One Identity

Senior Application Security Engineer

One Identity
Apply
18 hours ago
Remote, IndiaSenior

Responsibilities

  • Threat-model authentication, session handling, privilege elevation, connector and integration boundaries, tenant isolation, cryptographic handling, and secrets management.
  • Define security requirements during architecture and provide risk assessments that support product and release decisions.
  • Submit, review, and implement security fixes in product repositories while partnering with engineers on remediation.
  • Own static analysis, dependency scanning, dynamic testing, software composition analysis, and SBOM generation across product lines.
  • Develop secure coding patterns, libraries, reference implementations, and review practices for .NET and Java codebases.
  • Determine appropriate review and remediation practices for AI-assisted development and verify AI-generated changes.
  • Own product vulnerability response, including researcher and customer intake, triage, coordinated disclosure, CVE handling, and advisories.
  • Convert penetration-test and bug-bounty findings into fixes and systemic security improvements.
  • Provide product security evidence for customer questionnaires, security reviews, and certification work.

Requirements

  • Six or more years of experience in software engineering or security, with at least three years focused on application or product security.
  • Application security experience on products that customers deploy and operate in their own datacenters.
  • Production code-level fluency in C# and .NET, with sufficient experience to work in Java codebases.
  • Hands-on experience with AI-assisted development or AI-enabled security tooling within the last six months.
  • Experience threat-modeling with engineering teams during design and tuning static, dynamic, and composition analysis tools.
  • Knowledge of identity and authentication protocols including OAuth, OIDC, SAML, and SCIM.
  • Experience with coordinated vulnerability disclosure, CVE handling, and secure code review for web and API surfaces.
  • Ability to evaluate and communicate security risk with senior engineers and product leadership.
  • Preferred experience with SBOM standards, license compliance, cryptographic review, security champion programs, PCI DSS, FedRAMP, or product engineering.

Benefits

  • Globally distributed team with the role embedded directly in engineering and access to product repositories.
  • Opportunity to work across the full product portfolio and influence engineering practices and customer-facing security outcomes.
  • Health and wellness programs, career development opportunities, and rewards for employee contributions.
  • One Identity is an equal opportunity employer and prohibits discrimination and harassment.

Tech Stack

C#Java.NET

Categories

One Identity

About One Identity

501-1,000 employees

One Identity builds enterprise identity security software, unifying identity governance and administration, privileged access management, access management, and Active Directory lifecycle management for large organizations. It offers self-managed and SaaS deployments and sells via enterprise licenses and subscriptions, with services and support. Part of Quest Software and headquartered in Aliso Viejo, California, One Identity serves over 11,000 organizations and helps manage more than 500 million identities worldwide.

Contact me