Company Description
A leading global commercial vehicle manufacturer specializing in trucks and buses, with a strong presence across North America, Europe, and Asia. The company is recognized for its engineering excellence, strong brand portfolio, and focus on delivering reliable and efficient transportation solutions at scale.
- Location Bangalore
- Industry Automotive
- Experience Range 8+ Years
- Must-have Skills Authentication & Authorization Testing, Black Duck, CI/CD Security, Cloud-Native Security, GitHub / GitLab / Azure DevOps / Jenkins, OWASP Top 10, SAST, SCA / FOSS Security, Secure SDLC, Snyk / Snyk Code, Thick Client Security Testing, Web Application Security Testing
Job Summary
The Lead Security Engineer – Application Security & DevSecOps is responsible for strengthening and continuously improving an enterprise Application Security program. The role focuses on integrating cybersecurity throughout the Software Development Lifecycle (SDLC), leading SAST and SCA/FOSS programs, implementing DevSecOps security controls, integrating security tooling into CI/CD pipelines, performing application security assessments, and driving developer security enablement across global development teams.
Key Responsibilities
- Lead the implementation and enhancement of enterprise Application Security programs.
- Design secure-by-default architecture for Application Security tooling.
- Define and maintain Secure SDLC practices and application security governance standards.
- Own and manage enterprise SAST platforms, including Snyk Code.
- Manage SCA/FOSS security platforms such as Black Duck.
- Define and continuously improve SAST scanning policies, quality gates, and security baselines.
- Review scan results, validate vulnerabilities, and perform false-positive analysis.
- Support onboarding of repositories and applications into security scanning platforms.
- Integrate cybersecurity tools into CI/CD pipelines using GitHub, GitLab, Azure DevOps, and Jenkins.
- Design automated security scanning workflows and scalable DevSecOps controls.
- Develop integrations between cybersecurity platforms and source code management, build pipelines, issue tracking, reporting dashboards, and vulnerability management platforms.
- Develop automation scripts and APIs to improve security operations.
- Design scalable architecture for the Application Security tooling ecosystem.
- Evaluate new security technologies and recommend enterprise adoption.
- Participate in application architecture reviews from a security perspective.
- Support cloud-native and container security initiatives.
- Lead Web Application, REST API, and Thick Client security assessments.
- Perform secure code review, authentication and authorization testing, business logic testing, OWASP Top 10 validation, and API abuse testing.
- Conduct developer security awareness sessions and train Security Champions.
- Create secure development learning paths, coding guidelines, and technical documentation.
- Mentor engineering teams on vulnerability remediation.
- Drive adoption of security tooling and secure development practices across global teams.
- Present technical recommendations to senior leadership.
Required Skills & Experience
- 8+ years of experience in Application Security, DevSecOps, or Secure Software Engineering.
- Strong hands-on experience with Snyk, Black Duck, and enterprise SAST/SCA platforms.
- Proven experience integrating security tools into enterprise CI/CD pipelines.
- Experience designing scalable security tooling architecture.
- Hands-on experience performing Web Application, REST API, and Thick Client security assessments.
- Strong experience with vulnerability validation and false-positive analysis.
- Strong understanding of modern software development practices and Secure SDLC.
- Experience with application security testing methodologies.
- Strong technical leadership and stakeholder communication skills.
- Bachelor’s or Master’s degree in Computer Science, Information Security, Engineering, or a related field.
Preferred Qualifications
- Experience in the Automotive or Manufacturing industry.
- Knowledge of cloud-native application security.
- Experience implementing enterprise-wide DevSecOps transformation programs.
- Exposure to AI-assisted secure coding and security automation.
- Relevant certifications such as OSCP, CISSP, CSSLP, GWAPT, GWEB, GCSA, or Snyk Certified Professional.
Other Requirements
- Ability to work with global Software Development, DevOps, Enterprise Architecture, Product, Cybersecurity, and Business teams.
- Strong developer enablement and mentoring capabilities.
- Ability to drive adoption of security tooling and secure development practices.
- Strong presentation and communication skills for senior leadership engagement.