Application Security (AppSec) / DevSecOps Engineer

Posted 2 Days Ago
Be an Early Applicant
Hiring Remotely in IND
Remote
Senior level
eCommerce • Marketing Tech • Design • SEO
The Role
Designs and integrates application security controls into CI/CD pipelines and DevSecOps frameworks. Responsibilities include managing SAST, DAST, and SCA tools; triaging vulnerabilities; leading threat modeling; securing containers and Kubernetes workloads; governing vulnerability dashboards and secret vaults; hardening infrastructure as code; and investigating application-layer security incidents.
Summary Generated by Built In

This is a remote position.

Application Security (AppSec) / DevSecOps Engineer

Job Details
  • Employment Type: Contract
  • Work Mode: Remote
  • Location: Offshore
  • Total Experience Required: 4 to 8 years
  • Relevant Experience Required: 3+ years of dedicated experience securing software development lifecycles (SDLC) and engineering DevSecOps pipelines
  • Mandatory Certification: Certified Application Security Engineer (CASE), Certified DevSecOps Professional (CDP), CSSLP, or CEH

Job Summary
We are seeking an experienced Application Security / DevSecOps Engineer to bake robust safety controls directly into our automated software delivery frameworks. The ideal candidate will bridge software engineering with security operations, implementing automated code testing gates, leading threat modeling workshops, and hardening application containers to identify and mitigate software vulnerabilities before code hits production.

Key Responsibilities
  • Design and integrate automated security testing gates directly into modern CI/CD pipelines (e.g., GitHub Actions, GitLab CI, Jenkins).
  • Configure and manage application scanning frameworks, orchestrating Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) tooling.
  • Triage and remediate software vulnerabilities, analyzing code flaws, open-source dependency risks, and secret exposure incidents alongside software development teams.
  • Lead comprehensive threat modeling assessments for new applications and architecture features, identifying attack surfaces and defining secure coding frameworks.
  • Govern application security infrastructure, managing centralized vulnerability aggregation dashboards (e.g., DefectDojo, SonarQube) and secret vaults (e.g., HashiCorp Vault, AWS Secrets Manager).
  • Secure containerized application workloads, auditing Dockerfile construction rules, verifying baseline machine images, and checking Kubernetes network isolation parameters.
  • Drive application layer incident investigations, analyzing malicious payload web requests, API tampering logs, and cross-site scripting (XSS) vectors to improve software perimeters.



Requirements
  • 4 to 8 years of core software engineering or cloud DevOps experience, with 3+ dedicated years actively designing, building, and deploying application safety frameworks.
  • Strong technical mastery of automated testing engines (e.g., Snyk, Checkmarx, Veracode, OWASP ZAP), container security paradigms, and infrastructure-as-code hardening.
  • Deep structural understanding of the OWASP Top 10 vulnerabilities, API security perimeters, modern secure coding standards, and cryptographic signing protocols.
  • Mandatory certification: CASE, CDP, CSSLP, or CEH.

Preferred Qualifications
  • Prior experience with software development in languages like Java, Python, JavaScript/Node.js, or Go.
  • Experience implementing automated code patching routines or managing runtime application self-protection (RASP) layers.





Skills Required

  • 4 to 8 years of core software engineering or cloud DevOps experience
  • At least 3 years of dedicated experience securing software development lifecycles and engineering DevSecOps pipelines
  • One mandatory certification: Certified Application Security Engineer, Certified DevSecOps Professional, CSSLP, or CEH
  • Strong mastery of automated security testing tools, container security, and infrastructure-as-code hardening
  • Strong understanding of OWASP Top 10 vulnerabilities, API security, secure coding standards, and cryptographic signing protocols
  • Experience with software development in Java, Python, JavaScript or Node.js, or Go
  • Experience implementing automated code patching or managing RASP layers
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
527 Employees
Year Founded: 2021

What We Do

FyerX is a Bengaluru-based digital marketing agency that helps businesses strengthen their online presence and generate leads and sales. Its services span branding, logo and brand-guideline development, photography and video production, UI/UX design, website development, social media marketing, search engine optimization, email marketing, ecommerce marketing, and digital advertising across platforms such as Google, Facebook, Instagram, and YouTube.

Similar Jobs

Remote or Hybrid
3 Locations
1100 Employees

Atlassian Logo Atlassian

Senior Principal Forward Deployed Engineer

Cloud • Information Technology • Productivity • Security • Software • App development • Automation
In-Office or Remote
Bengaluru, Bengaluru Urban, Karnataka, IND
11000 Employees

Atlassian Logo Atlassian

Principal Forward Deployed Engineer

Cloud • Information Technology • Productivity • Security • Software • App development • Automation
In-Office or Remote
Bengaluru, Bengaluru Urban, Karnataka, IND
11000 Employees

CrowdStrike Logo CrowdStrike

Full-stack Engineer

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
India
11000 Employees

Similar Companies Hiring

Scotch Thumbnail
Artificial Intelligence • eCommerce • Fintech • Payments • Retail • Software • Analytics
US
35 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account