Verified today
Senior Application Security Engineer
About the role
Security Team at Jumio builds and protects the cloud infrastructure and application ecosystem supporting its identity verification platform. The Senior Application Security Engineer leads threat modeling, manual penetration testing, code reviews, and DevSecOps automation to embed security throughout the SDLC and cloud services. Bangalore, on-site role focusing on secure IaC, container security, and scaling security tooling across engineering teams.
What you’ll do
- Collaborate with engineering to identify and remediate security gaps
- Integrate security into SDLC from threat modeling to decommissioning
- Perform manual penetration testing and code reviews
- Deploy security services via IaC and promote security-as-code culture
- Conduct periodic cloud security assessments and configuration reviews
- Build custom security tooling and automation
- Scale DevSecOps practices across the organization
- Manage cross-functional security communications
What you’ll bring
- 10+ years application and cloud security engineering
- Strong Linux and AWS/GCP experience
- Penetration testing of web, mobile, and APIs
- Deep knowledge of OWASP Top 10 and CWE 25
- Experience with SAST/DAST/IAST/SCA tools
- Secure Infrastructure as Code (IaC) implementation
- Container security with Docker and Kubernetes
- Relevant security certifications (e.g., OSCP, AWS Security)
Skills
Education
Bachelor's degree in Computer Science or related field