Home
Jobs

Application Security Specialist

7 years

0 Lacs

Posted:9 hours ago| Platform: Linkedin logo

Apply

Work Mode

On-site

Job Type

Full Time

Job Description

Job Title: Application Security Specialist Location: India, Chennai Department: Cybersecurity Reports To: Head of Cybersecurity Job Purpose We are seeking a skilled and proactive Application Security Specialist to strengthen our secure software development processes, manage vulnerability remediation from various channels, including Bug Bounty programs and Security Scorecards, and support API security initiatives. The candidate will work closely with internal application managers, developers, external vendors, and the cybersecurity leadership to ensure a robust and audit-ready application security posture across the enterprise. Key Responsibilities Application Security Operations • Triage and analyze Bug Bounty submissions; coordinate with developers and PS managers for timely and effective remediation. • Act as a liaison with Bug Bounty hunters, maintaining portal updates and producing monthly bug statistics and ageing reports . • Collaborate with the Head of Cybersecurity to prioritize and drive risk-based remediation. Security Scorecard Oversight • Interpret findings from the security Scorecard platform, unpack mitigation recommendations, and ensure coordinated closure. • Regularly interact with MSSP team and PSL managers to maintain a score of > 90% across all tracked applications. • Deliver monthly scorecard analytics, including ageing and improvement metrics. Secure Software Development Lifecycle (SSDLC) • Review and recommend enhancements to current SSDLC processes, aligning with OWASP and Microsoft SDL standards. • Conduct training and awareness sessions for developers on secure coding in .NET , Java , and Azure DevOps pipelines. Application Security Scanning • Engage in vendor cadence calls to track Code scanning progress. • Support closure of findings related to ISO27001 pre-check and internal audits . API Security and WAF Integration • Guide developers in understanding and creating Swagger files for APIs. • Demonstrate creation of Swagger for 4–5 applications and oversee their integration with WAF for runtime protection. Required Qualifications Education • Bachelor’s Degree in Computer Science, Information Security, or a related discipline. Certifications (Preferred) • CEH / GWAPT / AZ-500 • ISO 27001 Internal Auditor (desirable) Experience • 4–7 years of experience in application security or secure development practices. • Hands-on with Veracode , OWASP , Swagger , and API Security Models . • Familiar with security audit cycles , especially ISO27001. • Previous exposure to security reporting , dashboards, and developer interaction. Key Competencies • Strong analytical skills in interpreting vulnerability descriptions and mitigation actions. • Excellent interpersonal skills for cross-functional coordination and vendor communication. • Proficient in technical documentation, reporting, and audit preparation . • Strong presentation and training ability for internal awareness sessions. Nice to Have • Knowledge of Azure cloud security controls • Experience integrating WAF rules with API definitions • Familiarity with CI/CD pipeline security and DevSecOps principles Show more Show less

Mock Interview

Practice Video Interview with JobPe AI

Start Security Interview Now

My Connections Bugbusterslabs

Download Chrome Extension (See your connection in the Bugbusterslabs )

chrome image
Download Now

RecommendedJobs for You

Hyderabad, Telangana, India

Kurnool, Andhra Pradesh, India