Talent.com
Application Security Engineer
Application Security EngineerFoodsmart • Guwahati, Republic Of India, IN
Application Security Engineer

Application Security Engineer

Foodsmart • Guwahati, Republic Of India, IN
28 days ago
Job description

About us :

Foodsmart is the leading telenutrition and foodcare solution, backed by a robust network of Registered Dietitians. Our platform is designed to foster healthier food choices, drive lasting behavior change, and deliver long-term health outcomes. Through our highly personalized, digital platform, we guide our 2.2 million members—including those in employer-sponsored health plans, regional and national Medicaid managed care organizations, Medicare Advantage plans, and commercial insurers—on a tailored journey to eating well while saving time and money.

Foodsmart seamlessly integrates dietary assessments and nutrition counseling with online food ordering and cost-effective meal planning for the entire family, optimizing ingredients both at home and on the go. We partner with national and regional retailers across the U.S., many of whom accept SNAP / EBT, making healthier food more accessible. Additionally, we assist members with SNAP enrollment and management, providing tangible access to nutritious food.In 2024, Foodsmart secured a $200 million investment from TPG’s Rise Fund, which supports entrepreneurs dedicated to achieving the United Nations’ Sustainable Development Goals. This investment will help us expand our reach, particularly to low-income workers who are disproportionately affected by diet-related diseases.

At Foodsmart, our mission is to make nutritious food accessible and affordable for everyone, regardless of economic status. We are committed to a set of core values that shape our culture and work environment :

⚖️ Measured : We make data-driven, truth-seeking decisions.

💥 Impactful : We are fueled by achieving our mission and vision.

🙏 Collaborative : We help each other be better and create a positive environment.

📈 Hungry : We maintain a healthy growth mindset, seeking to overcome challenges with courage.

😊 Joyful : We take joy in each other, our work, and the privilege of doing this work.

Whether you're a dietitian, a commercial leader, or a technologist, working at Foodsmart means being part of a team that is passionate, supportive, and driven by a shared purpose. Join us in transforming the way people access and enjoy healthy food.

About the role :

We are seeking an Application Security Engineer who will work at the intersection of security, DevOps, and development to ensure security is embedded throughout our SDLC. This role requires deep technical expertise in secure code review, static and dynamic application security testing (SAST / DAST), and infrastructure governance, especially in the segregation of environments, separation of duties, and branch protection in source control systems.

You will :

Code & Application Security

  • Conduct manual and automated code reviews to identify security vulnerabilities (e.G., XSS, SQLi, logic flaws).
  • Define and implement SAST and DAST pipelines using tools such as SNYK, Checkmarx, Fortify, OWASP ZAP, or Burp Suite.
  • Collaborate with development teams to remediate vulnerabilities and educate on secure coding standards (e.G., OWASP Top 10).

DevSecOps & CI / CD Pipeline Security

  • Integrate security controls into CI / CD pipelines using tools like GitHub Actions, Jenkins, and GitLab CI.
  • Define and enforce branch protection rules, code signing, and commit validation policies (e.G., mandatory code reviews, signed commits).
  • Work closely with DevOps to ensure security-as-code is implemented across build, test, and deployment stages.
  • Infrastructure & Environment Segregation

  • Ensure proper segregation between development, staging, and production environments, following least privilege principles.
  • Collaborate with infra and cloud teams to enforce network and access segregation (e.G., VPC segmentation, IAM policies).
  • Governance & Policy Enforcement

  • Define and monitor separation of duties policies between developers, testers, and deployers.
  • Create security baselines and compliance checks (e.G., CIS Benchmarks, SOC 2 / ISO 27001 readiness).
  • Set up auditing and alerting for anomalous activities in source control and deployment platforms.
  • Tooling & Automation

  • Deploy and maintain security tools (e.G., GitGuardian, Aqua, Prisma Cloud) to detect hard coded secrets, policy violations, and misconfigurations.
  • Automate remediation workflows where possible (e.G., auto-patching vulnerable dependencies).
  • You have :

  • 7-10 years in Security Architecture, AppSec, or a combined development and security engineering role.
  • Strong hands-on experience in secure coding, application security testing, and source code analysis.
  • Solid knowledge of CI / CD pipelines, version control (especially GitHub / GitLab), and branch control strategies.
  • Familiarity with cloud platforms (AWS, Azure, GCP) and security practices for each.
  • In-depth understanding of network security, access controls, and zero trust architecture.
  • Practical knowledge of regulatory or compliance frameworks (e.G., ISO 27001, SOC 2, NIST).
  • Preferred Qualifications

  • Experience working with Infrastructure as Code (IaC) tools (e.G., Terraform, CloudFormation) with embedded security checks.
  • Familiarity with container security (Docker, Kubernetes, image scanning).
  • Certifications : OSCP, CSSLP, CEH, GSEC, or AWS Security Specialty.
  • Contributions to open-source security tools or projects is a plus.
  • Key KPIs / Metrics of Success

  • Time-to-remediate for identified vulnerabilities.
  • Percentage of pipelines with integrated SAST / DAST.
  • Number of policy violations prevented via branch rules and access controls.
  • Coverage of secure coding training among developers.
  • Sign on bonus offered for immediate joiners
  • Create a job alert for this search

    Application Security Engineer • Guwahati, Republic Of India, IN

    Related jobs
    Azure Security Centre Analyst

    Azure Security Centre Analyst

    PwC • guwahati, assam, in
    Seeking an Azure Security Centre Analyst with proven experience in cloud security operations within the Microsoft Azure ecosystem. Key responsibilities include managing Azure security tools, vulnera...Show more
    Last updated: 11 days ago • Promoted
    Cyber Security Engineer

    Cyber Security Engineer

    Autodesk • Guwahati, Republic Of India, IN
    Cyber Security Engineer – Job DescriptionPosition SummaryThe Cyber Security Engineer is responsible for designing, implementing, and maintaining security systems to protect the organization’s compu...Show more
    Last updated: 4 hours ago • Promoted • New!
    IP / SOC Verification Engineer

    IP / SOC Verification Engineer

    ACL Digital • guwahati, assam, in
    IP / SS / SoC Verification Engineer (Hybrid – Bangalore / Hyderabad).The role involves hands-on contribution to.IP, Sub-system, and SoC-level verification. SystemVerilog / UVM-based verification environme...Show more
    Last updated: 14 days ago • Promoted
    Senior SailPoint Engineer

    Senior SailPoint Engineer

    Covenant HR • guwahati, assam, in
    Our client is a top-tier cybersecurity and managed services organization operating in partnership with one of the world’s leading IT management platforms. This Fortune-recognized enterprise is known...Show more
    Last updated: 14 days ago • Promoted
    Sr. Member of Technical Staff / Staff Engineer

    Sr. Member of Technical Staff / Staff Engineer

    Skyrelis • guwahati, assam, in
    Help Build the Security Layer for the Agentic AI Era.We’re building at the frontier of two unstoppable waves : .Autonomous AI agents are exploding in capability — planning, executing, and learning in...Show more
    Last updated: 1 hour ago • Promoted • New!
    Part-Time Cyber Deception & Honeypot-as-a-Service Consultant

    Part-Time Cyber Deception & Honeypot-as-a-Service Consultant

    CodeGuardian.ai • guwahati, assam, in
    Part-Time Cyber Deception & Honeypot-as-a-Service Consultant.Department : Cyber Defense & Threat Intelligence.Part-Time Cyber Deception & Honeypot-as-a-Service Consultant to design, deploy, and mana...Show more
    Last updated: 14 days ago • Promoted
    CipherTrust Engineer

    CipherTrust Engineer

    Capgemini • guwahati, assam, in
    We are seeking a skilled and experienced professional in.Encryption, Key Management, and Cryptography.Vormetric Data Security Manager (DSM). Onboard applications, databases, and storage platforms in...Show more
    Last updated: 14 days ago • Promoted
    Verint WFM Engineer

    Verint WFM Engineer

    MRP Group • guwahati, assam, in
    Our client are seeking an experienced Verint Workforce Management (WFM) Engineer with proven expertise in implementing Verint WFM, Desktop and Process Analytics (DPA), and Speech Analytics solution...Show more
    Last updated: 17 hours ago • Promoted • New!
    Saviynt (Cloud Identity Security and Management Solutions)

    Saviynt (Cloud Identity Security and Management Solutions)

    Tata Consultancy Services • guwahati, assam, in
    Come and join us for an exciting career with TCS!!!.TCS has always been in the spotlight for being adept in “the next big technologies”. What we can offer you is a space to explore varied technologi...Show more
    Last updated: 6 days ago • Promoted
    SAP GRC Security Lead Consultant - Australia (Onsite)

    SAP GRC Security Lead Consultant - Australia (Onsite)

    Avensys Consulting • guwahati, assam, in
    Avensys is a reputed global IT professional services company headquartered in Singapore.Our service spectrum includes enterprise solution consulting, business intelligence, business process automat...Show more
    Last updated: 11 days ago • Promoted
    Observability Engineer (Cloud Engineer) (Otel, AWS, Grafana)

    Observability Engineer (Cloud Engineer) (Otel, AWS, Grafana)

    FICO • guwahati, assam, in
    FICO is seeking a Full-Stack observability Lead Engineer to design, maintain, and optimize our observability platform.The ideal candidate will be an expert in Open telemetry(Otel) instrumentation a...Show more
    Last updated: 12 days ago • Promoted
    Infrastructure Engineer - Tier3

    Infrastructure Engineer - Tier3

    NEXPLAY SECURE • guwahati, assam, in
    The Infrastructure Engineer (Tier III, remote) serves as the senior technical authority within Nexplay Secure's Managed Services division. This role leads the deployment and ongoing support of criti...Show more
    Last updated: 30+ days ago • Promoted
    Senior Engineer - Digital Assets (Wholesale Banking)

    Senior Engineer - Digital Assets (Wholesale Banking)

    Flyers Soft • guwahati, assam, in
    Cloud (AWS / Azure / GCP), Enterprise Architecture (TOGAF), Security (CISSP / CISM), Blockchain / DLT (Hyperledger, Corda, CBP), Agile (PMI‑ACP / Scrum). Deep knowledge of DLT platforms and smart contracts; e...Show more
    Last updated: 12 days ago • Promoted
    Senior Cloud Security Specialist

    Senior Cloud Security Specialist

    ACL Digital • guwahati, assam, in
    We are a leading organization in the field of information security, dedicated to protecting our clients' data and ensuring their digital safety. Our mission is to provide innovative security solutio...Show more
    Last updated: 12 days ago • Promoted
    Senior 3D Secure Implementation specialist

    Senior 3D Secure Implementation specialist

    Art Technology and Software • guwahati, assam, in
    Client Implementation & Onboarding : .Lead end-to-end client 3DS implementations, including onboarding, integration, testing, and go-live for 3DS solutions. Collaborate with cross-functional teams to ...Show more
    Last updated: 11 days ago • Promoted
    Cyber Security Specialist

    Cyber Security Specialist

    Innefu Labs • guwahati, assam, in
    We are seeking experienced and detail-oriented professionals for the role.The selected candidates will be responsible for assisting cybercrime investigations by collecting and analysing digital evi...Show more
    Last updated: 12 days ago • Promoted
    Senior Security Automation Engineer (India) — Python, API Integrations, Databricks

    Senior Security Automation Engineer (India) — Python, API Integrations, Databricks

    Symosis Security • guwahati, assam, in
    Symosis is a fast-growing US cybersecurity and engineering firm building real, high-impact security automation for some of the largest tech companies in the world. We move fast, solve hard problems,...Show more
    Last updated: 17 hours ago • Promoted • New!
    Project Manager

    Project Manager

    iMerit Technology • Shillong, Meghalaya, India
    Manager / Project Manager - Delivery.Client Facing role in IT Services; Preferably leading AI Data Annotation Teams.Engineering Degree / Master’s Degree / Bachelor’s Degree.PMP or Prince 2 certific...Show more
    Last updated: 4 days ago • Promoted