CrawlJobs Logo

Senior Application Security Engineer

https://www.hpe.com/ Logo

Hewlett Packard Enterprise

Location Icon

Location:
India, Bangalore

Category Icon
Category:
IT - Software Development

Job Type Icon

Contract Type:
Employment contract

Salary Icon

Salary:

Not provided

Job Description:

This role involves embedding security into software delivery pipelines, designing and implementing security controls, and ensuring code integrity across systems. You'll engage in secure code reviews, vulnerability management, and mentoring team members while collaborating as a trusted partner across departments.

Job Responsibility:

  • secure SDLC & DevSecOps integration
  • design and implement security controls for build and release pipelines (GitHub Actions, Jenkins, GitLab, Azure DevOps)
  • ensure code integrity via signing, artifact scanning, and build provenance
  • automate SAST, DAST, SCA, and container image scanning as part of the software delivery pipeline
  • identify and remediate misconfigurations in pipeline environments and access control
  • design, implement, and monitor WAF rules and API protections
  • perform API risk assessments
  • champion secure design patterns
  • conduct secure code reviews and support automation of testing pipelines
  • triage, prioritize, and track security issues identified in code, pipelines, and deployed environments
  • facilitate threat modeling sessions for applications, APIs, and pipeline workflows
  • expand security automation coverage, including API discovery, dependency scanning, SBOM generation, and secrets detection
  • mentor developers and DevOps engineers on secure pipeline and coding practices
  • act as a trusted partner to product, platform engineering, and DevOps leaders
  • translate security risk into business impact
  • collaborate with SOC/IR teams in response to software supply chain or pipeline compromises

Requirements:

  • 5–8+ years of experience in Application Security, Product Security, or Secure Software Development
  • hands-on experience securing software delivery pipelines (CI/CD) and source code repositories (GitHub, GitLab, Jenkins)
  • knowledge of supply chain security frameworks and controls (e.g., SLSA, NIST SSDF)
  • familiarity with secrets management, artifact signing (Sigstore, Cosign), and build integrity practices
  • hands-on experience with WAF tuning, API security controls, and vulnerability remediation
  • proficiency with one or more programming languages (Python, Java, Go, JavaScript/Node.js)
  • experience with SAST, DAST, SCA, and container image scanning tools
  • cloud security experience with AWS, Azure, or GCP
  • deep understanding of OWASP Top 10 (Web + API), CWE, and secure coding practices

Nice to have:

  • experience integrating SBOM generation and software composition analysis into software delivery pipelines
  • knowledge of runtime protection tools (API security, RASP, EDR for containers)
  • familiarity with GitOps, Infrastructure as Code (IaC) scanning (Terraform, CloudFormation), and policy-as-code solutions
  • experience responding to pipeline compromises or dependency poisoning incidents
  • relevant certifications: OSWE, CSSLP, GPCS, GIAC GWEB, GIAC Cloud Security Automation (GCSA)
What we offer:
  • comprehensive suite of benefits that supports physical, financial and emotional wellbeing
  • programs catered to helping you reach career goals
  • inclusive work environment

Additional Information:

Job Posted:
September 30, 2025

Employment Type:
Fulltime
Work Type:
Hybrid work
Job Link Share:
Welcome to CrawlJobs.com
Your Global Job Discovery Platform
At CrawlJobs.com, we simplify finding your next career opportunity by bringing job listings directly to you from all corners of the web. Using cutting-edge AI and web-crawling technologies, we gather and curate job offers from various sources across the globe, ensuring you have access to the most up-to-date job listings in one place.