2 months ago
Pune, IndiaSenior / Staff+
Responsibilities
- Embed application security controls into CI/CD pipelines to provide accurate, actionable, and timely feedback.
- Investigate, remediate, and validate application security findings, including managing exceptions and false positives.
- Conduct targeted code reviews with engineers and platform teams to identify security issues and improve coding practices.
- Implement and maintain security controls, integrations, and automations for secure and privacy-preserving applications and APIs.
- Perform threat modeling to identify abuse cases, threat actors, and preventative and detective controls.
- Define security best practices, prioritize activities, and execute improvements across application and API platforms.
- Mentor engineers and raise awareness of security mandates.
Requirements
- 7 to 11 years of security experience in application security or a related area.
- Experience identifying, investigating, and remediating vulnerabilities throughout the software development lifecycle.
- Hands-on experience writing and reviewing code and contributing to design reviews, planning, and implementation.
- Experience designing, implementing, and improving security tooling and CI/CD integrations with a focus on reducing noise and prioritizing risk.
- Strong developer-experience focus and ability to communicate security issues clearly.
- Familiarity with monolithic and microservice-based application architectures.
- Solid understanding of OWASP Top 10, SAMM, ASVS, and FIRST principles.
- Comfort working with one or more programming languages such as Java, C++, Python, or JavaScript.
- Experience with LLMs, AI, and agentic coding platforms such as GitHub Copilot, Gemini, or Claude Code.
- Proven experience as a security subject-matter expert, including mentoring and raising awareness of security mandates.
