Match Score
Against your primary resumeLogin to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Protocol Intelligence
Data-driven signals on your job's competitivenessSpecialized AppSec role in Bangalore at a known employer yields moderately competitive candidate density.
Core application-security and DevSecOps skills transfer across industries, video domain knowledge is optional.
Explicit 7+ years plus mandatory AppSec tooling, cloud, CI/CD and secure-coding skills make filters strict.
Job Description
Structured overview of role & requirementsAbout This Role
Lead application security assessments and threat modelling for web, API, microservices, and cloud-native apps.
Implement and integrate AppSec tooling (SAST, DAST, SCA, secrets scanning) and security checks into CI/CD pipelines to enable secure SDLC.
Provide actionable vulnerability remediation guidance and track fixes in collaboration with engineering teams.
Minimum Requirements
7+ years of experience in Application Security, Product Security, DevSecOps, penetration testing, or secure software development.
Hands-on experience with SAST, DAST, SCA, secrets scanning, and web/API security testing tools such as Burp Suite or OWASP ZAP.
Experience with threat modelling (e.g., STRIDE) and source code review in languages like Java, C/C++, C#, Python, JavaScript/TypeScript, or Go.
Location: Bangalore, India (onsite or flexible working arrangements not explicitly detailed).
Ideal Candidate Profile
Experienced in integrating AppSec tooling and risk-based quality gates in Git-based CI/CD environments like Jenkins or GitHub Actions.
Comfortable communicating security risks, exploit scenarios, and mitigation strategies clearly to engineering teams.
Knowledge of cloud platforms (AWS, Azure, GCP), container security (Docker, Kubernetes), and modern identity/security standards (OAuth 2.0, OpenID Connect, SAML).
