onsite
Senior Application Security AppSec Engineer - Whitefield Careers Private Limited
Security Engineer
Senior Application Security Engineer leading secure code reviews, automated VAPT, and DevSecOps integration using Java, Python, Burp Suite, OWASP ZAP, SAST, and DAST to protect web, mobile, API, and backend services.
About the role
Key Responsibilities
- Conduct comprehensive vulnerability assessments and penetration tests on web, mobile, API, and backend services.
- Review and analyze application code in Java and Python to identify security flaws and recommend mitigations.
- Develop and maintain automation scripts for SAST, DAST, and SCA tools, integrating them into CI/CD pipelines.
- Collaborate with development teams to embed security best practices into the secure SDLC and DevSecOps workflows.
- Document findings, produce detailed reports, and present actionable recommendations to stakeholders.
Requirements
- Proven experience in Application Security, VAPT, and secure code review.
- Strong proficiency in Java and Python for code analysis and automation.
- Hands‑on expertise with Burp Suite, OWASP ZAP, SAST, DAST, and SCA tools.
- Deep understanding of authentication, authorization, and common web vulnerabilities.
- Experience integrating security testing into CI/CD pipelines and DevSecOps practices.
Skills
penetration testingjavapythonburp suite