Application Security Engineer

Remote
Apply
AI Summary

Secure applications across the SDLC and embed DevSecOps practices into engineering workflows. Perform manual and automated security testing, conduct secure code reviews, and implement security tools. Collaborate with engineering, QA, and Dev teams to drive developer security training and promote a security-first culture.

Key Highlights
Secure applications across the SDLC
Embed DevSecOps practices into engineering workflows
Collaborate with engineering, QA, and Dev teams
Key Responsibilities
Perform manual and automated security testing
Embed security into SDLC through DevSecOps practices
Conduct secure code reviews, threat modeling, and risk assessments
Implement and manage SAST, DAST, SCA, IAST tools
Integrate application security tools into CI/CD pipelines
Monitor, triage, and remediate application-layer vulnerabilities
Lead application security incident response
Partner with engineering, QA, and Dev teams to validate fixes
Drive developer security training and promote a security-first culture
Technical Skills Required
JavaScript Python REST APIs OWASP Top 10 SANS Top 25 CWE CVE AWS Azure GCP SAST DAST SCA IAST CI/CD pipelines
Benefits & Perks
100% remote work
Long-term contract
40 hours/week work schedule
Nice to Have
OSCP
CSSLP
GWAPT
CEHCI/CD
container security
SOC 2
ISO 27001
PCI DSS

Job Description


Role: Application Security Engineer

Position Type: Full-Time Contract (40hrs/week)

Contract Duration: Long Term

Work Schedule: 8 hours/day (Mon-Fri)

Work Hours: IST

Location: 100% Remote


We’re seeking a proactive Application Security Engineer to secure applications across the SDLC and embed DevSecOps practices into engineering workflows. This role is ideal for someone with a strong software development background who has moved into Application Security.


Key Responsibilities:

  • Perform manual and automated security testing (web, mobile, cloud apps)
  • Embed security into SDLC through DevSecOps practices
  • Conduct secure code reviews, threat modeling, and risk assessments
  • Implement and manage SAST, DAST, SCA, IAST tools
  • Integrate application security tools into CI/CD pipelines
  • Monitor, triage, and remediate application-layer vulnerabilities
  • Lead application security incident response
  • Partner with engineering, QA, and Dev teams to validate fixes
  • Drive developer security training and promote a security-first culture


Requirements:

  • 4–10 years of experience (minimum 3+ years in Application Security)
  • Strong software development background
  • Experience with web technologies (JavaScript, Python, REST APIs, etc.)
  • Knowledge of OWASP Top 10, SANS Top 25, CWE, CVE
  • Experience securing applications in AWS, Azure, or GCP
  • Strong collaboration and communication skills


Nice to Have:

  • Certifications: OSCP, CSSLP, GWAPT, CEH
  • CI/CD and container security
  • Familiarity with SOC 2, ISO 27001, PCI DSS


Similar Jobs

Explore other opportunities that match your interests

Visa Sponsorship Relocation Remote
Job Type Contract
Experience Level Mid-Senior level

aptonet

India

Senior Detection Engineer

Cyber Security
1d ago
Visa Sponsorship Relocation Remote
Job Type Contract
Experience Level Mid-Senior level

sapphire software solutions in...

India

Senior Security Engineer

Cyber Security
4d ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

GoDaddy

India

Subscribe our newsletter

New Things Will Always Update Regularly