Padmi
Onit logo
Onit

legal operations automation · contract lifecycle management

Senior Application Security Engineer

MumbaiPosted 4 months ago
CybersecuritySenior
Apply at Onit

Opens the source posting on naukri.com

Source description

About the role

View original

Position Summary Onit, Inc. is looking for an Application Security Engineer to help secure our SaaS applications, APIs, and emerging AI capabilities. This is a hands-on, high-impact role where you ll work closely with engineering and product teams to design secure systems, identify vulnerabilities, and improve how we build software. You ll play a key role in shaping our security practices as we scale. Key Responsibilities Security Architecture Design Reviews: Lead security reviews for application architecture and system design Go-Live Security Reviews Risk Decisions: Conduct pre-production / go-live security assessments Authentication, Authorization Access Control: Design and assess: OAuth2, OIDC, SAML implementations RBAC / fine-grained authorization models API Security: Lead security reviews of REST, GraphQL, and event-driven APIs AI Emerging Technology Security: Assess security risks in AI-powered features and systems Vulnerability Management Testing: Lead vulnerability identification using Static analysis (SAST) and Dependency scanning (SCA) Attack Surface Risk Assessment: Assess and map application attack surface Security Tooling DevSecOps: Integrate and optimize security tools in CI/CD pipelines Required Skills 10+ years of experience in Application Security, Security Engineering, or Software Engineering with a strong security focus Proven experience performing security architecture/design reviews, as well as Go-live/production readiness security assessments, with experience with cloud platforms (AWS, GCP, Azure) preferred Strong understanding of OWASP Top 10 and modern web vulnerabilities and secure system design and threat modeling Experience with SAST tools (e.g., SonarQube, Checkmarx) and SCA tools (e.g., Snyk, Dependabot) REST, GraphQL, and event-driven APIs OAuth2, OIDC, SAML implementations RBAC / fine-grained authorization models Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.

One address, no account. We’ll tell you when matching roles go live.

More at Onit

Related open roles

View all roles