TRCD-26-04851
Application Security (AppSec) Engineer
Hiring an Application Security (AppSec) Engineer (2–4 years) on contract for Gurgaon or Mumbai to support Cyber & Digital Risk Managed Services. The role focuses on securing web applications and REST APIs across the SDLC by running SAST/DAST/SCA scans, validating and triaging findings (including false positives), supporting secure code/architecture reviews and basic threat modeling, integrating security checks into CI/CD pipelines, and collaborating with developers to validate remediation and produce security assessment reports.
Position summary
- Location
- India
- Workplace
- On-site
- Employment
- Contract
- Experience
- Minimum 2 years and Maximum 4 years
Role overview
Why This Role Matters.
Hiring an Application Security (AppSec) Engineer (2–4 years) on contract for Gurgaon or Mumbai to support Cyber & Digital Risk Managed Services. The role focuses on securing web applications and REST APIs across the SDLC by running SAST/DAST/SCA scans, validating and triaging findings (including false positives), supporting secure code/architecture reviews and basic threat modeling, integrating security checks into CI/CD pipelines, and collaborating with developers to validate remediation and produce security assessment reports.
Your Impact
Deliver Enterprise Value
Help organisations solve complex business problems through modern technology, consulting expertise and measurable outcomes.
Collaboration
Work Across Teams
Collaborate with consultants, architects, engineers and client stakeholders throughout the project lifecycle.
Growth
Learn Continuously
Gain exposure to enterprise technologies, certifications, mentoring and real-world project experience.
Career Path
Grow With Ubique
Build a long-term consulting career with opportunities to take on greater responsibility and leadership over time.
Responsibilities
What You'll Be Doing.
Every role at Ubique contributes directly to solving meaningful business challenges for our clients.
Vulnerability Management & Triage: Validate vulnerabilities identified by automated scanners, eliminate false positives, track findings until complete closure, and maintain comprehensive documentation.
Code & Architecture Review: Support secure code review activities and basic threat modeling/security design reviews under the guidance of senior AppSec engineers.
API & Web Security Assessment: Assess common web application vulnerabilities based on the OWASP Top 10 and assist in specialized API security assessments.
SDLC & CI/CD Integration: Support seamless security testing integrations across the SDLC and modern CI/CD pipelines.
Remediation & Collaboration: Review security findings, coordinate directly with development teams to validate remediation, and prepare detailed security assessment reports.
Core Security Concepts: Solid understanding of the OWASP Top 10, secure SDLC practices, and fundamental web technologies.
Protocols & Architecture: Good working knowledge of HTTP/HTTPS and REST APIs.
Identity & Access Management: Basic understanding of authentication and authorization mechanisms including OAuth, JWT, and SAML.
Security Tooling: Familiarity with scanning tools used for SAST, DAST, and SCA.
Experience: 2 to 4 years of hands-on technical experience in Application Security or related cybersecurity domains.
Soft Skills: Strong communication skills to coordinate effectively with development and engineering teams for security remediation.
Technology stack
Tools & Technologies.
The platforms and technologies you'll use to build modern, enterprise-grade solutions.
Application Security
AppSec
SAST
DAST
SCA
OWASP Top 10
Secure SDLC
CI/CD
DevSecOps
Vulnerability Management
Triage
False Positives
HTTP
HTTPS
REST
API Security
OAuth
JWT
SAML
Threat Modeling
Requirements
Skills & Experience.
We value curiosity, collaboration and continuous learning. If you don't meet every requirement but believe you can make an impact, we'd still love to hear from you.
Essential
Required Qualifications
2–4 years hands-on experience in Application Security or related cybersecurity domain
SAST, DAST, and SCA concepts and execution using enterprise tools
Vulnerability validation/triage, false-positive elimination, tracking to closure, and documentation
OWASP Top 10 knowledge and web application vulnerability assessment
Secure SDLC practices and fundamental web technologies understanding
HTTP/HTTPS fundamentals
REST API security basics
Authentication and authorization basics (OAuth, JWT, SAML)
Ability to collaborate with development teams for remediation and reporting
Preferred
Nice to Have
Secure code review support
Basic threat modeling / security design review support
CI/CD security testing integration exposure
API-focused security assessment experience
What you'll gain
More Than Just A Job.
We're committed to helping every team member grow professionally, personally and technically while working on meaningful projects.
Global Exposure
Collaborate with international clients and multicultural teams on enterprise programmes.
Continuous Learning
Expand your expertise through mentoring, certifications and hands-on project experience.
Career Growth
Take ownership, develop leadership skills and grow your consulting career over time.
Flexible Working
Hybrid and remote collaboration designed around trust and delivering exceptional outcomes.
People First
Join a supportive culture where collaboration, respect and long-term relationships come first.
Enterprise Projects
Work on meaningful technology initiatives for leading organisations across industries.
Apply
Apply for Application Security (AppSec) Engineer
One page, about two minutes. We only ask for what we actually need to have a first conversation.