Skip to content
← Back to job listings

Manager - AppSec/DevSecOps Security Engineer

Fa Ewjt Saasfaprod1 · Noida, Uttar Pradesh, India

CybersecurityExternal listingfull-timeabout 4 hours ago

About The Role

Leadership & Programme Management

  • Own and evolve the application security strategy, testing roadmap, and service catalogue aligned to business and regulatory requirements.
  • Lead, and mentor a team of AppSec engineers and penetration testers; manage workload, quality, and career development.
  • Act as the primary escalation point for application security risk decisions across engineering and product leadership.
  • Drive continuous improvement in AppSec tooling, methodologies, and coverage metrics.
  • Represent the AppSec function in client discussions, audits, risk committees, and vendor assessments.

Web Application Penetration Testing

  • Oversee and conduct advanced web application penetration testing including complex business logic, authentication/authorisation flaws, API abuse, and chained attack scenarios.
  • Define and maintain testing methodology aligned to OWASP Testing Guide, PTES, and client-specific requirements.
  • Review and quality-assure penetration test reports produced by the team before delivery to clients or stakeholders.
  • Drive responsible disclosure and coordinated vulnerability management for critical findings.

Mobile Application Security

  • Lead mobile security assessments for Android and iOS—static/dynamic analysis, reverse engineering, and runtime manipulation (Frida, objection, Drozer).
  • Establish and maintain mobile security standards aligned to OWASP MASVS and MSTG across product teams.
  • Guide development teams on secure mobile architecture: certificate pinning, secure storage, and inter-process communication security.

Source Code Review

  • Conduct and oversee manual source code security reviews across multiple languages (Java, Python, JavaScript/TypeScript, Go, C#, and others).
  • Define code review standards and integrate SAST tooling (Semgrep, Checkmarx, Veracode, SonarQube) into development workflows.
  • Provide actionable, developer-centric findings with clear severity ratings and remediation guidance.
  • Track remediation SLAs and report on code security posture trends over time.

DevSecOps Integration

  • Lead integration of security tooling (SAST, DAST, SCA, container scanning, API security) into CI/CD pipelines (Jenkins, GitHub Actions, and similar).
  • Define pipeline security gates, policy-as-code standards, and developer feedback loops to shift security left.
  • Oversee IaC security (Terraform, CloudFormation), secrets management, and supply-chain security controls.
  • Collaborate with platform and cloud engineering on secure architecture, baseline hardening, and runtime protection.

Governance, Risk & Compliance

  • Own the application security risk register; track, prioritise, and report on vulnerability posture to senior leadership.
  • Ensure AppSec activities align with OWASP ASVS, NIST 800-53, ISO 27001, PCI-DSS, and SOC 2.
  • Define and track AppSec KPIs: mean time to remediation, critical findings per release, and coverage rates.
  • Translate regulatory and client security requirements into testable engineering controls.

AI / GenAI Security

  • Assess and mitigate risks in AI/GenAI applications: LLM-based apps, RAG pipelines, agentic workflows (OWASP LLM Top 10, prompt injection, data leakage).

Incorporate AI security testing into standard AppSec assessment methodologies.

Leadership & Programme Management

  • Own and evolve the application security strategy, testing roadmap, and service catalogue aligned to business and regulatory requirements.
  • Lead, and mentor a team of AppSec engineers and penetration testers; manage workload, quality, and career development.
  • Act as the primary escalation point for application security risk decisions across engineering and product leadership.
  • Drive continuous improvement in AppSec tooling, methodologies, and coverage metrics.
  • Represent the AppSec function in client discussions, audits, risk committees, and vendor assessments.

Web Application Penetration Testing

  • Oversee and conduct advanced web application penetration testing including complex business logic, authentication/authorisation flaws, API abuse, and chained attack scenarios.
  • Define and maintain testing methodology aligned to OWASP Testing Guide, PTES, and client-specific requirements.
  • Review and quality-assure penetration test reports produced by the team before delivery to clients or stakeholders.
  • Drive responsible disclosure and coordinated vulnerability management for critical findings.

Mobile Application Security

  • Lead mobile security assessments for Android and iOS—static/dynamic analysis, reverse engineering, and runtime manipulation (Frida, objection, Drozer).
  • Establish and maintain mobile security standards aligned to OWASP MASVS and MSTG across product teams.
  • Guide development teams on secure mobile architecture: certificate pinning, secure storage, and inter-process communication security.

Source Code Review

  • Conduct and oversee manual source code security reviews across multiple languages (Java, Python, JavaScript/TypeScript, Go, C#, and others).
  • Define code review standards and integrate SAST tooling (Semgrep, Checkmarx, Veracode, SonarQube) into development workflows.
  • Provide actionable, developer-centric findings with clear severity ratings and remediation guidance.
  • Track remediation SLAs and report on code security posture trends over time.

DevSecOps Integration

  • Lead integration of security tooling (SAST, DAST, SCA, container scanning, API security) into CI/CD pipelines (Jenkins, GitHub Actions, and similar).
  • Define pipeline security gates, policy-as-code standards, and developer feedback loops to shift security left.
  • Oversee IaC security (Terraform, CloudFormation), secrets management, and supply-chain security controls.
  • Collaborate with platform and cloud engineering on secure architecture, baseline hardening, and runtime protection.

Governance, Risk & Compliance

  • Own the application security risk register; track, prioritise, and report on vulnerability posture to senior leadership.
  • Ensure AppSec activities align with OWASP ASVS, NIST 800-53, ISO 27001, PCI-DSS, and SOC 2.
  • Define and track AppSec KPIs: mean time to remediation, critical findings per release, and coverage rates.
  • Translate regulatory and client security requirements into testable engineering controls.

AI / GenAI Security

  • Assess and mitigate risks in AI/GenAI applications: LLM-based apps, RAG pipelines, agentic workflows (OWASP LLM Top 10, prompt injection, data leakage).

Incorporate AI security testing into standard AppSec assessment methodologies.

Skills & Capabilities

Non-Negotiable – Must Have

  • 6–8+ years of progressive experience in application security, penetration testing, or a closely related security engineering discipline.
  • Expert-level web application penetration testing: complex chained attacks, API abuse, OAuth/OIDC flaws, deserialization, advanced injection techniques.
  • Hands-on mobile security testing for Android and iOS (static/dynamic analysis, Frida scripting, MASVS/MSTG alignment).
  • Strong source code review skills across at least two major languages—able to identify security defects manually and via SAST tooling.
  • Proven experience embedding security into CI/CD pipelines and operating SAST/DAST/SCA tooling in a DevSecOps environment.
  • Experience managing or technically leading a team of security engineers or penetration testers.
  • Ability to communicate complex security risk credibly to technical and executive audiences.

Good to Have

  • Certifications: eWPTX, OSCP, OSWE, BSCP (Burp Suite Certified Practitioner), GWAPT, GWEB, GPEN, CPENT, or equivalent offensive security credentials.
  • Cloud security experience across AWS, Azure, or GCP (IAM, network security, SIEM integration).
  • Knowledge of AI/GenAI security risks and securing ML pipelines (MLSecOps).
  • Threat modelling frameworks: STRIDE, PASTA, attack trees.
  • Experience in client-facing security consulting or managed security services.

Leadership & Soft Skills

  • Proven ability to build, mentor, and retain high-performing security teams.
  • Strong programme management—able to manage concurrent assessments, client deliverables, and operational priorities.
  • Influencing skills to drive secure-by-design adoption across engineering organisations without being a pure gatekeeper.
  • Commercial awareness: able to balance thoroughness, risk, and delivery timelines.

Qualifications

  • Bachelor’s or master’s degree in Computer Science, Information Security, Engineering, or equivalent practical experience.
  • 6–8+ years of relevant experience in application security, penetration testing, or DevSecOps with progressive responsibility.
  • 1–2+ years in a team lead or management capacity within a security function.
  • Offensive security certifications (eWPTX, OSCP, OSWE, or equivalent) strongly preferred.

This is an external listing. JobSpring does not represent or verify the employer. Report this listing