Padmi

Application Security Engineer (GTB Nagar)

IndiaPosted 1 month ago
CybersecurityMid-levelFull Time; Regular
Apply at Talentgigs

Opens the source posting on shine.com

Source description

About the role

View original

Role: SR. SECOPS & APPSEC LEAD Experience: 5-8 years Location: Noida JD: Role Overview We are looking for a Sr. SecOps & AppSec Lead to own and drive security operations across the entire product lifecycle from code commit through build, deployment, and production. You will manage our security scanning pipeline (Veracode, SonarQube, Trivy), identify and remediate vulnerabilities in application code and open-source dependencies, upgrade libraries to eliminate known CVEs, and work hands-on to fix application security issues alongside development teams. This role blends application security engineering with DevOps pipeline management. You will not just report vulnerabilities you will reproduce them, assess their real-world exploitability in our context, and either fix them yourself or guide developers through remediation. You will also own CI/CD pipeline health, ensuring security gates are embedded into every build without becoming a bottleneck. Additionally, you will lead 12 junior engineers, building a small but effective security operations practice. Key Responsibilities Security Scanning & Pipeline Management Own and manage the end-to-end security scanning pipeline: SAST (Veracode, SonarQube), SCA (Veracode SCA / Snyk / OWASP Dependency-Check), and container image scanning (Trivy) Configure, tune, and maintain scanning policies reduce false positives, set severity thresholds, and define quality gates that block vulnerable builds from promotion Integrate security scans seamlessly into CI/CD pipelines (Git runner/GitLab CI) so that every pull request and release build is automatically validated without slowing developer velocity Maintain dashboards and reporting on vulnerability trends, scan coverage, mean-time-to-remediate (MTTR), and open risk posture across the product portfolio Evaluate and onboard current security tools as the threat landscape and technology stack evolve Vulnerability Identification, Reproduction & Remediation Triage vulnerabilit Role: SR. SECOPS & APPSEC LEAD Experience: 5-8 years Location: Noida JD: Role Overview We are looking for a Sr. SecOps & AppSec Lead to own and drive security operations across the entire product lifecycle from code commit through build, deployment, and production. You will manage our security scanning pipeline (Veracode, SonarQube, Trivy), identify and remediate vulnerabilities in application code and open-source dependencies, upgrade libraries to eliminate known CVEs, and work hands-on to fix application security issues alongside development teams. This role blends application security engineering with DevOps pipeline management. You will not just report vulnerabilities you will reproduce them, assess their real-world exploitability in our context, and either fix them yourself or guide developers through remediation. You will also own CI/CD pipeline health, ensuring security gates are embedded into every build without becoming a bottleneck. Additionally, you will lead 12 junior engineers, building a small but effective security operations practice. Key Responsibilities Security Scanning & Pipeline Management Own and manage the end-to-end security scanning pipeline: SAST (Veracode, SonarQube), SCA (Veracode SCA / Snyk / OWASP Dependency-Check), and container image scanning (Trivy) Configure, tune, and maintain scanning policies reduce false positives, set severity thresholds, and define quality gates that block vulnerable builds from promotion Integrate security scans seamlessly into CI/CD pipelines (Git runner/GitLab CI) so that every pull request and release build is automatically validated without slowing developer velocity Maintain dashboards and reporting on vulnerability trends, scan coverage, mean-time-to-remediate (MTTR), and open risk posture across the product portfolio Evaluate and onboard current security tools as the threat landscape and technology stack evolve Vulnerability Identification, Reproduction & Remediation Triage vulnerabilit

One address, no account. We’ll tell you when matching roles go live.

More at Talentgigs

Related open roles

View all roles
Application Security Engineer (GTB Nagar) at Talentgigs · Padmi