Designs and integrates application security controls into CI/CD pipelines and DevSecOps frameworks. Responsibilities include managing SAST, DAST, and SCA tools; triaging vulnerabilities; leading threat modeling; securing containers and Kubernetes workloads; governing vulnerability dashboards and secret vaults; hardening infrastructure as code; and investigating application-layer security incidents.
This is a remote position.
Application Security (AppSec) / DevSecOps Engineer
Job Details
- Employment Type: Contract
- Work Mode: Remote
- Location: Offshore
- Total Experience Required: 4 to 8 years
- Relevant Experience Required: 3+ years of dedicated experience securing software development lifecycles (SDLC) and engineering DevSecOps pipelines
- Mandatory Certification: Certified Application Security Engineer (CASE), Certified DevSecOps Professional (CDP), CSSLP, or CEH
Job Summary
We are seeking an experienced Application Security / DevSecOps Engineer to bake robust safety controls directly into our automated software delivery frameworks. The ideal candidate will bridge software engineering with security operations, implementing automated code testing gates, leading threat modeling workshops, and hardening application containers to identify and mitigate software vulnerabilities before code hits production.
Key Responsibilities
- Design and integrate automated security testing gates directly into modern CI/CD pipelines (e.g., GitHub Actions, GitLab CI, Jenkins).
- Configure and manage application scanning frameworks, orchestrating Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) tooling.
- Triage and remediate software vulnerabilities, analyzing code flaws, open-source dependency risks, and secret exposure incidents alongside software development teams.
- Lead comprehensive threat modeling assessments for new applications and architecture features, identifying attack surfaces and defining secure coding frameworks.
- Govern application security infrastructure, managing centralized vulnerability aggregation dashboards (e.g., DefectDojo, SonarQube) and secret vaults (e.g., HashiCorp Vault, AWS Secrets Manager).
- Secure containerized application workloads, auditing Dockerfile construction rules, verifying baseline machine images, and checking Kubernetes network isolation parameters.
- Drive application layer incident investigations, analyzing malicious payload web requests, API tampering logs, and cross-site scripting (XSS) vectors to improve software perimeters.
Requirements
- 4 to 8 years of core software engineering or cloud DevOps experience, with 3+ dedicated years actively designing, building, and deploying application safety frameworks.
- Strong technical mastery of automated testing engines (e.g., Snyk, Checkmarx, Veracode, OWASP ZAP), container security paradigms, and infrastructure-as-code hardening.
- Deep structural understanding of the OWASP Top 10 vulnerabilities, API security perimeters, modern secure coding standards, and cryptographic signing protocols.
- Mandatory certification: CASE, CDP, CSSLP, or CEH.
Preferred Qualifications
- Prior experience with software development in languages like Java, Python, JavaScript/Node.js, or Go.
- Experience implementing automated code patching routines or managing runtime application self-protection (RASP) layers.
Similar Jobs
Artificial Intelligence • Productivity • Software • Automation
Leads Zapier’s India entity as statutory Board Director and General Manager. Owns local operations, governance, legal, tax, audit, transfer pricing, regulatory compliance, risk management, vendor relationships, and people decisions. Serves as the bridge between India-based teams and global leadership, translating strategy into execution and establishing operating rhythms for a fully remote workforce. Partners with Deloitte, HR, finance, auditors, regulators, and global executives while overseeing hiring, performance, compensation, employee relations, and compliance with Indian labor requirements.
Artificial Intelligence • Big Data • Cloud • Information Technology • Software • Big Data Analytics • Automation
Designs and optimizes scalable data ingestion pipelines for product telemetry and enterprise business data. Builds automated pipelines using Fivetran, Python, APIs, S3 lakehouse architectures, Kafka, Spark, and Snowflake. Applies advanced SQL, incremental loading, CDC, micro-batching, and rate-limit handling to support reliable, analytics-ready datasets. Implements CI/CD and DevOps practices, monitors pipeline performance, and partners with analysts and platform teams to rapidly deliver data solutions.
Top Skills:
Amazon S3SparkBulk ApisCdcCi/CdDevOpsFivetranKafkaPythonSnowflakeSQLVersion Control
Financial Services
Reviews marketing, sales, and promotional communications for accuracy, regulatory compliance, clarity, balance, and risk. Applies EMEA requirements, including ESMA, CSSF, and FCA expectations, while partnering with Marketing, Sales, Legal, Compliance, Audit, and Controls teams. Manages reviews and escalations, educates colleagues on communications standards, and improves control processes and efficiency across markets.
Top Skills:
CssfEsmaFca
What you need to know about the Delhi Tech Scene
Delhi, India's capital city, is a place where tradition and progress co-exist. While Old Delhi is known for its rich history and bustling markets, New Delhi is defined by its modern architecture. It's clear the region places a strong emphasis on preserving its cultural heritage while embracing technological advancements, particularly in artificial intelligence, which plays a central role in shaping the city's tech landscape, fueled by investments in research and development.



