# Application Security Engineer

> Weekday AI · Bengaluru, India · Full-time · Posted 2026-07-24

**Salary:** INR 1,800,000–2,500,000

**Workplace:** on_site

**Department:** Weekday's Client via platform

## Description

**This role is for one of the Weekday's clients**

**Salary range: Rs 1800000 - Rs 2500000 (ie INR 18 - 25 LPA)**

Min Experience: 4+ years

Location: Bengaluru  
JobType: full-time

We are looking for a highly skilled **Application Security Engineer** with **4–9 years of experience** to strengthen the security posture of modern software applications and development pipelines. The ideal candidate will have deep expertise in **Application Security** and **Cyber Security**, with hands-on experience identifying, assessing, and mitigating security vulnerabilities across the software development lifecycle (SDLC).

As an Application Security Engineer, you will work closely with software engineering, DevOps, cloud, and product teams to embed security into every phase of application development. You will perform security assessments, conduct code reviews, automate security testing, and drive secure coding practices to ensure applications remain resilient against evolving cyber threats.

## Requirements

### Key Responsibilities

-   Design, implement, and maintain application security programs across web, mobile, APIs, and cloud-native applications.
-   Perform secure code reviews and identify vulnerabilities such as SQL Injection, Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), Remote Code Execution (RCE), authentication flaws, and business logic vulnerabilities.
-   Conduct application security assessments, threat modeling, and architecture reviews during the software development lifecycle.
-   Integrate security testing tools including SAST, DAST, SCA, and container security solutions into CI/CD pipelines.
-   Collaborate with engineering teams to remediate security findings and ensure timely resolution of identified risks.
-   Perform penetration testing and vulnerability assessments for applications, APIs, and supporting infrastructure.
-   Develop secure coding standards, security guidelines, and best practices for engineering teams.
-   Monitor emerging cyber threats, security advisories, and vulnerabilities to proactively strengthen application defenses.
-   Support incident response by analyzing application-related security events and assisting with remediation efforts.
-   Work with cloud security teams to secure workloads deployed on AWS, Azure, or Google Cloud Platform.
-   Create security documentation, reports, and metrics to track application security posture and compliance.
-   Promote a security-first culture through developer training and security awareness initiatives.

### Required Skills & Qualifications

-   Bachelor's degree in Computer Science, Information Security, Cyber Security, or a related technical discipline.
-   **4–9 years of professional experience** in Application Security, Cyber Security, or Product Security.
-   Strong understanding of secure software development lifecycle (SSDLC) and secure coding principles.
-   Hands-on experience with application security testing methodologies and vulnerability management.
-   Expertise in common security standards including **OWASP Top 10**, CWE, CVSS, and secure authentication mechanisms.
-   Experience with security tools such as Burp Suite, OWASP ZAP, Checkmarx, Veracode, Fortify, Snyk, SonarQube, or similar platforms.
-   Knowledge of web technologies, REST APIs, microservices, containers, and Kubernetes security.
-   Familiarity with cloud security concepts across AWS, Azure, or GCP environments.
-   Strong understanding of encryption, identity and access management, OAuth, JWT, TLS, and secure API design.
-   Experience working with CI/CD pipelines and integrating automated security controls.
-   Knowledge of scripting or programming languages such as Python, Java, JavaScript, Go, or Bash is highly desirable.
-   Excellent analytical, problem-solving, and communication skills with the ability to explain security risks to both technical and non-technical stakeholders.

### Preferred Qualifications

-   Industry certifications such as **CSSLP, CEH, OSCP, CISSP, GWEB, GWAPT, or Security+**.
-   Experience in DevSecOps practices and security automation.
-   Familiarity with compliance frameworks such as ISO 27001, SOC 2, PCI DSS, or GDPR.
-   Experience securing cloud-native applications, containers, and Kubernetes environments.
-   Exposure to threat intelligence, attack simulation, and red team/blue team exercises.

## Apply

[Apply at Weekday AI](https://apply.workable.com/weekday-1/j/88B94A6217/apply)

---
Powered by [Workable](https://www.workable.com)
