Senior Application Security Engineer
Bengaluru East, Karnataka, India · Full Time
Be the first to apply
- Experience
- 5+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 6 days ago
- Work mode
- In office
- Education
- Graduate
- Resume
- Required to apply
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Overview
Seeking a Senior Application Security Engineer with a minimum of 5 years' direct experience in application or product security roles. The ideal candidate has strong technical proficiency in reviewing and understanding codebases written in modern programming languages including Python, Go, Java, and JavaScript/TypeScript. This role demands detailed knowledge of typical web, API, and mobile vulnerabilities as outlined in the OWASP Top 10, along with practical experience using security testing tools such as Burp Suite, Semgrep, Frida, Jadx, and Ghidra.
Key Responsibilities
The individual will be involved in identifying and mitigating security risks across software products by leveraging expertise in static and dynamic analysis tools, secure coding principles, and cloud security across platforms like AWS, GCP, or Azure. Knowledge of authentication and authorization frameworks like JWT, OAuth, SAML, and OpenID Connect is essential. Familiarity with cryptography fundamentals and emerging AI/ML-related security threats—including testing for vulnerabilities in AI agents, chatbots, and large language model-based applications—is critical.
Required Qualifications
- Graduate degree with at least 5 years of hands-on experience in application or product security or related software security positions.
- Ability to analyze and reason about code securely in multiple programming languages such as Python, Go, Java, and JavaScript/TypeScript.
- Comprehensive understanding of common vulnerabilities per OWASP Top 10 for web, API, and mobile platforms with experience mitigating these.
- Proficient use of security tools including Burp Suite, Semgrep, Frida, Jadx, Ghidra, or related SAST/DAST/SCA technologies.
- Experience with cloud platform security concepts on AWS, GCP, or Azure.
- Knowledge of standardized authentication and authorization protocols: JWT, OAuth, SAML, OpenID Connect.
- Understanding of core cryptographic principles.
- Awareness of security risks related to AI/ML applications, including prompt injection and model misuse.
- Strong communication skills for conveying security issues clearly to both technical and non-technical stakeholders.
- Excellent analytical and pragmatic problem-solving abilities applying risk-based approaches.
Preferred Qualifications
- Expertise building security automation and integrating security tools within continuous integration and deployment (CI/CD) pipelines.
- Exposure to Large Language Model (LLM) security challenges such as OWASP Top 10 for LLMs, agent security, retrieval-augmented generation (RAG) pipeline attacks, and jailbreak techniques.
- Experience managing or contributing to bug bounty programs.
- Security certifications like OSCP, OSWE, eWPT, eWPTX, or GWAPT are advantageous.
- Demonstrated contributions to the security community, such as publishing blogs, delivering talks, developing open-source tools, or recognized vulnerabilities (CVEs).
Minimum education
Bachelor's Degree