Senior Security Engineer
Thiruvananthapuram, Kerala, India · Full Time
Be the first to apply
- Experience
- 5+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 1 day ago
- Work mode
- In office
- Education
- Bachelor's degree in Computer Science, Cybersecurity, or a related field
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Role Overview
The Senior Application Security Engineer is tasked with safeguarding the security aspects of organizational products throughout their development lifecycle. This position collaborates with related security professionals and various business divisions to provide security advice, education, and input.
Key Responsibilities
- Conducting risk assessments including threat modeling, vulnerability analysis, and evaluating security gaps in product design and development.
- Driving secure development practices by implementing security tools and automation to enhance the Application Security team's workflows. Promoting and integrating security standards within the Software Development Lifecycle (SDLC) through code reviews, penetration testing, and static/dynamic analyses.
- Collaborating with product and engineering teams to architect and embed security controls directly into product development processes, integrating security tools such as SAST/DAST, software composition analysis, and infrastructure-as-code scanning into continuous integration and deployment pipelines.
- Engaging in product planning alongside key stakeholders, fostering cross-functional teamwork to develop risk mitigation strategies, mentoring teams on security best practices, and conducting security training and awareness programs.
- Maintaining comprehensive documentation of security measures, preparing detailed reports concerning security risks and mitigation activities for management and regulatory purposes, and auditing source code for critical application modifications.
Candidate Profile
- Minimum of five years experience in application security roles.
- Bachelor’s degree in Computer Science, Cybersecurity, or related fields.
- Proven leadership in driving architectural or cross-team initiatives to address security vulnerabilities.
- Deep understanding of threat modeling techniques like MITRE ATT&CK, STRIDE, and PASTA.
- Proficiency with cloud platforms AWS and Microsoft Azure and their security capabilities.
- Expertise in securing web applications and familiarity with orchestration tools such as Ansible and Terraform.
- Experienced with OWASP Top 10, static and dynamic application security testing tools, and integration within CI/CD pipelines.
- Programming fluency in Python, React, and Django Rest Framework.
- Strong experience in manual source code reviews and embedding security practices within production environment codebases.
- Successful deployment of application security tools in continuous integration and deployment workflows.
- Knowledge of securing the software development lifecycle by establishing programs that mitigate entire categories of vulnerabilities.
- Excellent communication and interpersonal skills, with ability to work independently and collaboratively.
- Strong organizational talents and capability to manage time effectively.
Additional Preferred Qualifications
- Certifications such as CISSP, CSSLP, CEH, or equivalents.
- Experience working with IoT, embedded systems, or mobile application security.
- Awareness of regulatory and compliance standards including AICPA SOC2, NIST CSF, GDPR, and HIPAA.
Equal Opportunity Employer Statement
H&R Block values diversity and is committed to providing equal employment opportunities free from discrimination on grounds such as race, color, religion, gender identity or expression, sexual orientation, citizenship, disability, or any other protected status under applicable laws.