Logo for FyerX - Your Trusted Marketing Partner

Application Security (AppSec) / DevSecOps Engineer

Role overview

Qualifications

  • 4 to 8 years of core software engineering or cloud DevOps experience
  • 3+ years of dedicated experience securing software development lifecycles (SDLC) and engineering DevSecOps pipelines
  • Strong technical mastery of automated testing engines
  • Mandatory certification: CASE, CDP, CSSLP, or CEH

Responsibilities

  • Design and integrate automated security testing gates directly into modern CI/CD pipelines
  • Configure and manage application scanning frameworks, orchestrating SAST, DAST, and SCA tooling
  • Triage and remediate software vulnerabilities, analyzing code flaws and open-source dependency risks
  • Lead comprehensive threat modeling assessments for new applications and architecture features

Key facts

  • Remote from: Anywhere
  • Full time
  • Mid-level (2-5 years)
  • Application Security Engineer
  • English

Hard skills

Other skills

  • Problem Solving

About the company

FyerX - Your Trusted Marketing Partner logo

FyerX - Your Trusted Marketing Partner

Digital Marketing & SEO Agencies

We are Digital Marketers with one primary focus. We help you realize improved outcomes from digital marketing strategies and services. Your success with us will be realized in large steps or in small incremental steps. FyerX, Bangalore is run by a passionate team of marketing experts who have devoted their time and expertise to make your business grow in the online world in this technology age. We fuel the growth of purpose driven brands through strategy activation, design empowerment, and market adoption. From cultivating new ideas to connecting the dots for customers or users, these are our core principles. Leverage our expertise to: Improve global online reach & visibility Strengthen local visibility Develop integrated marketing plans Drive growth for your brand online Improve and enhance your online reputation Measure and optimize digital efforts Craft effective digital campaigns Build your digital strategy

Company details

IndustryDigital Marketing & SEO Agencies
Company size11 - 50

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

This is a remote position.

Application Security (AppSec) / DevSecOps Engineer

Job Details
  • Employment Type: Contract
  • Work Mode: Remote
  • Location: Offshore
  • Total Experience Required: 4 to 8 years
  • Relevant Experience Required: 3+ years of dedicated experience securing software development lifecycles (SDLC) and engineering DevSecOps pipelines
  • Mandatory Certification: Certified Application Security Engineer (CASE), Certified DevSecOps Professional (CDP), CSSLP, or CEH

Job Summary
We are seeking an experienced Application Security / DevSecOps Engineer to bake robust safety controls directly into our automated software delivery frameworks. The ideal candidate will bridge software engineering with security operations, implementing automated code testing gates, leading threat modeling workshops, and hardening application containers to identify and mitigate software vulnerabilities before code hits production.

Key Responsibilities
  • Design and integrate automated security testing gates directly into modern CI/CD pipelines (e.g., GitHub Actions, GitLab CI, Jenkins).
  • Configure and manage application scanning frameworks, orchestrating Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) tooling.
  • Triage and remediate software vulnerabilities, analyzing code flaws, open-source dependency risks, and secret exposure incidents alongside software development teams.
  • Lead comprehensive threat modeling assessments for new applications and architecture features, identifying attack surfaces and defining secure coding frameworks.
  • Govern application security infrastructure, managing centralized vulnerability aggregation dashboards (e.g., DefectDojo, SonarQube) and secret vaults (e.g., HashiCorp Vault, AWS Secrets Manager).
  • Secure containerized application workloads, auditing Dockerfile construction rules, verifying baseline machine images, and checking Kubernetes network isolation parameters.
  • Drive application layer incident investigations, analyzing malicious payload web requests, API tampering logs, and cross-site scripting (XSS) vectors to improve software perimeters.



Requirements

  • 4 to 8 years of core software engineering or cloud DevOps experience, with 3+ dedicated years actively designing, building, and deploying application safety frameworks.
  • Strong technical mastery of automated testing engines (e.g., Snyk, Checkmarx, Veracode, OWASP ZAP), container security paradigms, and infrastructure-as-code hardening.
  • Deep structural understanding of the OWASP Top 10 vulnerabilities, API security perimeters, modern secure coding standards, and cryptographic signing protocols.
  • Mandatory certification: CASE, CDP, CSSLP, or CEH.

Preferred Qualifications
  • Prior experience with software development in languages like Java, Python, JavaScript/Node.js, or Go.
  • Experience implementing automated code patching routines or managing runtime application self-protection (RASP) layers.





Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Application Security Engineer Related jobs

Other jobs at FyerX - Your Trusted Marketing Partner

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.