Role Overview
We are looking for an Application Security Engineer to help us build, test, and harden secure systems across our products and infrastructure. If you think like an attacker but build like a defender, this role is for you. This is a full-time, in-person position based in Pune.
Responsibilities
- Perform penetration testing and vulnerability assessments on web applications, APIs, and mobile platforms
- Conduct secure code reviews and work with developers to fix vulnerabilities early in the SDLC
- Define and enforce application security standards, hardening guidelines, and secure configuration baselines
- Carry out threat modeling for new features and major architectural changes
- Manage vulnerability disclosure, patching cycles, and risk remediation timelines
- Monitor for emerging threats, CVEs, and attack techniques
- Collaborate with DevOps/Cloud teams to secure CI/CD pipelines and cloud infrastructure
- Support incident response efforts when security issues are identified
- Document findings, risk ratings, and remediation guidance
Requirements
- Bachelor's degree in Computer Science, Information Technology, Cyber Security, or a related field
- 3–5 years of experience in Application Security, Ethical Hacking, or Penetration Testing
- Relevant certifications preferred: CEH, OSCP, or CompTIA Security+
- Solid understanding of OWASP Top 10, secure coding principles, and common application vulnerabilities
- Prior experience working closely with development teams in a Secure SDLC environment
Skills
OWASP Top 10PythonAWSPenetration TestingNice to Have
- Exposure to ISO 27001 or other compliance/governance frameworks
- Experience securing CI/CD pipelines or container environments (Docker/Kubernetes)
Benefits
- Flexible schedule
- Provident Fund