TRPD-26-04452
Application Security Engineer (Security Defect Management & Engineering Consulting)
Hire an Application Security Engineer to partner with software teams on security defect management and secure engineering consulting. The role focuses on analyzing and validating findings from SAST/DAST/SCA, penetration tests and bug bounty, enabling tooling like CodeQL and Rapid7, onboarding and managing security testing, and guiding teams using OWASP Top 10/CWE/ASVS. Candidates should have 5+ years across software engineering, AppSec/cybersecurity, and/or major cloud platforms, plus strong secure coding knowledge for web apps, SPAs, and REST APIs, and the ability to communicate remediation guidance clearly.
Position summary
- Location
- India
- Workplace
- On-site
- Employment
- Full Time
- Experience
- Minimum 5 years and Maximum 7 years
Role overview
Why This Role Matters.
Hire an Application Security Engineer to partner with software teams on security defect management and secure engineering consulting. The role focuses on analyzing and validating findings from SAST/DAST/SCA, penetration tests and bug bounty, enabling tooling like CodeQL and Rapid7, onboarding and managing security testing, and guiding teams using OWASP Top 10/CWE/ASVS. Candidates should have 5+ years across software engineering, AppSec/cybersecurity, and/or major cloud platforms, plus strong secure coding knowledge for web apps, SPAs, and REST APIs, and the ability to communicate remediation guidance clearly.
Your Impact
Deliver Enterprise Value
Help organisations solve complex business problems through modern technology, consulting expertise and measurable outcomes.
Collaboration
Work Across Teams
Collaborate with consultants, architects, engineers and client stakeholders throughout the project lifecycle.
Growth
Learn Continuously
Gain exposure to enterprise technologies, certifications, mentoring and real-world project experience.
Career Path
Grow With Ubique
Build a long-term consulting career with opportunities to take on greater responsibility and leadership over time.
Responsibilities
What You'll Be Doing.
Every role at Ubique contributes directly to solving meaningful business challenges for our clients.
Tool Enablement - Enabling and monitoring automated defect detection tooling (CodeQL, Rapid7, etc.) at the repository or application level according to established process.
Security Test Onboarding & Management – Collecting and communicating required scope and access information for penetration testing and security assurance assessments, as well as handling the output of these assessments via our Defect Management Process.
Maturity Measurement – Consulting with software engineers on practices which will improve their application’s security maturity according to scorecards and maturity models established by Cat Digital.
Correction of Error – Authoring, in close partnership with software engineers, correction of error reports which help engineers and architects across Cat Digital avoid similar mistakes in their own applications.
5+ years of experience as a software engineer (in any language or framework) or software engineering manager
5+ years of experience as a software development-focused cybersecurity professional
5+ years of experience working on a major cloud platform (AWS, Azure, GCP, or Salesforce) as a software engineer, cloud/DevOps engineer, security engineer, or architect.
Experience analyzing and remediating security findings from automated and manual sources such as Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), penetration testing, Software Composition Analysis (SCA), etc.
Experience leveraging one or more of the following resources to support secure coding and decision-making
b. MITRE Common Weakness Enumeration (CWE) Top 25
c. OWASP Application Security Verification Standard (ASVS)
Technology stack
Tools & Technologies.
The platforms and technologies you'll use to build modern, enterprise-grade solutions.
CodeQL
Rapid7
SAST
DAST
SCA
OWASP Top 10
CWE
OWASP ASVS
penetration testing
bug bounty
web application security
API security
REST
Single Page Application
AWS
Azure
GCP
Salesforce
secure coding
vulnerability management
Requirements
Skills & Experience.
We value curiosity, collaboration and continuous learning. If you don't meet every requirement but believe you can make an impact, we'd still love to hear from you.
Essential
Required Qualifications
Security defect management (triage, validation, communication, remediation guidance)
SAST/DAST/SCA findings analysis and remediation
Penetration testing output handling and vulnerability management workflow
Secure coding guidance using OWASP Top 10
Knowledge of MITRE CWE (Top 25)
Knowledge of OWASP ASVS (or equivalent secure engineering frameworks)
Web application and API security (SPA and RESTful APIs)
Proficiency in at least one programming language
Tool enablement/monitoring for automated security scanning (e.g., CodeQL, Rapid7)
Cloud platform experience on at least one of AWS, Azure, GCP, or Salesforce (as part of the 2-of-3 qualification set)
Strong technical communication for mixed audiences
Preferred
Nice to Have
Bug bounty triage and validation
Security maturity measurement using scorecards/maturity models
Authoring security correction-of-error reports / internal advisories
Engineering consulting with architects/product owners on secure design decisions
Experience as a software engineering manager
What you'll gain
More Than Just A Job.
We're committed to helping every team member grow professionally, personally and technically while working on meaningful projects.
Global Exposure
Collaborate with international clients and multicultural teams on enterprise programmes.
Continuous Learning
Expand your expertise through mentoring, certifications and hands-on project experience.
Career Growth
Take ownership, develop leadership skills and grow your consulting career over time.
Flexible Working
Hybrid and remote collaboration designed around trust and delivering exceptional outcomes.
People First
Join a supportive culture where collaboration, respect and long-term relationships come first.
Enterprise Projects
Work on meaningful technology initiatives for leading organisations across industries.
Apply
Apply for Application Security Engineer (Security Defect Management & Engineering Consulting)
One page, about two minutes. We only ask for what we actually need to have a first conversation.