ApplySarthi

Sr. Application Security Engineer

Jobgether

Tailor my CV for this job, freeView job and applyYour CV rewritten for this role, from your real experience. Sign in with Google, nothing to install.

Got this interview? Our apps help you get the job.

Skills named in this job

Read from the description itself, not inferred.

This role on the market

1,220 open application roles across 211 companies are on ApplySarthi right now, most of them in Bengaluru (99), Hyderabad (63), Delhi NCR (47).

What application roles keep asking for: Python (15%), Java (13%) — counted across their open postings here.

Application Security Engineer jobs in the United States · Remote Application Security Engineer jobs · AWS jobs · CI/CD jobs · Java jobs · Kubernetes jobs

Jobgether has 4,273 open roles listed here.

Counted across 14 company job boards, updated as roles open and close.

Preparing for this interview

Interviews for application roles keep coming back to Python, Java. Practise those questions before you sit with Jobgether.

Questions you are likely to be asked

  1. Why do you want to join Jobgether?
  2. What is your experience with AWS? Tell me one thing you learned the hard way.
  3. How do you decide what to monitor, and what should wake someone up at night?
  4. How would you cut the cloud bill of a system without hurting it?
  5. How do you keep secrets and access safe in your infrastructure?

Prep Sarthi gives you a free mock interview: an AI interviewer asks you questions like these out loud, from your own CV and this job, and shows your score and your weakest answer.

Practise the Sr. Application Security Engineer at Jobgether interview free →

Accountabilities:: As a Sr. Application Security Engineer , you will serve as a hands-on technical authority for application security, partnering closely with Engineering and Security teams to identify risks, drive remediation, and embed security into development practices. Perform hands-on security analysis of applications, APIs, services, and supporting components. Conduct secure code reviews across Java, Python, and Go codebases, identifying root causes and practical remediation paths. Reproduce and validate vulnerabilities independently, assessing exploitability, reachability, exposure, data sensitivity, business criticality, and compensating controls. Own vulnerability remediation from discovery through prioritization, remediation, retesting, and closure. Maintain remediation SLAs and escalate unresolved Critical and High findings when appropriate. Develop reusable secure coding patterns, preventative controls, and automation to reduce recurring vulnerabilities. Mature security gates and review checkpoints across architecture, design, sprint, and release processes. Integrate preventative security controls into developer workflows and CI/CD pipelines. Configure, operate, and tune SAST, DAST, and SCA tooling to deliver actionable security feedback. Assess software dependency and supply-chain risks using application context, reachability, exploitability, and remediation options. Threat-model new features and significant architectural changes using STRIDE, PASTA, or equivalent methodologies. Review authentication, authorization, OAuth 2.0/OIDC, mTLS, rate limiting, data flows, trust boundaries, cryptographic controls, and abuse scenarios. Evaluate application security across AWS, Kubernetes/EKS, containers, Linux/Ubuntu, distributed services, and cloud-native architectures. Partner with Engineering as a technical advisor, providing clear and actionable remediation guidance. Deliver secure-coding guidance and training based on real vulnerabilities and recurring security patterns. Help establish and mature a Security Champions program across development teams. Create security runbooks, standards, and reusable development patterns that teams can apply independently. Validate application and API vulnerabilities through hands-on testing and coordinate external penetration-testing engagements. Drive first-year improvements in vulnerability remediation, threat modeling, dependency security, secure development practices, and the overall effectiveness of the Application Security function. Requirements The role requires deep Application Security expertise combined with strong software engineering capabilities, hands-on vulnerability analysis, and the ability to collaborate effectively with technical and engineering leadership. 7+ years of progressive experience in Application Security, Product Security, security-focused software engineering, or a closely related field. Demonstrated senior-level ownership of Application Security initiatives and vulnerability remediation. Strong hands-on coding and secure code review experience with Java, Python, and Go. Ability to read, debug, and reason about production application code and communicate technical findings clearly to software engineers. Proven ability to reproduce vulnerabilities, trace findings to root cause, assess exploitability and reachability, and validate remediation. Hands-on experience with SAST, DAST, and SCA tools and integrating security testing into engineering workflows. Strong knowledge of software dependency and supply-chain security. Experience prioritizing vulnerabilities based on application and business context rather than scanner severity alone. Strong understanding of the OWASP Top 10 and OWASP API Security risks. Experience with threat modeling using STRIDE, PASTA, or similar methodologies. Experience securing cloud-native applications running in AWS and Kubernetes/EKS environments. Strong communication and collaboration skills, with the ability to influence developers, architects, and engineering leadership. Hands-on application and API penetration-testing experience is preferred. Experience in financial services, fintech, identity, fraud, regulated SaaS, or other highly regulated environments is a plus. Familiarity with PCI-DSS application security requirements is preferred. Experience building or leading a Security Champions program is a plus. Experience developing Application Security automation or internal security tooling is desirable. OSCP, GWEB, CSSLP, or a similar technical security certification is preferred. Benefits Salary: $130,000–$190,000 per year, with individual compensation varying based on experience, professional competencies, and geographic differentials. Remote flexibility: A virtual-first working environment designed to support remote work from a home office as well as in-person collaboration. Career growth: Opportunities for professional development, meaningful technical ownership, and work in an innovative, collaborative environment. Healthcare: Universal, supplemental, or private healthcare plan options depending on geographic location. Financial future: Retirement or pension contributions and participation in a stock plan. Income protection: Life event and disability coverage. Paid time off: Generous annual leave, company holidays, and volunteer time off. Learning: E-learning resources, tuition reimbursement, and opportunities to participate in hackathons. Home office: Home office setup allowance. Additional benefits: Optional benefits may include pet insurance, identity theft protection, and legal assistance. Technical scope: Exposure to internet-facing financial software, complex API integrations, cloud-native environments, and a dual US/EU regulatory context. Visibility and ownership: Direct collaboration with senior Security and Engineering leadership and meaningful ownership of Application Security initiatives.

Match this job to your CV

ApplySarthi scores your CV against this role, shows the skills you are missing, and writes a tailored version for the application.

Check my match →

Similar open roles

Need answers during your interview? Try Live Sarthi.

Live Sarthi, an Interview Sarthi app, shows answer suggestions during the call.

Try Live Sarthi free →

A Windows app, from the same team as ApplySarthi.

Listed on lever · posted 2026-10-02. ApplySarthi collects openings and links to application pages; the role is advertised by Jobgether, not by us.