Senior Application Security Engineer

Infosys
United States
6 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Software System Penetration Testing Microsoft Azure Burp Suite Continuous Integration Open Web Application Security Systems Development Life Cycle Power BI Fortify (Software) Secure Coding SonarQube Software Vulnerability Management
+10 more
Software Security Mitre Att&ck Mttr Sonatype Nexus GWAPT Appscan Devsecops Servicenow Static Application Security Testing Dynamic Application Security Testing

Job description

Experteer Overview In this role you will lead application security testing and governance to strengthen software security across web, API, and cloud apps. You will drive vulnerability management, collaborate with development teams to embed secure practices in the SDLC, and contribute to risk-based security reporting. You will work within a security-focused function that partners with cross-functional teams to scale secure development and compliance. This is a chance to shape security maturity in a global consulting environment. Compensation / Benefits * Perform SAST, DAST, SCA, penetration testing, API security testing and manual security reviews across web, API, cloud and enterprise apps * Validate findings, analyze false positives, and retest to verify remediation effectiveness * Lead vulnerability management activities including prioritization, remediation tracking, and reporting * Advise development teams on secure coding, remediation strategies, and secure SDLC integration in CI/CD/DevSecOps * Support security governance, risk assessments, threat modeling, secure design reviews, and compliance activities * Create security dashboards and metrics (vulnerability trends, SLAs, MTTR, testing coverage) and communicate risks to stakeholders Tasks * 10+ years of experience in Application Security, Security Testing, Vulnerability Management, or related disciplines * Strong hands-on with SAST, DAST, SCA, penetration testing, API security testing, and manual assessments * Extensive experience with Burp Suite; familiarity with HCL AppScan, Sonatype Nexus IQ/Lifecycle, Fortify, SonarQube, Black Duck (or similar SCA tools) * Deep understanding of OWASP Top 10, CWE, OWASP ASVS, Secure SDLC, and risk-based prioritization * Experience collaborating with development teams to drive remediation and security maturity * Strong written and verbal communication with stakeholders * Preferred: Azure Cloud & Azure DevOps, ServiceNow, Power BI, and governance frameworks (NIST, MITRE ATT&CK, CIS) * Certifications such as CISSP, CSSLP, GWAPT, GWEB, OSCP/OSWE, Security+, AZ-500 are a plus Key requirements *

Requirements

effectiveness * Support security governance, risk assessments, threat modeling, secure design reviews, and compliance activities * Create security dashboards and metrics (vulnerability trends, SLAs, MTTR, testing coverage) and communicate risks to stakeholders Tasks * 10+ years of experience in Application Security, Security Testing, Vulnerability Management, or related disciplines * Strong hands-on with SAST, DAST, SCA, penetration testing, API security testing, and manual assessments * Extensive experience with Burp Suite; familiarity with HCL AppScan, Sonatype Nexus IQ/Lifecycle, Fortify, SonarQube, Black Duck (or similar SCA tools) * Deep understanding of OWASP Top 10, CWE, OWASP ASVS, Secure SDLC, and risk-based prioritization * Experience collaborating with development teams to drive remediation and security maturity * Strong written and verbal communication with stakeholders * Preferred: Azure Cloud & Azure DevOps, ServiceNow, Power BI, and governance frameworks (NIST, MITRE ATT&CK, CIS) * Certifications such as CISSP, CSSLP, GWAPT, GWEB, OSCP/OSWE, Security+, AZ-500 are a plus Key requirements *

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on us.experteer.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Defining application, pipeline, and security operations roles

Aarno Aukia · LIVE

3:08 min

Aligning engineering processes with core business impact metrics

Chris Riley · WWC 2021

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:07 min

Establishing service level agreements directly for internal platforms

Pawel Piwosz · LIVE

4:01 min

Implementing the barbell strategy and focusing on recovery time

Jan de Vries Jan de Vries · WWC Europe 2026

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

Videos

See all

Related articles

See all