Job Description: Application Security Engineer (4–5 Years Experience)
Location: PuneDepartment: Information SecurityExperience: 4–5 YearsCompany: Bajaj Auto Credit Ltd.
Role Overview
We are seeking a skilled and proactive Application Security Engineer to strengthen the security posture of our applications and digital platforms. The candidate will be responsible for integrating security throughout the Software Development Life Cycle (SDLC), conducting application security assessments, managing vulnerability remediation, and collaborating with development, DevOps, cloud, and infrastructure teams.
The ideal candidate should have hands-on experience in secure code reviews, application security testing, DevSecOps implementation, and BFSI/NBFC regulatory requirements.
Perform Secure Code Reviews (SAST) for web, mobile, APIs, and backend applications.
Conduct Energetic Application Security Testing (DAST), API Security Testing, and vulnerability assessments.
Review application architecture and design from a security perspective.
Validate security controls during application development and deployment.
Perform threat modelling and identify security risks in application designs.
DevSecOps & Secure SDLC
Integrate security controls into CI/CD pipelines.
Implement and manage DevSecOps tools for automated security testing.
Establish security gates for application releases.
Drive Secure SDLC practices across development teams.
Develop security standards, coding guidelines, and best practices.
Vulnerability Management
Identify, prioritize, and track remediation of application vulnerabilities.
Validate fixes and perform retesting activities.
Manage risk acceptance and exception processes.
Monitor vulnerability trends and report metrics to management.
Cloud & API Security
Assess cloud-native applications deployed on AWS, Azure, or GCP.
Review API security controls and conduct API penetration testing.
Validate authentication,