Job Summary
We are seeking an experienced Application Security Engineer with strong expertise in Application Security, Vulnerability Management, and Security Operations. The ideal candidate will have hands-on experience identifying, analyzing, prioritizing, and remediating application and infrastructure security vulnerabilities while working closely with development, DevOps, infrastructure, and Security Operations teams.
This is an L3 / Senior-level role, requiring the ability to independently investigate complex security issues, drive remediation, improve vulnerability management processes, and support security incident and operational activities.
Required Skills
- Application Security – Intermediate to Master / L3 level
- Vulnerability Management – Strong hands-on experience
- Security Operations – Intermediate level
- Application vulnerability assessment and remediation
- Vulnerability scanning and management tools
- Secure SDLC and DevSecOps practices
- OWASP Top 10 and common application security vulnerabilities
- CVE, CVSS scoring, risk assessment, and vulnerability prioritization
- Security incident investigation and triage
- Working knowledge of cloud and container security
- Strong collaboration with Development, DevOps, Infrastructure, and Security teams
Key Responsibilities
- Perform and support application security assessments and vulnerability analysis.
- Identify, investigate, validate, and prioritize security vulnerabilities.
- Manage the complete vulnerability lifecycle, including identification, triage, remediation tracking, validation, and closure.
- Analyze vulnerabilities using CVE, CVSS, exploitability, business impact, and risk.
- Work with application development and engineering teams to recommend remediation and secure coding solutions.
- Support Security Operations activities, including security alert investigation, triage, and incident support.
- Perform root cause analysis for recurring security vulnerabilities and recommend preventive controls.
- Support vulnerability scanning across applications, APIs, infrastructure, cloud, and container environments.
- Track remediation SLAs and provide vulnerability status reporting to security and technology stakeholders.
- Participate in security incident investigations and coordinate with SOC and engineering teams when required.
- Support implementation and improvement of DevSecOps and Secure SDLC practices.
- Stay updated on emerging vulnerabilities, threats, exploits, and application security risks.
Preferred Technical Skills
- Vulnerability Management tools such as Qualys, Tenable/Nessus, Rapid7 InsightVM
- Application Security tools such as Snyk, Veracode, Checkmarx, Fortify, SonarQube
- SAST, DAST, SCA and API security testing
- OWASP Top 10
- CVE/CVSS and vulnerability prioritization
- SIEM/SOC tools such as Splunk, Sentinel, QRadar, or similar
- Cloud security experience with AWS, Azure, or Google Cloud Platform
- Container and Kubernetes security knowledge
- CI/CD and DevSecOps integration
- Scripting knowledge in Python, PowerShell, or Bash
Experience Required
- 5+ years of experience in Cybersecurity, Application Security, or Vulnerability Management.
- Strong hands-on experience in Application Security and Vulnerability Management.
- Experience working with Security Operations / SOC teams.
- Ability to independently handle complex vulnerabilities and security investigations at an L3 level.