Skip to content

Open nowPosted 41 hours agoWe saw it 74 min after it went up

Senior Application Security Engineer

Jobgether4,506 open roles

Where
India
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Application Security EngineerJobgether · India
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Jobgether's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.2% of postings close within 7 days. Measured by our own scanner across the market. Jobgether postings stay open a median of 6 days.

Share of postings closed within
  1. 1.9%1 day
  2. 3.8%3 days
  3. 8.2%7 days
  4. 15.2%14 days
  5. 34.1%30 days
This job: posted 41 hours ago

Jobgether median: 6 days open

The posting

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Application Security Engineer based in India.

This is a senior individual contributor role embedded directly within product engineering and focused on strengthening security throughout the software development lifecycle. You will help secure enterprise products that are deployed across customer-managed environments as well as hosted offerings. The role combines threat modeling, secure coding, vulnerability management, security testing, and software supply-chain security. You will work directly with engineers and product leaders to identify risks early and turn security requirements into practical, scalable solutions. Your work will influence what gets designed, developed, tested, released, and ultimately deployed by customers. The environment is technically hands-on, globally distributed, and focused on measurable security improvements rather than simply identifying issues. This is an opportunity to shape application security practices across multiple product lines while remaining close to production code and engineering teams.

Accountabilities

  • Lead threat modeling for critical application areas, including authentication and session management, privilege escalation, integrations, tenant isolation, cryptography, and secrets management.
  • Define security requirements early in the architecture and development process, working directly with engineering teams to address risks before release.
  • Assess security risks and provide clear recommendations to product and engineering leadership to support informed release and risk-acceptance decisions.
  • Contribute directly to product repositories by reviewing and implementing security fixes, dependency updates, and code-level remediation in collaboration with development teams.
  • Own and improve static application security testing, dynamic testing, dependency scanning, and related security tooling across product lines.
  • Tune security tools to improve signal quality, reduce unnecessary disruption, and ensure findings reach the teams responsible for remediation.
  • Promote secure coding practices across large C#/.NET and Java codebases through reusable patterns, libraries, reference implementations, and targeted code reviews.
  • Establish appropriate security review practices for AI-assisted software development, including assessment of AI-generated code and automated remediation workflows.
  • Lead product vulnerability response from intake through triage, remediation, coordinated disclosure, CVE management, and customer-facing security advisories.
  • Analyze penetration-testing and bug-bounty findings to identify recurring weaknesses and implement systemic controls that prevent similar vulnerabilities.
  • Own software composition analysis and SBOM generation, including software provenance and licensing information required by customers and internal stakeholders.
  • Maintain security evidence that can support customer questionnaires, security reviews, certifications, and other assurance activities.
  • Collaborate with engineering, product, legal, and other stakeholders to continuously strengthen application security across the product portfolio.
  • 6+ years of experience in software engineering or security, including at least 3 years focused on application or product security; equivalent professional depth may be considered.
  • Demonstrated application security experience with products that customers deploy and operate within their own environments.
  • Strong production-level programming skills in C# and .NET, with sufficient experience in Java to review and contribute to Java-based applications.
  • Recent hands-on experience with AI-assisted development or AI-enabled security tooling, ideally within the last six months.
  • Strong understanding of threat modeling and the ability to collaborate with engineering teams during the design stage.
  • Experience with static analysis, dynamic application testing, software composition analysis, dependency scanning, and security tooling optimization.
  • Knowledge of identity and authentication technologies and protocols such as OAuth, OIDC, SAML, and SCIM.
  • Experience with coordinated vulnerability disclosure, vulnerability triage, CVE processes, and customer-facing security advisories.
  • Strong secure code review capabilities across web applications and APIs.
  • Understanding of software supply-chain security, SBOM standards, dependency management, and license compliance.
  • Experience with cryptographic reviews, security champion programs, PCI DSS, FedRAMP, or similar security frameworks is advantageous.
  • Ability to communicate complex security risks clearly to technical and non-technical stakeholders and influence senior engineers effectively.
  • Strong analytical and problem-solving skills, with the judgment to prioritize security risks according to business and technical impact.
  • Ability to work independently across multiple product teams while collaborating effectively within a globally distributed organization.
  • Prior experience as a product or software engineer is a plus.
  • Remote working opportunity based in India.
  • Senior-level ownership across multiple product lines and application security initiatives.
  • Direct collaboration with engineering and product leadership.
  • Opportunity to influence security architecture, secure development practices, and vulnerability management at scale.
  • Hands-on exposure to modern application security, AI-assisted development, software supply-chain security, and cloud-hosted products.
  • Globally distributed and collaborative working environment.
  • Opportunities for professional development, learning, and career growth.
  • Employee-focused health and wellbeing programs.
  • Inclusive and equal-opportunity workplace committed to diversity and respect.

How Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

Why Apply Through Jobgether?

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Jobgether's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Jobgether's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Jobgether's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.