Role Description Conduct application security testing in order to comply with corporate policies, and regulatory requirements. Coordinate and execute application security tests, communicate the results to relevant stakeholders, and help application developers understand how to fix code security issues.
Responsibilities: Conduct thorough application security penetration tests Work effectively with a cross-functional team to plan, execute, and communicate findings from application security testing Work with application owners to improve their knowledge and practical application of information security best practices, including but not limited to threat assessment, vulnerability prevention and secure coding practices. Partner with DevOps team to ensure application security tools such as SAST and DAST are performing well and generating accurate testing results. Flexibility to change direction and manage conflicting demands.
Experience: 10 -12 years progressive Information Technology experience or equivalent specialized skills with 5+ years of application security experience.
Experience in running & administrating static analysis (SAST), dynamic analysis (DAST), and Software Composition Analysis (SCA) tools and processes Experience in conducting and training application penetration testing Experience in Cloud Security.
Experience and strong understanding of DevSecOps processes, tools, and integrations.
Qualifications: Strong knowledge and ability to work with DevOps teams on the processes and integrations. Strong web application security knowledge with thorough understanding of web, mobile,
and API testing Knowledge of application security architecture and ability to perform threat modeling and risk assessments on identified applications. Knowledge of DevSecOps processes and ability to work with the stakeholders to deliver the results for security integrations in DevOps.
Development background in .Net, Java, and/or Python a plus Strong knowledge of Security Standards, frameworks and groups (OWASP, WASC, OSSTMM) Knowledge of the software development lifecycle under agile environment in a large enterprise Knowledge of database, application and Web server design Knowledge of current and emerging security technologies, threats and techniques for exploiting security vulnerabilities Knowledge of public cloud services Education: Bachelor's degree in Computer Science, Information Technology or equivalent Advanced degree preferred Certifications including GWAPT, GWEB, GPEN, OSCP, CSSLP, CASE, or similar preferred The priority is not tool-specific expertise but robust security fundamentals combined with hands-on execution: Application Security (SAST, DAST, SCA, secrets management) Threat Modelling Penetration Testing DevSecOps and Cloud Security Ability to leverage AI/LLMs and automation in security processes Strong coding and integration capabilities to build or automate workflows Strong Emphasis on Automation and AI Highlighted that the primary need is for engineers who can: Evaluate and implement security automation solutions.
Use AI tools and agents to improve: Threat modelling SAST analysis Penetration testing Security workflow automation
Skills Threat Modeling, SAST, DevSecOps, Cloud Security, Application Security, AWS Security, Workflow Automation, DAST, DevSecOps, Vulnerability Assessment and Penetration Testing, AI Security
📌 Specialist II - Information Security (Bengaluru)
🏢 UST
📍 Bengaluru