S&P Global

Application Security Engineer

S&P Global
Apply
1 day ago
Remote, India or Hyderābād, IndiaSenior

Responsibilities

  • Implement, configure, administer, and optimize enterprise SAST capabilities across applications and repositories.
  • Analyze, validate, prioritize, and track application security findings through remediation, retesting, risk acceptance, or closure.
  • Design and maintain CI/CD security controls, risk-based gates, reusable pipeline templates, and source-control integrations.
  • Develop AppSec automation using scripting languages, REST APIs, webhooks, command-line interfaces, and SDKs.
  • Provide secure coding guidance, threat modeling support, developer enablement, documentation, and secure SDLC standards.
  • Support cloud security governance, control assessments, exception management, compliance evidence, and audit readiness across AWS, Microsoft Azure, and Google Cloud.
  • Produce application security metrics, dashboards, governance records, and audit evidence.

Requirements

  • Bachelor's or Master's degree in Computer Science, Information Security, Engineering, or a related discipline, or equivalent practical experience.
  • At least five years of relevant experience in Application Security, Product Security, DevSecOps, or software security engineering.
  • Hands-on experience with enterprise SAST platforms, secure code analysis, vulnerability validation, and CI/CD security integration.
  • Experience with GitHub, GitHub Actions, Azure DevOps, Jenkins, GitLab CI, or equivalent technologies.
  • Strong scripting or development skills with Python, PowerShell, Bash, Java, C#, JavaScript, or similar languages.
  • Experience building integrations with REST APIs, webhooks, service accounts, and modern authentication mechanisms.
  • Strong understanding of OWASP Top 10, CWE classifications, secure coding, vulnerability remediation, web applications, APIs, microservices, containers, and cloud-native architectures.
  • Working knowledge of cloud security governance, IAM, encryption, secrets management, logging, monitoring, secure configuration, compliance evidence, and exception management.
  • Preferred qualifications include SAST administration or integration experience, relevant SAST or AppSec certifications, OSCP or comparable penetration-testing certification, and cloud security certifications.
  • Preferred experience includes SCA, secrets scanning, API security, infrastructure-as-code scanning, container security, reusable CI/CD components, AppSec dashboards, security research, and software supply chain security.
  • Knowledge of NIST CSF, NIST SP 800-53, ISO/IEC 27001, SOC 2, PCI DSS, or equivalent control frameworks is beneficial.

Benefits

  • Health care coverage and wellness benefits.
  • Generous paid time off and flexible downtime.
  • Continuous learning resources and career development support.
  • Retirement planning, continuing education, company-matched student loan contributions, and financial wellness programs.
  • Family-focused benefits, retail discounts, and referral incentive awards.
  • Benefits vary by country; details are provided through the S&P Global benefits site.

Tech Stack

AWSAzureBashC#GitHub ActionsGitLab CI/CDGoogle CloudJavaJavaScriptJenkinsPowerShellPython

Categories

Contact me