Engineer (Application Security)
dunnhumby View all jobs
- Gurgaon, Haryana
- Permanent
- Full-time
- Integrate security best practices into the SDLC and operate, tune, and maintain AppSec tooling (SAST, DAST, SCA).
- Provide secure design guidance, perform secure code reviews, reproduce issues, propose fixes, and validate remediations with developers.
- Embed security checks in CI/CD for container images, IaC, and Helm charts & contribute to runtime protections such as admission controls, policy-as-code, scanning, and drift detection.
- Promote secure infrastructure configurations and Kubernetes defaults (RBAC, network policies, PodSecurity, secrets handling, image provenance).
- Ensure CI/CD pipelines have robust, effective security coverage and manage exceptions & risk workflows.
- Maintain a consolidated vulnerability backlog with clear ownership and SLA tracking and build automated reporting using tools like Power BI or Excel/Pandas.
- Develop secure coding standards and practical developer guidance.
- Run secure development forums, build and maintain strong relationship with engineering teams and drive application vulnerability management through engagements and reporting.
- Act as a trusted advisor to both engineers and leadership - identifying and communicating risk clearly and persuasively.