Application Security Engineer

6 - 11 years

15 - 30 Lacs

Posted:3 days ago| Platform: Naukri logo

Apply

Work Mode

Work from Office

Job Type

Full Time

Job Description

Application Security Engineer

Key Responsibilities:

  • Conduct penetration testing on applications and supporting infrastructure to identify and remediate security vulnerabilities.
  • Perform security code reviews and provide guidance on secure coding practices to development teams.
  • Collaborate in threat modeling, attack surface analysis, and design reviews during the SDLC.
  • Integrate security tools and practices (e.g., SAST, DAST) into CI/CD pipelines.
  • Lead the implementation of security controls across containerized environments, especially within

    Kubernetes

    .
  • Evaluate and improve the security posture of applications running in on-premise, cloud, and hybrid environments.
  • Develop and maintain security automation scripts and tools for continuous testing and compliance.
  • Provide technical expertise in application, network, database, and cloud security architecture.
  • Support incident response efforts related to application-level security breaches.
  • Stay updated with the latest vulnerabilities, threats, and technologies in the application security space.

Required Skills and Experience:

  • Proven experience in

    application and infrastructure penetration testing

    .
  • Strong knowledge of

    application security principles

    and modern

    software development practices

    .
  • Experience with

    DevSecOps

    , including integrating security into

    CI/CD

    workflows.
  • Proficiency in secure coding and ability to review source code in languages like Java, Python, JavaScript, or Go.
  • Hands-on experience with

    SAST

    and

    DAST

    tools (e.g., Fortify, SonarQube, Veracode, Burp Suite, OWASP ZAP).
  • Deep understanding of security mechanisms in

    Applications

    ,

    Operating Systems

    ,

    Networks

    ,

    Databases

    ,

    Virtualization

    , and

    Cloud

    platforms (e.g., AWS, Azure, GCP).
  • Working knowledge of securing

    Kubernetes

    clusters and containerized applications.
  • Familiarity with

    network security architecture

    , firewalls, and threat modeling techniques.
  • Strong understanding of security standards and frameworks (e.g., OWASP Top 10, NIST, ISO 27001, CIS Benchmarks).

Preferred Qualifications:

  • Certifications such as OSCP, GWAPT, CEH, CISSP, or CSSLP.
  • Experience with Infrastructure as Code (IaC) security and tools like Terraform or CloudFormation.
  • Background in development or system administration is a plus.

Mock Interview

Practice Video Interview with JobPe AI

Start Job-Specific Interview
cta

Start Your Job Search Today

Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.

Job Application AI Bot

Job Application AI Bot

Apply to 20+ Portals in one click

Download Now

Download the Mobile App

Instantly access job listings, apply easily, and track applications.

coding practice

Enhance Your Skills

Practice coding challenges to boost your skills

Start Practicing Now

RecommendedJobs for You