AdTechTalent
Engineering8 months agoOn-site

Zeta Global

Senior Application Security Engineer

application securitydevsecopssecure software developmentthreat modelingSASTDASTcloud securityCI/CDsecurity automationAI securityOAuth2OIDCJWTAWSGCPAzureDockerKubernetesSemgrepSonarQubeBurp SuiteZapTrivyReactNode.jsDjangoFastAPI

Key details

Salary

Not specified

Employment type

Full-time

Seniority

Senior

Years experience

3-5

Location

Bengaluru, India

Full job description

Seeking a Senior Application Security Engineer to strengthen application and platform security. Responsibilities include threat modeling, security code reviews, incident response, embedding security into SDLC, security automation, emerging threat monitoring, and security awareness. Requires 2-4 years experience in Application Security or DevSecOps, knowledge of OWASP Top 10, experience with React, Node.js, Django, FastAPI, securing APIs and authentication mechanisms, cloud platforms (AWS, GCP, Azure), containerization (Docker, Kubernetes), and security testing tools (Semgrep, SonarQube, Burp Suite, Zap, Trivy). Strong collaboration and communication skills needed.

What you'll do

  • Conduct threat modeling and security reviews for distributed cloud-native systems
  • Perform security code reviews, static/dynamic analysis (SAST/DAST), and dependency scanning
  • Participate in incident response exercises and red/blue team simulations
  • Assess third-party libraries, APIs, and vendor integrations for security compliance
  • Partner with developers and QA engineers to embed security testing into CI/CD pipelines
  • Review architecture and design documents to identify and mitigate risks early
  • Contribute to security automation initiatives and tooling to improve developer velocity
  • Support security checkpoints in release and deployment processes
  • Stay current on evolving security risks, frameworks, and attack vectors, including AI/ML-specific threats
  • Assist in designing and deploying proactive defense mechanisms across applications and data platforms
  • Support investigations and post-incident reviews to strengthen detection and prevention capabilities
  • Advocate secure coding and best practices through code reviews, workshops, and documentation
  • Contribute to internal security standards and playbooks
  • Collaborate closely with Engineering, DevOps, and Product teams to foster a security-first culture

Requirements

  • Bachelor’s degree in computer science, Cybersecurity, or related field, or equivalent experience
  • 2 - 4 years of experience in Application Security, DevSecOps, or Secure Software Development
  • Strong understanding of OWASP Top 10, SANS CWE Top 25, and general application threat modeling
  • Experience with frameworks and architectures such as React, Node.js, Django, or FastAPI
  • Knowledge of securing APIs, microservices, and authentication mechanisms (OAuth2, OIDC, JWT)
  • Experience with cloud platforms (AWS, GCP, Azure) and containerization (Docker, Kubernetes)
  • Working knowledge of security testing tools (e.g., Semgrep, SonarQube, Burp Suite, Zap, Trivy)
  • Solid collaboration and communication skills with cross-functional teams

Tech stack

ReactNode.jsDjangoFastAPIOAuth2OIDCJWTAWSGCPAzureDockerKubernetesSemgrepSonarQubeBurp SuiteZapTrivy

Apply now

Ready to take the next step in your career? Click the button below to continue to the application process.

Similar jobs

More roles worth a look

Related opportunities based on specialty and working model so candidates can keep momentum.