Talent.com
Application Security Engineer
Application Security EngineerFoodsmart • Bengaluru, Republic Of India, IN
Application Security Engineer

Application Security Engineer

Foodsmart • Bengaluru, Republic Of India, IN
30+ days ago
Job description

About us :

Foodsmart is the leading telenutrition and foodcare solution, backed by a robust network of Registered Dietitians. Our platform is designed to foster healthier food choices, drive lasting behavior change, and deliver long-term health outcomes. Through our highly personalized, digital platform, we guide our 2.2 million members—including those in employer-sponsored health plans, regional and national Medicaid managed care organizations, Medicare Advantage plans, and commercial insurers—on a tailored journey to eating well while saving time and money.

Foodsmart seamlessly integrates dietary assessments and nutrition counseling with online food ordering and cost-effective meal planning for the entire family, optimizing ingredients both at home and on the go. We partner with national and regional retailers across the U.S., many of whom accept SNAP / EBT, making healthier food more accessible. Additionally, we assist members with SNAP enrollment and management, providing tangible access to nutritious food.In 2024, Foodsmart secured a $200 million investment from TPG’s Rise Fund, which supports entrepreneurs dedicated to achieving the United Nations’ Sustainable Development Goals. This investment will help us expand our reach, particularly to low-income workers who are disproportionately affected by diet-related diseases.

At Foodsmart, our mission is to make nutritious food accessible and affordable for everyone, regardless of economic status. We are committed to a set of core values that shape our culture and work environment :

⚖️ Measured : We make data-driven, truth-seeking decisions.

💥 Impactful : We are fueled by achieving our mission and vision.

🙏 Collaborative : We help each other be better and create a positive environment.

📈 Hungry : We maintain a healthy growth mindset, seeking to overcome challenges with courage.

😊 Joyful : We take joy in each other, our work, and the privilege of doing this work.

Whether you're a dietitian, a commercial leader, or a technologist, working at Foodsmart means being part of a team that is passionate, supportive, and driven by a shared purpose. Join us in transforming the way people access and enjoy healthy food.

About the role :

We are seeking an Application Security Engineer who will work at the intersection of security, DevOps, and development to ensure security is embedded throughout our SDLC. This role requires deep technical expertise in secure code review, static and dynamic application security testing (SAST / DAST), and infrastructure governance, especially in the segregation of environments, separation of duties, and branch protection in source control systems.

You will :

Code & Application Security

  • Conduct manual and automated code reviews to identify security vulnerabilities (e.G., XSS, SQLi, logic flaws).
  • Define and implement SAST and DAST pipelines using tools such as SNYK, Checkmarx, Fortify, OWASP ZAP, or Burp Suite.
  • Collaborate with development teams to remediate vulnerabilities and educate on secure coding standards (e.G., OWASP Top 10).

DevSecOps & CI / CD Pipeline Security

  • Integrate security controls into CI / CD pipelines using tools like GitHub Actions, Jenkins, and GitLab CI.
  • Define and enforce branch protection rules, code signing, and commit validation policies (e.G., mandatory code reviews, signed commits).
  • Work closely with DevOps to ensure security-as-code is implemented across build, test, and deployment stages.
  • Infrastructure & Environment Segregation

  • Ensure proper segregation between development, staging, and production environments, following least privilege principles.
  • Collaborate with infra and cloud teams to enforce network and access segregation (e.G., VPC segmentation, IAM policies).
  • Governance & Policy Enforcement

  • Define and monitor separation of duties policies between developers, testers, and deployers.
  • Create security baselines and compliance checks (e.G., CIS Benchmarks, SOC 2 / ISO 27001 readiness).
  • Set up auditing and alerting for anomalous activities in source control and deployment platforms.
  • Tooling & Automation

  • Deploy and maintain security tools (e.G., GitGuardian, Aqua, Prisma Cloud) to detect hard coded secrets, policy violations, and misconfigurations.
  • Automate remediation workflows where possible (e.G., auto-patching vulnerable dependencies).
  • You have :

  • 7-10 years in Security Architecture, AppSec, or a combined development and security engineering role.
  • Strong hands-on experience in secure coding, application security testing, and source code analysis.
  • Solid knowledge of CI / CD pipelines, version control (especially GitHub / GitLab), and branch control strategies.
  • Familiarity with cloud platforms (AWS, Azure, GCP) and security practices for each.
  • In-depth understanding of network security, access controls, and zero trust architecture.
  • Practical knowledge of regulatory or compliance frameworks (e.G., ISO 27001, SOC 2, NIST).
  • Preferred Qualifications

  • Experience working with Infrastructure as Code (IaC) tools (e.G., Terraform, CloudFormation) with embedded security checks.
  • Familiarity with container security (Docker, Kubernetes, image scanning).
  • Certifications : OSCP, CSSLP, CEH, GSEC, or AWS Security Specialty.
  • Contributions to open-source security tools or projects is a plus.
  • Key KPIs / Metrics of Success

  • Time-to-remediate for identified vulnerabilities.
  • Percentage of pipelines with integrated SAST / DAST.
  • Number of policy violations prevented via branch rules and access controls.
  • Coverage of secure coding training among developers.
  • Sign on bonus offered for immediate joiners
  • Create a job alert for this search

    Application Security Engineer • Bengaluru, Republic Of India, IN

    Related jobs
    Security (DevSecOps)and QA (Automation)

    Security (DevSecOps)and QA (Automation)

    PioVation GmbH • hosur, tamil nadu, in
    If you care about European-grade safety, quality, and compliance, read on.Senior Security Engineer (DevSecOps).Application & cloud security (threat modeling, secure SDLC).Kubernetes security (netwo...Show more
    Last updated: 16 days ago • Promoted
    Senior Application Security Engineer

    Senior Application Security Engineer

    Atomicwork • Bengaluru, Karnataka, India
    Atomicwork is reimagining IT and workplace operations by putting employees at the center of the experience.With a strong emphasis on automation, integration, and security, Atomicwork helps organiza...Show more
    Last updated: 30+ days ago • Promoted
    Application Security Engineer II

    Application Security Engineer II

    FICO • Bengaluru, Republic Of India, IN
    Join our world-class team today and fulfill your career potential!.As a Product Security Engineer II in Cyber Security, you will be supporting security governance for a wide set of customer-facing ...Show more
    Last updated: 30+ days ago • Promoted
    Principal Application Security Engineer

    Principal Application Security Engineer

    Okta • Bengaluru, Republic Of India, IN
    Preferred qualification and abilities : .Java, building highly reliable and mission-critical software.Work experience and excellent understanding in mitigating OWASP Top 10 attacks on applications, A...Show more
    Last updated: 8 days ago • Promoted
    Lead Application security engineer

    Lead Application security engineer

    Capillary Technologies • Bengaluru, Karnataka, India
    We operate in the loyalty domain where we help our customers to better engage their users to enhance their business outcomes. To provide assurances to our customers, we comply with ISO 27001, PCI & ...Show more
    Last updated: 13 days ago • Promoted
    Application Security Engineer

    Application Security Engineer

    Confidential • Bengaluru / Bangalore
    Conduct DAST (manual and automated) for web, API, and thick client applications.Perform manual code reviews and mobile application VAPT (static and dynamic). Execute infrastructure VA and configurat...Show more
    Last updated: 30+ days ago • Promoted
    Security Engineer

    Security Engineer

    Infogain • Bengaluru, Karnataka, India
    Title : Security Engineer (6+ Years).Use CrowdStrike reports to evaluate all security vulnerabilities on both Windows and Linux systems. Analyze the requirements to remediate the security vulnerabili...Show more
    Last updated: 29 days ago • Promoted
    Lead Application Security Engineer

    Lead Application Security Engineer

    Capillary Technologies • Bengaluru, Republic Of India, IN
    We operate in the loyalty domain where we help our customers to better engage their users to enhance their business outcomes. To provide assurances to our customers, we comply with ISO 27001, PCI & ...Show more
    Last updated: 12 days ago • Promoted
    Senior Application Security (DevSecOps) Engineer

    Senior Application Security (DevSecOps) Engineer

    Confidential • Bengaluru / Bangalore
    Pearson is seeking a highly motivated and experienced.Senior Application Security (DevSecOps) Engineer.DevOps, Application Security, and Cloud Security. In this role, you will be crucial in leading ...Show more
    Last updated: 30+ days ago • Promoted
    Security Engineer III

    Security Engineer III

    CME Group • Bengaluru, Karnataka, India
    The Application Security Engineer leads efforts to enhance application security and the secure software development lifecycle. This individual is responsible for performing manual application securi...Show more
    Last updated: 1 day ago • Promoted
    Security Engineer

    Security Engineer

    London Stock Exchange Group • Bangalore, India
    Are you an Active Directory specialist with a security mentality? We are looking for a support specialist to work within a team operating within a 24 / 7 service, who are responsible for maintaining ...Show more
    Last updated: 30+ days ago • Promoted
    Azure Security Centre Analyst

    Azure Security Centre Analyst

    PwC • hosur, tamil nadu, in
    Seeking an Azure Security Centre Analyst with proven experience in cloud security operations within the Microsoft Azure ecosystem. Key responsibilities include managing Azure security tools, vulnera...Show more
    Last updated: 13 days ago • Promoted
    Senior Application Security Engineer

    Senior Application Security Engineer

    Confidential • Bengaluru / Bangalore, India
    Atomicwork is reimagining IT and workplace operations by putting employees at the center of the experience.With a strong emphasis on automation, integration, and security, Atomicwork helps organiza...Show more
    Last updated: 30+ days ago • Promoted
    Senior Application Security Engineer

    Senior Application Security Engineer

    Sphera • Bangalore, IN
    Sphera is a leading global provider of enterprise software and services that enables companies to manage and optimize their environmental, health, safety and sustainability.Our mission is to create...Show more
    Last updated: 6 days ago • Promoted
    Senior Security Engineer

    Senior Security Engineer

    Razorpay • Bengaluru, Karnataka, India
    Title : Senior Product Security Security Engineer.Razorpay is looking for a Senior Application Security Engineer with solid experience in AppSec fundamentals—secure code review, vulnerability discov...Show more
    Last updated: 23 hours ago • Promoted
    Principal Application Security Engineer

    Principal Application Security Engineer

    CME Group • Bengaluru, Republic Of India, IN
    The Application Security Engineer leads efforts to enhance application security and the secure software development lifecycle. This individual is responsible for performing manual application securi...Show more
    Last updated: 1 day ago • Promoted
    Application Security Engineer

    Application Security Engineer

    Foodsmart • Bangalore, IN
    Foodsmart is the leading telenutrition and foodcare solution, backed by a robust network of Registered Dietitians.Our platform is designed to foster healthier food choices, drive lasting behavior c...Show more
    Last updated: 30+ days ago • Promoted
    Application Security Lead

    Application Security Lead

    Atomicwork • Bengaluru, Republic Of India, IN
    Atomicwork is reimagining IT and workplace operations by putting employees at the center of the experience.With a strong emphasis on automation, integration, and security, Atomicwork helps organiza...Show more
    Last updated: 30+ days ago • Promoted