Source description
About the role
Join ABC Fitness and become part of a culture thats as ambitious as it is authentic. Lets transform the future of fitnesstogether! Our Values Best Life We believe great work begins with great people. Thats why our culture is built on respect, trust, and belonging. We create an inclusive environment where every team member can bring their authentic self to workbecause diverse perspectives drive innovation and meaningful impact. Growth Mindset We are doers, thinkers, and dreamers. At ABC Fitness, your growth is our investment. Through continuous learning, mentorship, and professional development opportunities, we empower you to reach new heightspersonally and professionally. One Team From day one, youll be part of a team that collaborates, celebrates, and cares. We move fast, support one another, and have fun along the way. Because when you thrive, we all thrive. As a Principal Application Security Engineer, you will drive secure application development and vulnerability remediation across our AWS and Azure environments by embedding security into systems, CI/CD pipelines, and developer workflows. This role focuses on building scalable security practices, automation, and guardrails that enable engineering teams to ship securely. This is not an offensive security or red-team role. Instead, you will partner closely with product and engineering teams to prevent vulnerabilities, improve secure design, and drive remediation through engineering and process improvements. You will collaborate with Product, Engineering, Cloud Operations, IT, Legal, and Compliance partners to ensure security is integrated throughout the software development lifecycle and aligned with regulatory and business requirements. WHAT YOULL DO: Own vulnerability management workflows in cloud environments, including scanning, triage, prioritization, and remediation in partnership with engineering teams. Integrate and optimize SAST, DAST, and SCA tooling within CI/CD pipelines and developer workflows. Partner with development teams to improve secure coding practices and resolve vulnerabilities through engineering solutions. Contribute to application and infrastructure threat modeling to identify and mitigate risks early in the design process. Apply Kubernetes and container security best practices to ensure secure deployment and operation of services. Evaluate and advise on security considerations for AI-enabled applications and large language models (LLMs). Define and maintain application security standards, technical controls, and secure development guidelines. Partner with external penetration testing vendors, including scoping, coordinating testing, and driving remediation of findings. Collaborate with cloud operations and SIEM teams to improve security logging, monitoring, and alerting strategies. Build and automate security controls and guardrails that reduce recurring vulnerabilities and improve developer experience. Provide training, documentation, and knowledge sharing to development teams on application security tools and best practices. Stay current on emerging threats, security trends, and regulatory changes to continuously improve security posture. Partner with IT, Legal, Compliance, and Risk teams to ensure a coordinated and enterprise-wide approach to security. WHAT YOULL NEED: Bachelors degree in Computer Science, Information Security, or related field, or equivalent practical experience. 9+ years of experience in information security, with significant experience in application or cloud security roles. Strong understanding of secure software architecture, Kubernetes and container security, and cloud-native environments (AWS and Azure). Prior software development experience with the ability to assess security risks at the code and architecture level. Solid understanding of the Software Development Life Cycle (SDLC) and how to integrate security into each phase. Experience managing vulnerability and penetration testing programs, including coordinating external testing and driving remediation. Familiarity with industry security frameworks and regulatory standards such as GDPR, PCI DSS 4.0, and ISO 27001. Strong communication skills and the ability to partner effectively with engineers, product teams, and business stakeholders. CISSP or equivalent security certification required; CSSLP or cloud security certifications preferred. WHATS IN IT FOR YOU: Purpose led company with a Values focused culture Best Life, One Team, Growth Mindset Time Off competitive PTO plans with 15 Earned accrued leave, 12 days Sick leave, and 12 days Casual leave per year 11 Holidays plus 4 Days of Disconnect once a quarter, we take a collective breather and enjoy a day off together around the globe. #oneteam Group Mediclaim insurance coverage of INR 500,000 for employee + spouse, 2 kids, and parents or parent-in-laws, and including .