Application Security Architect (Hyderabad)

Application Security Architect (Hyderabad)

03 Oct
|
Orcapod Consulting Services
|
Hyderabad

03 Oct

Orcapod Consulting Services

Hyderabad

Job Title: Application Security Architect
Experience: 12+ Years
Location: Hyderabad (Hybrid)

Company Overview

Ensemble Health Partners India is at the forefront of innovation in the Revenue Cycle Management (RCM) space, leveraging modern technology to drive meaningful, realworld impact. Our futureready platforms bring together AIdriven analytics, intelligent data ingestion, workflow automation, and business intelligence built on a scalable, cloudnative architecture.

Our AIpowered solutions are actively running in production, continuously optimizing processes and delivering datadriven insights at scale. With the secondlargest market share in the U.S. RCM industry, a global workforce of 15,000+ professionals, and 12 technology patents, we deliver results through strong teams, proven processes, and flexible, modern technologies.

As part of our continued growth, we have launched our Global Capability Center (GCC) in Hyderabad designed to serve as a strategic extension of our global operations. The GCC brings together technology, analytics, and RCM expertise to build scalable solutions, accelerate innovation, and support our longterm vision of transforming healthcare operations.

At Ensemble Health Partners India, we foster a culture of growth, collaboration, and innovation where your expertise is valued, your ideas are heard, and your work makes a measurable impact.

Position Summary:

We are looking for a hands-on **Application Security Architect** who combines strong software engineering skills with deep application security expertise. This is a generalist role you should be comfortable reading and writing production-quality code across multiple languages, and equally comfortable designing and running an AppSec program that spans SAST, DAST, and SCA tooling, secure architecture reviews, and developer enablementThis position will require occasional after-hours and weekend work. The selected candidate will be expected to attend work on a regular and predictable schedule in accordance with agency leave policy and perform other duties as assigned.

Roles & Responsibilities

- Design and drive the application security strategy across the SDLC — from design reviews through CI/CD to production.

- Own and continuously tune **SAST** (e.g.,



Checkmarx, Fortify, Semgrep, CodeQL), **DAST** (e.g., Burp Suite Enterprise, OWASP ZAP, Invicti), and **SCA** (e.g., Snyk, Black Duck, Mend, Dependency-Track) tooling — integration, rule tuning, false-positive reduction, and coverage.

- Perform secure architecture and design reviews for new features, services, and major system changes.

- Read, write, and refactor code (not just review it) to build internal tooling, PoCs for vulnerabilities, custom scanners, and secure-by-default libraries/frameworks.

- Conduct manual code reviews and threat modeling for high-risk services, complementing automated tooling.

- Partner with engineering teams to remediate vulnerabilities, and act as a technical escalation point for security findings.

- Build and maintain CI/CD security gates (pre-commit hooks, pipeline scanning, break-the-build policies).

- Define and evangelize secure coding standards, guardrails, and reusable security patterns/libraries.

- Run or support penetration tests and coordinate remediation with engineering.

- Mentor developers and security champions; deliver secure coding training.

- Track and report AppSec metrics (vulnerability density, MTTR, tool coverage, false-positive rates) to leadership.

- Stay current on emerging threats (OWASP Top 10, CWE/SANS Top 25, supply chain attacks) and evolve the program accordingly.

Required Skills

**Engineering foundation (must-have — this is a generalist coding role, not a pure GRC/tooling role): **

- Strong hands-on software development experience in at least one backend language (e.g., Java, Python, Go, Node.js, C#) and working familiarity with others.

- Comfortable reading and writing code across the stack — APIs, web front ends, mobile, or infrastructure-as-code, as relevant to your environment.

- Solid understanding of software design patterns, frameworks,



and modern CI/CD pipelines.

**Application security expertise: **

- Deep, practical experience with **SAST**, **DAST**, and **SCA** tools — selection, deployment, tuning, and interpreting results (not just running scans).

- Strong grasp of OWASP Top 10, OWASP ASVS, CWE/SANS Top 25, and secure design principles (authN/authZ, cryptography, input validation, session management).

- Experience with threat modeling methodologies (STRIDE, PASTA, or similar).

- Familiarity with container/cloud security (Docker, Kubernetes, AWS/Azure/GCP security services) is a plus.

- Understanding of software supply chain security (SBOM, dependency risk, artifact signing).

- Experience building custom security tooling or writing SAST/DAST rules.

- Exposure to regulated industries (BFSI, healthcare) or compliance frameworks (PCI-DSS, ISO 27001, SOC 2).

Why Join US?

- Work on real-world healthcare and technology challenges, powered by emerging technologies and a strong innovation mindset.
- Be part of a fast-growing, people-first organization where your work creates measurable impact.
- Grow continuously with structured learning, certifications, and industry-recognized development programs.
- Collaborate with highcaliber teams that value ownership, trust, and accountability.
- Grow alongside an organization that’s scaling with purpose and clarity. Be part of a fastscaling Global Capability Center with meaningful global responsibility.

Advantages:

- Comprehensive health insurance coverage for associate, kids (2) and parents supporting physical and financial wellbeing beyond the workplace.
- Accidental insurance coverage for the associate that adds an extra layer of security.
- Professional development programs with reimbursement support to help you upskill and grow with confidence.
- A workplace that is fully compliant with labor laws, including maternity and paternity benefits.
- Thoughtful experiences like welcome kits, company swag, and workanniversary gifts that recognize your journey with us.
- Benefits designed to support you at different stages of life and career, not just on day one.

(phone hidden) [email protected]

📌 Application Security Architect (Hyderabad)
🏢 Orcapod Consulting Services
📍 Hyderabad

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: application security architect (hyderabad) / hyderabad

Subscribe to this job alert:

Get the latest job offers by email for: application security architect (hyderabad) / hyderabad