
Information Security Engineer (Application Security)
Barracuda Networks, Inc.2 hours ago
Bengaluru, IndiaMid Level
Responsibilities
- Support application security activities across the software development lifecycle.
- Identify, document, and track application security risks such as insecure design, weak access control, exposed secrets, vulnerable components, and misconfigurations.
- Review application security findings, coordinate with owners, and track remediation or accepted exceptions through closure.
- Support threat modeling by identifying application assets, data flows, trust boundaries, misuse scenarios, and security requirements.
- Promote awareness of OWASP Top 10 risks, secure coding, authentication and authorization, input validation, data protection, and secure configuration.
- Maintain documentation for application risks, remediation status, ownership, exceptions, timelines, and follow-up actions.
- Support secure design and security review discussions for new features, product changes, integrations, and higher-risk workflows.
- Collaborate with Engineering, Product, IT, and Security teams to improve secure-by-design practices.
- Provide limited support to SOC and security operations for application-related alerts, incidents, and evidence.
- Assist with vulnerability assessments, penetration testing, security policies and procedures, GRC tool onboarding, security event response, and threat hunting activities.
Requirements
- At least 2 years of experience in application security, information security, software security, security operations, software engineering, or a related technical area.
- Basic understanding of the software development lifecycle and application security across design, development, testing, release, and maintenance.
- Foundational knowledge of common application security vulnerabilities and OWASP Top 10 concepts.
- Basic understanding of software risk management, including severity, ownership, remediation timelines, exceptions, and follow-up.
- Awareness of threat modeling concepts including assets, data flows, trust boundaries, attack paths, misuse cases, and security requirements.
- Ability to collaborate with Engineering and Security teams, understand findings, document risks, and track remediation.
- Strong documentation skills, attention to detail, communication, and collaboration abilities.
- Bachelor’s degree in IT, Cybersecurity, Computer Science, Software Engineering, or equivalent practical experience.
- Preferred exposure to secure coding, software development collaboration, application design reviews, secure SDLC processes, software risk reviews, CI/CD pipelines, cloud security, SOC, incident response, vulnerability management, or security monitoring.
- Preferred entry-level certifications such as CompTIA Security+, ISC2 Certified in Cybersecurity, or similar security certifications.
Benefits
- Equity in the form of non-qualifying options.
- Internal mobility, cross-training, and opportunities for career progression.
- Onsite work arrangement, indicated by the #LI-onsite designation.