Application Security Analyst – DevSecOpsPosition Summary
We are seeking an experienced Application Security Analyst with a strong focus on DevSecOps and Secure Software Development Lifecycle (SSDLC) practices. This role serves as a trusted security advisor to software development teams, providing security guidance, training, and direction throughout the application development lifecycle.
The ideal candidate will have a strong background in application security, secure coding practices, threat modeling, and DevSecOps. They will work closely with developers, architects, DevOps engineers, and cloud teams to embed security into engineering processes, promote secure-by-design principles, and drive security maturity across the organization.
Key Responsibilities
- Serve as the primary application security advisor to development, DevOps, and engineering teams.
- Provide security guidance and consultation during application design, development, testing, and deployment phases.
- Conduct secure code reviews for Java applications and services.
- Review application architectures and perform threat modeling to identify potential security risks early in the SDLC.
- Establish and promote DevSecOps practices across development teams.
- Integrate security controls and automated security testing into CI/CD pipelines.
- Drive “Shift Left Security” initiatives and advocate secure-by-design development practices.
- Mentor developers on secure coding standards, OWASP Top 10, API Security, authentication, authorization, and cryptography.
- Develop and deliver secure coding training, workshops, and security awareness programs for software engineering teams.
- Support remediation efforts by helping development teams understand, prioritize, and resolve vulnerabilities.
- Analyze and validate findings from SAST, DAST, SCA,
penetration tests, and vulnerability assessments.
- Collaborate with DevOps and cloud engineering teams to secure containerized and cloud-native applications.
- Assist with security incident investigations involving application-layer vulnerabilities.
- Act as a Security Champion and help establish security best practices throughout the engineering organization.
Required Qualifications
- 5+ years of experience in Application Security, DevSecOps, Secure Software Development, or related security functions.
- Robust understanding of Secure SDLC, DevSecOps methodologies, and application security best practices.
- Experience providing security guidance, consulting, mentoring, and training to software development teams.
- Strong proficiency in Java, Spring Boot, REST APIs, and modern application architectures.
- Hands-on experience with secure code reviews and application threat modeling.
- Experience with OWASP Top 10, CWE, Secure Design Principles, and Application Security Testing methodologies.
- Hands-on experience with security tools such as Semgrep, Trivy, SonarQube, Snyk, Veracode, Checkmarx, or similar solutions.
- Experience integrating security controls into CI/CD pipelines using Azure DevOps, GitHub Actions, Jenkins, GitLab, JFrog, Jit.io, or similar platforms.
- Knowledge of secure authentication technologies including OAuth 2.0, OpenID Connect, SAML, MFA, and Identity Security concepts.
- Understanding of container security and cloud security principles in Azure, AWS, or GCP environments.
- Strong communication and stakeholder management skills with the ability to influence engineering teams and drive secure development practices.
Preferred Qualifications
- Experience leading DevSecOps or Application Security initiatives in an enterprise environment.
- Security certifications
📌 Application security Analyst (Java/DevSecops) (Mysuru)
🏢 Huzzl
📍 Mysuru