Back to jobs
W
Hiring companyWaters

Verified today

Application Security Specialist Engineer

Bangalore, India Full-time On-site

About the role

Application Security Engineer responsible for vulnerability operations, tooling ownership, and automation across global portfolio. Leads triage, remediation, inventory, metrics, and dashboards. Drives security maturity with CI/CD integration and cloud platforms.

What you’ll do

  • Triage, validate, prioritize vulnerabilities SAST, SCA, DAST, IaC, secrets, container.
  • Administer, tune, maintain security tooling ecosystems, ensuring CI/CD integration.
  • Create, track, manage remediation tickets with engineering teams, enforcing SLAs.
  • Maintain inventories, classify by criticality, exposure, sensitivity.
  • Contextualize vulnerabilities with impact, exploitability, controls, asset risk.
  • Develop dashboards for vulnerability posture, aging, SLA compliance, reporting.
  • Conduct trend analysis to identify recurring vulnerabilities, improvements.
  • Build automation scripts to streamline triage, ticketing, enrichment, reporting.

What you’ll bring

  • Bachelor's in CS, Cybersecurity, or equivalent.
  • 3–5+ years in Application, Product, or Vulnerability Security.
  • Hands‑on SAST, SCA, DAST, IaC, container, or secrets scanning.
  • Strong CVSS, exploitability, and vulnerability class knowledge.
  • Python scripting (Go/JS acceptable) and CI/CD integration.
  • Cloud platforms (AWS, Azure, GCP) and modern app architecture.
  • Analytical, investigative, problem‑solving, high attention to detail.
  • Collaborative in fast‑paced global engineering environment.

Nice to have

  • Large‑scale, multi‑business‑unit vulnerability program experience.
  • Kubernetes, container security, cloud‑native scanning expertise.
  • Dashboard building with PowerBI, Tableau, Grafana, or Looker.
  • Knowledge of NIST CSF, ISO 27001, SOC 2, EO 14028.
  • Software composition analysis, supply chain security, SBOM familiarity.
  • Security automation via APIs, webhooks, serverless, workflow engines.
  • Security certifications: GWAPT, GXPN, GCSA, CSSLP, OSCP, or equivalent.

Skills

SASTSCADASTIaCSecrets ScanningContainer SecurityPythonGoJavaScriptCI/CDAWSAzureGCPKubernetesPowerBITableauGrafanaLookerNIST CSFISO 27001SOC 2EO 14028SBOMSecurity AutomationAPIsWebhooksServerlessWorkflow Engines

Education

Bachelor's