrates independent execution within defined security domainsn * Proactively identifies security gaps and drives improvementsn * Robust collaboration and influencing skills without direct authorityn * Balances security risk with business and engineering prioritiesn * Shows ownership, accountability, and a continuous learning mindsetnnnnWhat Success Looks Like in This Rolenn * Improved security posture of APIs, cloud infrastructure, containers, and OSS usagen * Faster and more effective vulnerability remediation by engineering teamsn * Security embedded early and consistently across the SDLCn * Clear, scalable security standards adopted across product teamsnnnn## Qualificationsnn### Education:nnBacheloru0027s Degreenn### Skillsnn### Certifications:nn### Languages:nn### Years of Experience:nn2 - 4 Yearsnn### Work Experience:nn## Additional Informationnn### nn### Shift:nnDay (India)nn### nn### Travel:nnYes, 10% of the Timenn### nn### Relocation Eligible:nnYesnn### Referral Payment Plan:nnEmployee Referral (Standard)nnApplied Materials is an Equal Opportunity Employer committed to diversity in the workplace. All qualified applicants will receive consideration for employment without regard to race, color, national origin, citizenship, ancestry, religion, creed, sex, sexual orientation, gender identity, age, disability, veteran or military status, or any other basis prohibited by law. n

📌 Senior AppSec Engineer Cloud, API & Software Supply Chain (Bengaluru)
🏢 Important Group
📍 Bengaluru

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior appsec engineer cloud, api & software supply chain (bengaluru) / bengaluru

Subscribe to this job alert:

Get the latest job offers by email for: senior appsec engineer cloud, api & software supply chain (bengaluru) / bengaluru