
Senior Application Security Engineer
Hyland Software, LLC2 months ago
Hyderābād, IndiaSenior
Responsibilities
- Partner with engineering, product, infrastructure, platform, and DevOps teams to integrate security throughout the software development lifecycle.
- Design, implement, and maintain CI/CD security tooling and gates for SAST, DAST, SCA, secrets detection, and container scanning.
- Improve the security posture of cloud-native environments across AWS, GCP, and Azure, including containers, Kubernetes clusters, serverless functions, IAM, and managed services.
- Lead threat modeling and conduct application security assessments, code reviews, and manual penetration testing.
- Triage and remediate findings from security tools and bug bounty programs while helping developers fix vulnerabilities.
- Define secure coding standards, security testing requirements, and developer-facing security documentation.
- Advise engineers on AI and LLM security risks, including prompt injection, insecure output handling, data leakage, and AI coding assistant usage.
- Evaluate AppSec tooling, investigate application-layer security incidents, mentor engineers, and contribute to security architecture reviews.
Requirements
- 5+ years of experience in application security, software security engineering, or a closely related role.
- Hands-on experience securing cloud-native environments on AWS, GCP, or Azure, including containers, Kubernetes, IAM, and serverless architectures.
- Experience integrating SAST, DAST, SCA, and secrets scanning into CI/CD pipelines, including with GitHub Actions or Jenkins.
- Strong knowledge of OWASP Top 10, secure design principles, injection, authentication flaws, business logic issues, and other common vulnerability classes.
- Experience with application security testing and proficiency with tools such as Checkmarx, Burp Suite, Trivy, Checkov, and Veracode.
- Ability to read and reason about code in Python, JavaScript/TypeScript, Java, Go, .NET (C#), or a similar language.
- Experience with infrastructure-as-code security using Terraform, CloudFormation, or Helm and policy-as-code frameworks such as OPA is preferred.
- Familiarity with AI/LLM security risks, the OWASP Top 10 for LLMs, AI-assisted development workflows, and reviewing AI-generated code is preferred.
- One or more relevant certifications such as OSCP, CISSP, CEH, GWEB, or CCSP is preferred.
- Prior experience in a product-led technology or SaaS environment is preferred.
Benefits
- Hybrid work arrangement requiring three days in the office in Hyderabad.
- Hyland offers career development resources, wellbeing programs, innovation practices, and employee and community support initiatives.
- Hyland is committed to an inclusive workplace and is an equal opportunity employer.
Tech Stack
AWSAzureC#GitHub ActionsGoGoogle Cloud PlatformHelmJavaJavaScriptJenkinsKubernetes.NETPythonTerraformTypeScript