Job Description :
We are seeking an experienced Security Engineer with strong expertise in Application Security, Cloud Security, and VAPT to join our client's engineering team. The role requires hands-on experience in SAST, DAST, Secure Code Review, Bug Bounty programs, and Cloud Security (AWS / GCP). The ideal candidate should have worked in product-based or SaaS environments and be passionate about building secure, scalable solutions.
Key Responsibilities :
1. Perform Application Security (SAST, DAST, IAST) across web, API, and mobile applications.
2. Conduct Vulnerability Assessment & Penetration Testing (VAPT) for applications, infrastructure, and cloud.
3. Lead and implement Secure SDLC practices within engineering teams.
4. Perform manual and automated Secure Code Reviews (Java, Python, Go, etc.).
5. Strengthen Cloud Security controls across AWS / GCP, including containerized environments.
6. Manage and enhance the Bug Bounty / Responsible Disclosure programs.
7. Work with developers, DevOps, and product managers to embed security from design to release.
8. Contribute to Threat Modeling, Exploit Development, and Reverse Engineering when required.
Required Skills & Experience :
1. 4-7 years of proven experience in Application Security, VAPT, and Cloud Security.
2. Hands-on expertise with tools like Burp Suite Pro, Checkmarx, Sonatype, Prisma Cloud, Wiz, NowSecure.
3. Strong in manual and automated Secure Code Reviews.
4. Experience securing applications and infrastructure on AWS and GCP.
5. Knowledge of CI / CD pipeline security.
6. Preferred certifications : CEH, OSCP, eCXD, GWAPT or similar.
7. Strong communication skills with the ability to collaborate across engineering and business teams.
Benefits :
1. Opportunity to work with a fast-scaling product-based client in the SaaS / Tech domain.
2. Exposure to cutting-edge Application Security and Cloud Security frameworks.
3. Competitive salary and career growth opportunities.
4. Continuous learning with certification support, training, and conferences.
(ref : hirist.tech)
Application Security Engineer • Bangalore