Experience : 5.00 + years
Salary : INR 3000000-4000000 / year (based on experience)
Shift : (GMT+05 : 30) Asia / Kolkata (IST)
Opportunity Type : Hybrid (Pune)
Placement Type : Full time Permanent Position
- Note : This is a requirement for one of Uplers' client - Urbint)
What do you need for this opportunity
Must have skills required :
Application Security, threat modeling, Security Automation, Vulnerability Assessment, Secure SDLC
Urbint is Looking for :
Job Summary :
We are seeking an Application Security Engineer-II to help embed security within Urbints software development lifecycle and scale our product security practices. This role focuses on enabling developers with the right tools, patterns, and guidance, while collaborating with engineering, CloudOps, and InfoSec to proactively identify, assess, and mitigate risk across Urbints platforms. Youll also support Urbints security posture in customer engagements and help evaluate and improve the maturity of security controls across our products.
What You'll Do :
Design and implement security tooling and automation in CI / CD pipelines (SAST, secrets scanning, dependency checks, IaC scanning) to integrate security at build-time.Conduct security assessments of Urbints web apps, APIs, cloud-native services, and internal tooling using manual and automated approaches.Lead and facilitate threat modeling for critical features and systems, and drive mitigation strategies with engineering teams.Collaborate on application security design, providing guidance on authentication, authorization, encryption, input validation, error handling, and data protection.Evaluate the security maturity of Urbint products, identify gaps, and partner with engineering to close them.Partner with InfoSec to support customer security questionnaires, audits, and external security posture communications.Promote secure coding practices and define reusable secure patterns, golden paths, and developer guides.Support and enable Security Champions across squads through mentorship, training, and playbooks.Work with CloudOps on runtime guardrails, including secrets management, identity controls, and logging practices.Assist in security incident investigations related to application-layer vulnerabilities and support remediation planning.Deliver security awareness sessions and workshops to uplift team security knowledge.Stay up to date on security trends, tools, and best practices, and share knowledge with engineering teams.Who You Are :
6+ years experience in application security or DevSecOps roles.Solid understanding of web application security (e.g., OWASP Top 10, ASVS) and common vulnerabilitiesHands-on experience with security tooling in CI / CD pipelines (e.g., SAST, SCA, secrets scanning, IaC scanning).Experience in secure architecture, threat modeling, and design reviews.Proficiency with a modern programming language (Python, TypeScript, JavaScript, or similar).Strong communication skills, able to collaborate effectively across engineering, CloudOps, and InfoSec teams.Bonus : Experience supporting data security initiatives or customer security assessments.Bonus : Familiarity with cloud-native environments (AWS, GCP, Azure)How to apply for this opportunity
Step 1 : Click On Apply! And Register or Login on our portal.Step 2 : Complete the Screening Form & Upload updated ResumeStep 3 : Increase your chances to get shortlisted & meet the client for the Interview!About Uplers :
Our goal is to make hiring reliable, simple, and fast. Our role will be to help all our talents find and apply for relevant contractual onsite opportunities and progress in their career. We will support any grievances or challenges you may face during the engagement.
(Note : There are many more opportunities apart from this on the portal. Depending on the assessments you clear, you can apply for them as well).
So, if you are ready for a new challenge, a great work environment, and an opportunity to take your career to the next level, don't hesitate to apply today. We are waiting for you!
Skills Required
Vulnerability Assessment, security automation , Typescript, Web Application Security, Gcp, Javascript, Application Security, SAST, Owasp Top 10, threat modeling , secure sdlc , Azure, Python, Aws