06 Aug
|
ESDS Software Solutions
|
Mumbai
06 Aug
ESDS Software Solutions
Mumbai
L3 Product Security / Application Security Engineer (DevSecOps & SOC)
Location: Mumbai / Nashik (Onsite)
Experience: 58 Years
Are you passionate about building secure applications and integrating security into every stage of the software development lifecycle? We are looking for an experienced L3 Product Security / Application Security Engineer to join our Cyber Security team.
Key Responsibilities
- Design and implement Product Security and Application Security best practices.
- Perform Secure SDLC reviews, threat modeling, and secure architecture assessments.
- Conduct Application Security Assessments, Vulnerability Assessments, and Penetration Testing (VAPT).
- Integrate security controls into CI/CD pipelines as part of DevSecOps practices.
- Perform SAST, DAST, SCA, and code security reviews using industry-standard tools.
- Identify, prioritize, and drive remediation of security vulnerabilities.
- Collaborate with Development, DevOps, Infrastructure, Cloud, and SOC teams to improve security posture.
- Support security incident investigations related to applications and provide technical expertise to SOC teams.
- Develop and enhance security monitoring and detection use cases for application threats.
- Ensure compliance with secure coding standards and industry security frameworks.
Required Skills
- Product Security
- Application Security (AppSec)
- DevSecOps
- Secure SDLC
- Threat Modeling
- Secure Code Review
- SAST / DAST / SCA
- Vulnerability Assessment & Penetration Testing (VAPT)
- API Security
- OWASP Top 10 / OWASP ASVS
- CI/CD Security
- Docker & Kubernetes Security
- Cloud Security (Azure/AWS)
- Networking Fundamentals (TCP/IP, HTTP/HTTPS, DNS, SSL/TLS)
SOC Knowledge (Preferred)
Candidates should have exposure to or experience with:
- Security Operations Center (SOC)
- SIEM (Microsoft Sentinel, Splunk, IBM QRadar)
- Incident Response
- Threat Hunting
- EDR/XDR (Microsoft Defender XDR, CrowdStrike, SentinelOne)
- MITRE ATT&CK; Framework
- Log Analysis & Security Monitoring
Security Tools
Experience with one or more of the following:
- Burp Suite
- OWASP ZAP
- Checkmarx
- Veracode
- Fortify
- SonarQube
- Snyk
- Nessus
- Qualys
- Rapid7
- Nmap
- Metasploit
Preferred Certifications
- CISSP
- CSSLP
- OSCP / OSWE
- CEH
- CompTIA Security+
- Microsoft SC-200 / SC-100
- AWS Security Specialty
- Azure Security Engineer Associate
What We're Looking For
5–8 years of experience in Product Security, Application Security, or DevSecOps.
Robust understanding of secure coding practices and application security testing.
Hands-on experience with vulnerability management and penetration testing.
Ability to collaborate with SOC teams on security monitoring and incident response.
Excellent analytical, problem-solving, and communication skills.
📌 Product Security / Application Security Engineer (DevSecOps) (Mumbai)
🏢 ESDS Software Solutions
📍 Mumbai