02 Aug
|
Alignity Solutions
|
India
02 Aug
Alignity Solutions
India
Job Description
Do you love a career where you Experience, Grow & Contribute at the same time, while earning at least 10% above the market? If so, we are excited to have bumped onto you.
Learn how we are redefining the meaning of work, and be a part of the team raved by Clients, Job-seekers and Employees.
- Jobseeker Video Testimonials
- Employee Glassdoor Reviews
If you are a Application Security Engineer looking for excitement, challenge and stability in your work, then you would be glad to come across this page.
We are an IT Solutions Integrator/Consulting Firm helping our clients hire the right professional for an exciting long-term project. Here are a few details.
Check if you are up for maximizing your earning/growth potential, leveraging our Disruptive Talent Solution.
Role: Application Security Engineer
Experience: 5-8Years
Location: Hyderabad | Bengaluru | Pune | ChennaiWork Mode:Hybrid
Type:Contract to Hire
Notice Period: 0-30 days
Requirements
Role Summary
We are looking for an Application Security Engineer to support Static and Dynamic Application Security Testing (SAST/DAST) scan and triage activities, while also providing hands-on outage support for the security tooling ecosystem — including App Scan, Checkmarx, Cycode, and GCP Model Armor. This role combines day-to-day vulnerability triage and remediation guidance with structured, SOP-driven incident response when scanning tools are degraded or unavailable, including support during scheduled patching windows and off-business-hours coverage.
Key Responsibilities
SAST & DAST Testing and Triage
• Perform and support Static (SAST) and Dynamic (DAST) application security testing across in-scope applications.
• Triage scan findings across SAST, DAST, SaaS, Secrets, and API security scan results, distinguishing false positives from confirmed vulnerabilities.
• Provide developers with clear, actionable remediation guidance for validated vulnerabilities.
• Support application onboarding into scan tooling and manage Penalty-Box exception handling and unblock decisions.
• Provide security support during production release ACAB reviews and Breakglass approvals.
• Create, validate, and drive Vulnerability Information Tracker (VIT) and defect records through to closure.
App Scan & Checkmarx Windows Server Patching Outage Support
• Provide support during scheduled monthly Windows Server patching windows to ensure App Scan and Checkmarx remain available and operational after server restarts.
• Validate application access for App Scan and Checkmarx following patching.
• Use RDP to connect to in-scope management servers for troubleshooting.
• Check IIS Manager to confirm required application pools are in Started status; verify all required HCL App Scan and Cx services are in Running status.
• Start any stopped services or application pools; reboot the App Scan management server when required for database-related errors.
• Revalidate application login pages after restart and escalate unresolved issues via email or Microsoft Teams.
Cycode Tool Outage Support
• Support Cycode-related issues, primarily stuck or delayed pull requests during the secret-scanning process.
• Review incident details and validate pull request scan history in Cycode; check for missing or delayed pull requests.
• Coordinate with the E3 team to verify Azure Dev Ops webhooks and recent ADO changes, and confirm branch policy settings.
• Validate whether an actual secret is blocking the pull request and raise a vendor support ticket with Cycode when required.
• Coordinate unresolved issues with the appropriate internal teams and Cycode Support until resolution.
GCP Model Armor Support
• Provide off-business-hours support for managing Google Cloud Model Armor configurations.
• Enable or disable Model Armor for required projects and switch configurations between Inspect Only mode and Inspect and Block mode.
• Update the necessary Terraform configuration, create pull requests, coordinate approvals, and trigger pipeline deployments.
• Approve Terraform runs in accordance with the SOP, coordinating with reviewers and approvers as needed.
Required Skills & Experience
• Hands-on experience with SAST and DAST tools and processes (e.g., Checkmarx, HCL App Scan, or equivalent), including scan triage and false-positive analysis.
• Basic Windows Server support knowledge, with experience using RDP for remote troubleshooting.
• Working knowledge of IIS Manager and Windows Services, including starting/stopping services and application pools.
• Basic knowledge of Cycode or similar secret-scanning tools, Azure Dev Ops, pull request workflows, webhooks/service hooks, and branch policies.
• Basic knowledge of Google Cloud Platform (GCP), Terraform,
Git repositories, pull request processes, pipeline deployments, and HCP Terraform workspace approvals.
• Experience with incident handling, vendor coordination, and SOP-based outage support procedures.
• Strong written and verbal communication skills, including the ability to escalate and coordinate via email and Microsoft Teams.
• Willingness to support scheduled patching windows and off-business-hours / on-call activities as needed.
Preferred Qualifications
• Prior experience in an Application Security Testing (AST), Dev SecOps, or security operations support role.
• Familiarity with vulnerability management workflows (VIT/defect lifecycle: creation, validation, closure).
• Exposure to CI/CD pipelines and infrastructure-as-code approval workflows.
• Relevant certifications (e.g., Security+, GCP Associate/Professional, or vendor-specific tool certifications) are a plus.
Soft Skills
• Strong attention to detail when following SOP-based procedures under time pressure.
• Clear, calm communication during live outage or incident scenarios.
• Ability to work independently during off-hours support windows while knowing when to escalate.
Team-oriented mindset for coordinating across internal teams (E3, Dev Ops, application teams) and external
BenefitsVisit us at http://alignity.io/careers. Alignity Solutions is an Equal Opportunity Employer, M/F/V/D.
CEO Message: Click Here
Clients Testimonial: Click Here
Requirements
Required Skills & Experience • Hands-on experience with SAST and DAST tools and processes (e.g., Checkmarx, HCL App Scan, or equivalent), including scan triage and false-positive analysis. • Basic Windows Server support knowledge, with experience using RDP for remote troubleshooting. • Working knowledge of IIS Manager and Windows Services, including starting/stopping services and application pools. • Basic knowledge of Cycode or similar secret-scanning tools, Azure Dev Ops, pull request workflows, webhooks/service hooks, and branch policies. • Basic knowledge of Google Cloud Platform (GCP), Terraform, Git repositories, pull request processes, pipeline deployments, and HCP Terraform workspace approvals. • Experience with incident handling, vendor coordination, and SOP-based outage support procedures. • Strong written and verbal communication skills, including the ability to escalate and coordinate via email and Microsoft Teams. • Willingness to support scheduled patching windows and off-business-hours / on-call activities as needed.
📌 Application Security Engineer – SAST/DAST & Security Tooling Outage Support (India)
🏢 Alignity Solutions
📍 India