





Niche AppSec role but mid-level, Bangalore location, and moderate employer brand increase applicant density.
AppSec skills transfer across industries but require domain security knowledge.
Explicit 5+ years and domain-specific AppSec tooling and skills required.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Lead comprehensive security testing of on-premises and cloud-based applications including web, mobile, and APIs using automated tools and manual techniques.
Conduct threat modeling and security assessments throughout the software development lifecycle (SDLC) across various environments (on-premises and cloud).
Provide remediation guidance, validate fixes, perform code reviews, and mentor junior security testers to improve the application security posture.
Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or related field.
Minimum 5 years of experience in application security testing or offensive security.
Hands-on experience with security testing tools (e.g., Fortify, Checkmarx, Veracode, Burp Suite Pro, OWASP ZAP, Snyk) and familiarity with cloud environments (AWS, Azure, or GCP).
Strong understanding of OWASP Top 10, CWE/SANS Top 25, secure SDLC and DevSecOps principles.
Experienced in testing applications hosted in multiple cloud platforms and knowledgeable about container security and microservices architecture.
Proficient in scripting languages (Python, Bash, PowerShell) for automation and custom testing.
Ability to lead security assessments end-to-end across SDLC and effectively collaborate with DevOps, Engineering, and Cloud teams.