Application Security Analyst (Hyderabad)

Application Security Analyst (Hyderabad)

29 Aug
|
Orcapod Consulting Services
|
Hyderabad

29 Aug

Orcapod Consulting Services

Hyderabad

Application Security Analyst

Location: Hyderabad (Hybrid)

Employment Type: C2H

We are looking for a skilled Application Security Analyst to support our Enterprise Vulnerability Management and Application Security (AppSec) program. The ideal candidate will be responsible for analyzing, validating, and triaging application security findings generated through automated security tools while working closely with development and security teams to improve remediation effectiveness and reduce false positives.

Key Responsibilities

Application Security Triage & Validation

- Perform first-level analysis of application security findings from security scanning tools.
- Validate findings by reviewing source code, application data flows, and security controls.

- Classify findings as

- True Positive

- False Positive

- Requires Additional Investigation
- Document findings, analysis, evidence, and recommendations.

Vulnerability Assessment & Management

- Analyze security findings from:
- Checkmarx (SAST, SCA, IaC)
- DAST tools such as WhiteHat or similar platforms
- Update and maintain vulnerability records in the vulnerability management platform.
- Ensure findings have accurate ownership, remediation notes, and metadata.

False Positive Reduction & Tool Optimization

- Identify recurring false positives and recommend tuning improvements.
- Assist in creating suppression rules and maintaining approved secure-pattern documentation.
- Improve overall scan quality and signal-to-noise ratio.





Developer Collaboration

- Provide actionable remediation guidance to development teams.
- Assist developers in understanding and resolving security findings.
- Promote secure coding practices and security awareness.

Reporting & Metrics

- Track vulnerability trends, remediation timelines, and false-positive rates.
- Support audit, compliance, and AppSec reporting activities.

Required Skills & Experience

Technical Skills

- Strong understanding of OWASP Top 10 and web application security concepts.
- Knowledge of vulnerability classes including:

- XSS

- SQL Injection
- Authentication & Authorization flaws

- SSRF

- Deserialization vulnerabilities
- Experience reviewing source code in one or more of:

- Java
- C#
- ASP.NET

- JavaScript

- TypeScript
- Experience with Checkmarx or other SAST/DAST tools.
- Familiarity with CI/CD pipelines and Git-based development workflows.

Security Knowledge

- Understanding of secure coding practices.
- Knowledge of CVE, CWE, and OWASP classifications.
- Ability to assess vulnerability exploitability beyond automated tool results.

Soft Skills

- Excellent written and verbal communication skills.
- Strong analytical and problem-solving abilities.
- Ability to work independently and collaborate with global teams.

We are looking for Immediate Joiners only. Interested candidates can apply through the job posting or share their updated resume at:

[email protected]

📌 Application Security Analyst (Hyderabad)
🏢 Orcapod Consulting Services
📍 Hyderabad

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: application security analyst (hyderabad) / hyderabad

Subscribe to this job alert:

Get the latest job offers by email for: application security analyst (hyderabad) / hyderabad