Application Security Engineer-1
HiringUpstox
Multiple Locations · IndiaFull-time· 3d ago
Experience
2+ years
Work Type
Full-time
Domain
FinTech, Application Security
Core SkillsMust Have
Application securityPenetration testingSource code reviewPythonGoRustAWSSecure SDLCThreat modellingSAMLOAuthOIDCSoftware supply chain securityCloudflare WAFAWS WAFWeb application securityMobile application securityAPI security
What You'll Do
1Perform penetration testing across web applications, mobile applications (Android/iOS), and APIs to identify vulnerabilities before they reach production
2Conduct manual and tool-assisted source code reviews to identify security vulnerabilities early in the development lifecycle
3Partner with engineering teams to embed security into the Secure SDLC, including security requirements, design reviews, and release gating
4Drive and participate in threat modelling exercises for new features and systems
5Configure, tune, and manage WAF rules across Cloudflare and AWS WAF to protect production applications and APIs
6Write, maintain, and improve scripts and security tools to automate security testing and streamline recurring security assessments
7Work with cloud infrastructure, preferably AWS, to review configurations and identify potential security gaps
8Track identified vulnerabilities through remediation and work closely with engineering teams to ensure vulnerabilities are addressed within defined SLAs
9Stay current with the evolving threat landscape, emerging vulnerabilities, new attack techniques, and application security tooling
Nice to HaveOptional
Container securityDockerKubernetesDevSecOpsCI/CD securityBug bounty
Domain
FinTechApplication Security