Application Security Specialist Engineer - InfoSec
Waters View all jobs
- Bangalore, Karnataka
- Permanent
- Full-time
- Perform vulnerability triage, validation, prioritization, and routing across SAST, SCA, DAST, IaC, secrets, and container scanning tools.
- Administer, tune, and maintain application security tooling ecosystems, ensuring full CI/CD integration and high-fidelity results.
- Create, track, and manage remediation tickets with engineering teams, enforcing SLAs and structured workflows.
- Maintain accurate application and service inventories, including classification by criticality, exposure, and data sensitivity.
- Contextualize vulnerabilities with business impact, exploitability, compensating controls, and asset risk profiles.
- Develop dashboards and metrics for vulnerability posture, aging, SLA compliance, and executive reporting.
- Conduct trend analysis to identify systemic issues, recurring vulnerabilities, and areas requiring structural improvements.
- Build automation and orchestration scripts to streamline triage, ticketing, enrichment, and reporting workflows.
- Bachelor's degree in Computer Science, Cybersecurity, or equivalent practical experience.
- 3–5+ years of experience in Application Security, Product Security, or Vulnerability Management.
- Direct hands-on experience with SAST, SCA, DAST, IaC, container security, or secrets scanning platforms.
- Strong understanding of vulnerability classes, CVSS scoring, and exploitability factors.
- Proficiency in scripting or programming languages (Python preferred; Go, JavaScript, or similar acceptable).
- Experience working with CI/CD systems and integrating security tools into developer workflows.
- Familiarity with cloud platforms (AWS, Azure, or GCP) and modern application architectures.
- Strong analytical, investigative, and problem-solving skills with a high attention to detail.
- Ability to work collaboratively in a fast-paced global engineering environment.
- Experience supporting large-scale, multi-business-unit vulnerability management programs.
- Expertise in Kubernetes, container security platforms, and cloud-native scanning tools.
- Experience building dashboards using tools such as PowerBI, Tableau, Grafana, or Looker.
- Knowledge of regulatory frameworks such as NIST CSF, ISO 27001, SOC 2, and EO 14028 requirements.
- Familiarity with software composition analysis, supply chain security, and SBOM management.
- Hands-on experience building security automation using APIs, webhooks, serverless functions, or workflow engines.