04 Oct
|
Cloudxtreme
|
Hyderabad
04 Oct
Cloudxtreme
Hyderabad
Role & responsibilities
Strong Application Security expertise with hands-on SAST-driven secure code review and manual validation of vulnerabilities, aligned with OWASP Top 10 (e.g., using tools such as Snyk or Checkmarx).
Preferred candidate profile
Security Assessment Code Review - Perform application security assessments across backend frontend and API environments - Conduct secure code reviews using SAST tools Snyk Checkmarx and manual analysis to validate findings and distinguish true positives from false positives - Identify vulnerabilities aligned with OWASP Top 10 and API Top 10 - Provide clear actionable remediation guidance to developers Remediation Tracking Developer Support - Work with development teams to implement fixes and track remediation efforts - Create vulnerability assessments remediation guidance and knowledge base articles - Support development teams in effectively using application security testing tools - Maintain operation manuals and documentation Tool Management Governance - Support enforcement of SAST policies and compliance with security requirements - Manage and optimise SAST tools maintain tool hygiene and data quality - Track and report on vulnerability metrics remediation status and security trends Tool Management Governance - Work with development teams to implement fixes and track remediation efforts - Create vulnerability assessments remediation guidance and knowledge base articles - Support development teams in effectively using application security testing tools - Maintain operation manuals and documentation Tool Management Governance - Support enforcement of SAST policies and compliance with security requirements - Manage and optimise SAST tools maintain tool hygiene and data quality - Track and report on vulnerability metrics remediation status and security trends Security Program Evolution - Contribute to secure SDLC practices and internal security standards - Research emerging threats in web API and modern application architectures - Partner with developers DevOps and security teams to embed secure design and secure coding practices into the SDLC - Proactively identify gaps in tool coverage and security processes Technologies in Scope The Application Security Consultant will perform security assessments across a full stack technology workplace including - Backend Core Languages Python Java C C NET Go Ruby PHP nodejs - Frontend Languages Libraries JavaScript React Angular Vuejs The role also requires the ability to research and assess security risks in legacy unsupported or less common technologies encountered in different environments Technologies in Scope The Application Security Consultant will perform security assessments across a fullstack technology environment including - Backend Core Languages Python Java C C NET Go Ruby PHP nodejs - Frontend Languages Libraries JavaScript React Angular Vuejs The role also requires the ability to research and assess security risks in legacy unsupported or less common technologies encountered in different environments - 3 5 years of experience in Application Security Security Assessments or Software Development with a security focus - Strong understanding of common vulnerability classes eg injection broken authentication access control cryptographic issues - Ability to script or program to validate findings automate tasks or create small security tools - Hands on experience with at least one SAST tool eg Snyk Checkmarx Fortify Semgrep - Experience reviewing code in at least two modern programming languages - Understanding of CI CD DevOps and DevSecOps approaches and experience working with DevOps tools - Strong analytical and problem solving skills
Certifications Required
Nice to Have - Experience supporting SCA/DAST tools, especially in a role responsible for triaging findings and refining scanning rules. - Experience reviewing APIs and microservices architectures
📌 Application Security Engineer (Hyderabad)
🏢 Cloudxtreme
📍 Hyderabad