Security Compliance & Application Security Engineer

3 - 5 years

0 - 1 Lacs

Posted:4 days ago| Platform: Naukri logo

Apply

Work Mode

Remote

Job Type

Full Time

Job Description

Security Compliance & Application Security Engineer

  • Implement and support compliance with:
    • SOC Type 1 & Type 2

    • ISO 27001

    • PCI DSS

    • HIPAA

    • GDPR


  • Translate compliance requirements into technical security controls
  • Support audits through evidence collection, control testing, and remediation tracking
  • Maintain security policies, procedures, and compliance documentation

Application Security & Penetration Testing

  • Perform

    application-level penetration testing

    for web applications, including:
    • Authentication & authorization
    • Session management
    • Business logic vulnerabilities

  • Conduct security testing beyond APIs, covering full application flows and data handling
  • Validate security implementations:
    • OAuth 2.0

    • HMAC SHA-512

    • TLS 1.2+


  • Coordinate and review third-party penetration testing and validate remediation

Collaboration

  • Work with engineering and DevOps teams to integrate security into CI/CD
  • Provide secure coding guidance and remediation support
  • Participate in application security incident response when required

Required Skills & Experience

  • 35 years of hands-on experience in

    application security, penetration testing, and security compliance

  • Direct involvement with all of the following frameworks:

    SOC Type 1 & 2, ISO 27001, PCI DSS, HIPAA, and GDPR

  • Strong experience with

    manual web application penetration testing

  • Knowledge of

    OWASP Top 10

  • Experience with tools such as

    Burp Suite, OWASP ZAP

    , or similar
  • Understanding of cloud environments (AWS, Azure, or GCP)
  • Ability to clearly document findings and communicate with technical teams

Preferred Qualifications

  • Certifications:

    OSCP, CEH, CISSP, CISA, ISO 27001 Lead Implementer

  • Experience with SAST/DAST tools and CI/CD integration
  • Background in SaaS, fintech, or healthcare environments

Role Clarity

  • Hands-on compliance and application security role
  • Includes application-level and API penetration testing
  • Not a CISO or executive role
  • Not a policy-only position

Mock Interview

Practice Video Interview with JobPe AI

Start DevOps Interview
cta

Start Your Job Search Today

Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.

Job Application AI Bot

Job Application AI Bot

Apply to 20+ Portals in one click

Download Now

Download the Mobile App

Instantly access job listings, apply easily, and track applications.

coding practice

Enhance Your Skills

Practice coding challenges to boost your skills

Start Practicing Now

RecommendedJobs for You

hyderabad, bengaluru, delhi / ncr