Solventum Logo

Solventum

Application Security Engineer

Posted Yesterday
Be an Early Applicant
Remote
Hiring Remotely in Karpura, Bangalore, Karnataka, IND
Mid level
Remote
Hiring Remotely in Karpura, Bangalore, Karnataka, IND
Mid level
Administer and enhance application security tools, execute and tune DAST scans for web applications and APIs, validate and prioritize vulnerabilities, eliminate false positives, and partner with development teams on remediation. Maintain vulnerability records, verify fixes, support compliance with security standards, and build solutions that present vulnerability and compliance data to leadership.
The summary above was generated by AI

At Solventum, we improve lives by helping healthcare professionals do their best work. Join a team using innovation and insight to make a real impact on the future of healthcare. All roles listed are with Solventum, and we’re committed to protecting your personal information—learn more in our Privacy Policy: https://www.solventum.com/en-us/home/legal/website-privacy-statement/applicant-privacy/

Job Description:

Application Security Engineer


3M Health Care is now Solventum


At Solventum, we enable better, smarter, safer healthcare to improve lives. As a new company with a long legacy of creating breakthrough solutions for our customers’ toughest challenges, we pioneer game-changing innovations at the intersection of health, material and data science that change patients' lives for the better while enabling healthcare professionals to perform at their best. Because people, and their wellbeing, are at the heart of every scientific advancement we pursue.


We partner closely with the brightest minds in healthcare to ensure that every solution we create melds the latest technology with compassion and empathy. Because at Solventum, we never stop solving for you.


The Impact You’ll Make in this Role
 

Joining a team of cybersecurity professionals motivated to secure Solventum's healthcare information systems and the personal health information of our clients and their patients.


  • Operating and enhancing application security tool environments.
  • Authoring automation scripts for reoccurring tasks (Python preferred)
  • Setup and execute authenticated and unauthenticated dynamic application security testing (DAST) scans against web applications and APIs using approved tools.
  • Manage scan scheduling, configuration, and coverage across application security tool environments.
  • Tune scanning profiles to reduce false positives and improve detection accuracy.
  • Ensure DAST scanning aligns with release cycles and risk-based scanning requirements
  • Validate DAST findings to confirm exploitability and business impact.
  • Categorize vulnerabilities using industry standards (e.g., OWASP Top 10).
  • Prioritize findings based on risk, application criticality, and exposure.
  • Eliminate false positives and duplicate findings prior to developer handoff.
  • Partner with development and platform teams to explain DAST findings and remediation expectations.
  • Track remediation progress and verify fixes through re‑scanning or targeted validation.
  • Maintain accurate vulnerability records in enterprise tracking systems.
  • Escalate overdue or high‑risk vulnerabilities in accordance with policy.
  • Working with application teams to validate that software applications meet security guidelines and compliance standards such as HIPPA, SOC II, GDPR, NIST 800-53, etc.
  • Building solutions that collect and present vulnerability and compliance data to Solventum’s leadership.

Your skills & expertise (Minimum qualifications):


  • Bachelor’s Degree & 3-6 years of experience
  • Experience administering Qualys VM or App sec
  • Experience in working across multiple teams and disciplines
  • Strong attention to detail and analytical skills.
  • Risk-based prioritization and sound judgment.
  • Knowledgeable with AWS or Azure cloud environments
  • Familiarity with best practice software security requirements in industry standard compliance programs (NIST, HITRUST, FedRAMP, etc.)
  • Experience developing or testing RESTful APIs with an understanding of Postman and/or Swagger files
  • Strong communication skills, ability to work independently or collaborate with application teams

Additional qualifications (Nice to have):

  • Experience administering Qualys or WebInspect vulnerability management and application security modules

Work location:

  • Hybrid – India Only

Travel: May include up to 10%  


Relocation Assistance: Is not authorized. 


Supporting Your Well-being 

Solventum offers many programs to help you live your best life – both physically and financially. To ensure competitive pay and benefits, Solventum regularly benchmarks with other companies that are comparable in size and scope. 


Diversity & Inclusion  

(*) We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, gender, sexual orientation, age, civil status, disability, family status, or membership of the travelling community.  


   

Solventum is committed to maintaining the highest standards of integrity and professionalism in our recruitment process.  Applicants must remain alert to fraudulent job postings and recruitment schemes that falsely claim to represent Solventum and seek to exploit job seekers.

Please note that all email communications from Solventum regarding job opportunities with the company will be from an email with a domain of @solventum.com. Be wary of unsolicited emails or messages regarding Solventum job opportunities from emails with other email domains.

Please note: your application may not be considered if you do not provide your education and work history, either by: 1) uploading a resume, or 2) entering the information into the application fields directly.

Solventum Global Terms of Use and Privacy Statement

Carefully read these Terms of Use before using this website. Your access to and use of this website and application for a job at Solventum are conditioned on your acceptance and compliance with these terms.

Please access the linked document by clicking here. Before submitting your application you will be asked to confirm your agreement with the
terms.

Similar Jobs

2 Days Ago
Remote
India
Senior level
Senior level
Edtech • Information Technology • Software
Identify, triage, and remediate vulnerabilities in web applications and proprietary software. Refactor .NET/C# code, implement secure coding standards, conduct code reviews, support secure SDLC practices, and assess SAST, DAST, penetration testing, and bug bounty findings. Monitor emerging threats and OWASP Top 10 updates while supporting compliance with FERPA, COPPA, GDPR, UK GDPR, and other data protection standards. The role is fully remote but requires permanent residency in India and specified IST working hours.
Top Skills: .NetAWSAzureC#DastGCPObject-Relational Mapping (Orm)Owasp Top 10Sast
16 Days Ago
Remote
India
Junior
Junior
Greentech • Energy • Solar • Renewable Energy
Own application security across mobile apps, APIs, microservices, cloud infrastructure, AI products, and third-party integrations. Responsibilities include threat modeling, architecture reviews, penetration testing, secure coding, vulnerability management, incident response, SSDLC onboarding, CI/CD security tool integration, cloud hardening, developer training, and communicating risk. The role also assesses AI and LLM security risks and develops production guardrails and automation.
Top Skills: AndroidAWSBashCi/CdCloudflare WafDastDigitaloceanDockerFirebaseGoogle Cloud PlatformIamIastIstioJwtKeycloakKubernetesOauth2OidcPythonRest ApisSastSca
17 Days Ago
Remote
India
Entry level
Entry level
Security • Cybersecurity
Curate, triage, validate, and assess vulnerability submissions for managed bug bounty programs. Evaluate validity, accuracy, and severity; communicate with clients and security researchers; escalate critical vulnerabilities through incident response; and contribute to tooling that improves the triage and validation process. The role requires strong application security knowledge, especially OWASP Top Ten vulnerabilities, and proficiency with security testing tools.
Top Skills: Burp SuiteKali LinuxNmapOwasp Top TenSqlmap

What you need to know about the Delhi Tech Scene

Delhi, India's capital city, is a place where tradition and progress co-exist. While Old Delhi is known for its rich history and bustling markets, New Delhi is defined by its modern architecture. It's clear the region places a strong emphasis on preserving its cultural heritage while embracing technological advancements, particularly in artificial intelligence, which plays a central role in shaping the city's tech landscape, fueled by investments in research and development.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account