
Application Security Engineer
S&P Global1 day ago
Remote, India or Hyderābād, IndiaSenior
Responsibilities
- Implement, configure, administer, and optimize enterprise SAST capabilities across applications and repositories.
- Analyze, validate, prioritize, and track application security findings through remediation, retesting, risk acceptance, or closure.
- Design and maintain CI/CD security controls, risk-based gates, reusable pipeline templates, and source-control integrations.
- Develop AppSec automation using scripting languages, REST APIs, webhooks, command-line interfaces, and SDKs.
- Provide secure coding guidance, threat modeling support, developer enablement, documentation, and secure SDLC standards.
- Support cloud security governance, control assessments, exception management, compliance evidence, and audit readiness across AWS, Microsoft Azure, and Google Cloud.
- Produce application security metrics, dashboards, governance records, and audit evidence.
Requirements
- Bachelor's or Master's degree in Computer Science, Information Security, Engineering, or a related discipline, or equivalent practical experience.
- At least five years of relevant experience in Application Security, Product Security, DevSecOps, or software security engineering.
- Hands-on experience with enterprise SAST platforms, secure code analysis, vulnerability validation, and CI/CD security integration.
- Experience with GitHub, GitHub Actions, Azure DevOps, Jenkins, GitLab CI, or equivalent technologies.
- Strong scripting or development skills with Python, PowerShell, Bash, Java, C#, JavaScript, or similar languages.
- Experience building integrations with REST APIs, webhooks, service accounts, and modern authentication mechanisms.
- Strong understanding of OWASP Top 10, CWE classifications, secure coding, vulnerability remediation, web applications, APIs, microservices, containers, and cloud-native architectures.
- Working knowledge of cloud security governance, IAM, encryption, secrets management, logging, monitoring, secure configuration, compliance evidence, and exception management.
- Preferred qualifications include SAST administration or integration experience, relevant SAST or AppSec certifications, OSCP or comparable penetration-testing certification, and cloud security certifications.
- Preferred experience includes SCA, secrets scanning, API security, infrastructure-as-code scanning, container security, reusable CI/CD components, AppSec dashboards, security research, and software supply chain security.
- Knowledge of NIST CSF, NIST SP 800-53, ISO/IEC 27001, SOC 2, PCI DSS, or equivalent control frameworks is beneficial.
Benefits
- Health care coverage and wellness benefits.
- Generous paid time off and flexible downtime.
- Continuous learning resources and career development support.
- Retirement planning, continuing education, company-matched student loan contributions, and financial wellness programs.
- Family-focused benefits, retail discounts, and referral incentive awards.
- Benefits vary by country; details are provided through the S&P Global benefits site.