
Senior Application Security Engineer
Kimshuka Technologies Pvt Ltd
About this job
Kimshuka is actively seeking a highly experienced and dedicated Application Security Engineer to join our dynamic team in Bangalore. This is a critical role for a professional with deep expertise in safeguarding enterprise applications, particularly within the Amazon Web Services (AWS) ecosystem. As an Application Security Engineer, you will be instrumental in fortifying our cloud-native applications against evolving threats, ensuring the integrity, confidentiality, and availability of our systems.
We are looking for a proactive security leader who can drive DevSecOps initiatives and implement robust security controls across the software development lifecycle. If you possess a strong background in product security, AWS security services, and an unwavering commitment to secure coding practices, we encourage you to apply and contribute to a secure future with Kimshuka.
Key Responsibilities
- Design, implement, and maintain comprehensive application security solutions tailored for AWS cloud environments.
- Conduct thorough threat modeling, security architecture reviews, and vulnerability assessments focusing on OWASP Top 10 and API Security best practices.
- Integrate and manage SAST, DAST, and SCA tools (e.g., SonarQube, Checkmarx, Veracode, Snyk, Burp Suite, OWASP ZAP) into CI/CD pipelines.
- Implement and enforce Infrastructure as Code (IaC) security using tools like Terraform and CloudFormation to ensure secure deployments.
- Secure containerized applications and orchestration platforms, including Docker, Kubernetes, EKS/ECS, and serverless functions like AWS Lambda.
- Oversee CI/CD security, ensuring security gates are embedded within Jenkins, GitHub Actions, and GitLab CI workflows.
- Perform secure code reviews for applications developed in Python and Go, identifying and mitigating potential vulnerabilities.
- Drive DevSecOps initiatives, fostering a culture of security awareness and shared responsibility across development teams.
- Manage the end-to-end vulnerability management lifecycle, from identification and prioritization to remediation and reporting.
Requirements
- A minimum of 8 years of progressive experience in Application Security or Product Security roles.
- Demonstrable expert-level proficiency in AWS Security services, including IAM, WAF, GuardDuty, Inspector, Security Hub, KMS, Secrets Manager, and CloudTrail.
- Extensive practical experience with OWASP Top 10, API Security, and threat modeling methodologies.
- Hands-on experience with various SAST/DAST/SCA tools such as SonarQube, Checkmarx, Veracode, Snyk, Burp Suite, or OWASP ZAP.
- Solid understanding and experience with IaC tools like Terraform and CloudFormation, with a focus on security hardening.
- Proficiency in securing containerization technologies (Docker, Kubernetes, EKS/ECS) and serverless computing (AWS Lambda).
- Proven track record in securing CI/CD pipelines using Jenkins, GitHub Actions, or GitLab CI.
- Strong programming skills in Python or Go, specifically applied to secure code review and automation.
- Comfortable with rotational shifts to support a global operational environment.
- AWS Certified Security – Specialty certification is highly preferred.
What We Offer
- An opportunity to shape the security posture of innovative applications within a leading technology company.
- A stimulating hybrid work environment in Bangalore that fosters collaboration and professional growth.
- Exposure to cutting-edge AWS security technologies and advanced DevSecOps practices.
- A culture that values continuous learning, professional development, and impactful contributions.
- Competitive compensation and benefits package reflective of your expertise and experience.
Eligibility
Professionals • 8-8 years of experience