NextRaiseNextRaiseFind jobs
Sign inSign up free
Jobs / Functional Consultant in India
9 hours agoBe an early applicant
Apply with autofill
Apply with autofill
RA
Ramboll·9 hours ago
9 hours agoBe an early applicant

Application Security Specialist

Chennai, IndiaFull-timeMid · 2-5 yearsFunctional Consultant

Sign up free to see how well your resume matches this role.

Boost your chances at Ramboll

How you compare FREE

?
Your scoreYour score: not yet known
→
57
Top 10%Top 10%: 57 out of 100

Top 10% of NextRaise users matched against Functional Consultant roles in India.

Must-have skills for this role

  • application security
  • devsecops
  • owasp
  • sast

PDF or DOCX · no account needed

Apply faster with autofill FREERamboll uses SmartRecruiters - autofill it instead of retyping.careers.example.com/applyAutofillingFull namePriya SharmaEmailpriya.sharma@example.comPhone+49 30 1234567LocationBerlGet the extension

What you'll do

  • Translate security policies into actionable technical controls for development teams
  • Ensure alignment with ISO/IEC 27001, CIS Critical Security Controls, and OWASP Top 10
  • Support internal/external audits by providing application security evidence and metrics
  • Contribute to risk registers, control effectiveness reviews, and exception handling
  • Embed application security controls into CI/CD pipelines across business units
  • Drive adoption of security-by-design and shift-left security practices
  • Integrate and manage tools for SAST, DAST, SCA, Secrets Scanning
  • Partner with DevOps teams to standardize secure pipelines globally
  • Perform risk-based vulnerability assessments and prioritize remediation
  • Align risk ratings aligned with Cyber and Information security risk methodology
  • Track remediation SLAs and report on risk posture to CISO office
  • Conduct threat modeling for critical applications and digital solutions

What they're looking for

  • 5+ years in Application Security, Cyber Security, or Software Development
  • Experience working in Agile/DevOps environments
  • Strong understanding of Web technologies (HTTP, REST APIs, microservices)
  • Strong understanding of Authentication and authorization mechanisms (OAuth, JWT, SSO)
  • Knowledge of common vulnerabilities (e.g., SQL Injection, XSS, CSRF)
  • Experience with security tools such as SAST: Checkmarx, Fortify
  • Experience with security tools such as DAST: Burp Suite, Acunetix
  • Experience with security tools such as SCA: Snyk, Black Duck
  • Familiarity with programming languages (Java, Python, JavaScript, .NET)
  • Hands-on experience with OWASP Top 10 risks
  • Understanding of threat modeling methodologies
  • Experience in bridging policy-to-technical implementation gaps

Nice to have

  • Knowledge of cloud security (AWS, Azure, GCP)
  • Prior experience in secure coding or vulnerability management
  • Certified Secure Software Lifecycle Professional (CSSLP)
  • Offensive Security Certified Professional (OSCP)
  • Certified Information Systems Security Professional (CISSP)
  • GIAC Web Application Penetration Tester (GWAPT)
  • Experience with bug bounty programs
  • Knowledge of container security (Docker, Kubernetes)

Summarised by NextRaise from the employer’s description, which follows in full below.

Full description from employer

Company Description

About Ramboll

Ramboll is a global leader in sustainable architecture, engineering, and consultancy. At Ramboll Tech, we drive digital transformation across Ramboll, setting the pace for how technology transforms the built environment. Our mission is to become the leading tech-enabled partner for sustainable change.

If you are passionate about shaping high-impact digital products and want to connect product strategy with engineering execution, cloud platforms, data, integration and AI-enabled capabilities, this is your opportunity.

Ramboll globally

Ramboll is a leading engineering, architecture and consultancy company. Working at one of our offices in 35 countries you will join 16,000 fellow bright minds in creating innovative and sustainable solutions within Buildings, Transport, Energy, Environment & Health, Architecture, Landscape & Urbanism, Water and Management Consulting. Combining local experience with global knowledge, we help shape the society of tomorrow.

Inviting bright minds

Do you want to push the boundaries of your profession and develop your excellence in an open, collaborative, and empowering culture? We work to create a sustainable future and our inspiring projects and innovative solutions aim to set the standard among our peers. You will join a global company that has been growing successfully since its founding in 1945. Together, we lead and leave a positive impact on societies, companies, and people around the world.

Job Description

Application Security Specialist India

Are you motivated by turning complex security and compliance risks into clear, decision‑ready insights? Do you want to work at the intersection of information security, data compliance and governance in a global organisation? Are you looking to make a tangible impact on how a leading consultancy manages cyber and data‑related risks?

If this sounds like you, or you’re curious to learn more, then this role could be the perfect opportunity. Join our Information Security and Data Compliance department

Your new role

The Application Security Specialist operates at the intersection of Information Security and Assurance (ISA) and DevSecOps, ensuring that application security is embedded, measurable, and compliant across Ramboll’s global digital landscape and application development.

This role focuses on integrating security into engineering workflows while aligning with enterprise security frameworks such as ISO 12207 /ISO/IEC 27001 / CIS 18 and industry best practices like OWASP.

The Application Security specialist is responsible for identifying, analyzing, and mitigating security vulnerabilities in applications throughout the software development lifecycle (SDLC). This role works closely with development, DevOps, and security teams to ensure secure coding practices and compliance with organizational and industry standards. You will work closely with RAMTECH, data compliance, regulatory and business teams.

Your key responsibilities will be:

Alignment & Assurance

•Translate security policies into actionable technical controls for development teams
•Ensure alignment with:
    ISO/IEC 27001
    CIS Critical Security Controls
    OWASP Top 10
•Support internal/external audits by providing application security evidence andmetrics
•Contribute to risk registers, control effectiveness reviews, and exception handling

DevSecOps Enablement

•Embed application security controls into CI/CD pipelines across business units
•Drive adoption of security-by-design and shift-left security practices
•Integrate and manage tools for:
         oSAST, DAST, SCA, Secrets Scanning
•Partner with DevOps teams to standardize secure pipelines globally
Confidential.

Application Risk Management

• Perform risk-based vulnerability assessments and prioritize remediation
• Align risk ratings aligned with Cyber and Information security risk methodology
• Track remediation SLAs and report on risk posture to CISO office.
• Conduct threat modeling for critical applications and digital solutions

Security Testing & Validation

• Oversee and/or perform:
     o Secure code reviews
     o Penetration testing (manual & automated)
• Validate vulnerability fixes and ensure closure meets compliance requirements
• Establish baseline security requirements for all applications

Developer Security Advisory

• Act as a security champion enabler across distributed engineering teams
• Provide secure coding guidance and conduct targeted training sessions
• Develop reusable secure design patterns and reference architectures.

Metrics, Reporting & Continuous Improvement

• Define and track KPIs such as:
      o Vulnerability density
      o Mean Time to Remediate (MTTR)
      o % of applications onboarded to DevSecOps pipelines
• Build dashboards for leadership visibility and regulatory reporting
• Drive continuous improvement initiatives across global teams

Qualifications

Required Skills & Qualifications
Technical Skills
• Strong understanding of:
              o Web technologies (HTTP, REST APIs, microservices)
              o Authentication and authorization mechanisms (OAuth, JWT, SSO)
• Knowledge of common vulnerabilities (e.g., SQL Injection, XSS, CSRF)
• Experience with security tools such as:
              o SAST: Checkmarx, Fortify
              o DAST: Burp Suite, Acunetix
              o SCA: Snyk, Black Duck
• Familiarity with programming languages (Java, Python, JavaScript, .NET)

Security Knowledge

• Hands-on experience with OWASP Top 10 risks
• Understanding of threat modeling methodologies
• Experience in bridging policy-to-technical implementation gaps
• Knowledge of cloud security (AWS, Azure, GCP) is a plus

About you

• 5+ years in Application Security, Cyber Security, or Software Development
• Experience working in Agile/DevOps environments
• Prior experience in secure coding or vulnerability management preferred
• Certifications (Preferred)
        • Certified Secure Software Lifecycle Professional (CSSLP)
        • Offensive Security Certified Professional (OSCP)
        • Certified Information Systems Security Professional (CISSP)
        • GIAC Web Application Penetration Tester (GWAPT)

Nice to Have

• Experience with bug bounty programs
• Knowledge of container security (Docker, Kubernetes)
• Experience with Infrastructure as Code (IaC) security tools

Additional Information

What we can offer you
• Flexible work environment with the possibility of working from home.
• Commitment to your professional and personal development.
• Leaders guided by Ramboll’s Leadership Principles.
• A culture that welcomes you as the unique person you are.
• The long‑term thinking of a foundation‑owned company.

Ready to join us?
Please submit your application and CV online. We invite diversity in all its forms and encourage applicants from all groups to apply.

Company

RA
Ramboll
Chennai, India

Company facts come from this company's own listings. We only show what the postings themselves carry.

Sourced from Ramboll's careers site·first seen 22 Sept 2026·last verified 22 Sept 2026·How we source jobs

Similar jobs

  • Sr. Application Engineer at georgfischerMumbai, India–match not yet calculated
  • Application Security Specialist at entainPune, India–match not yet calculated
  • Head Application Development - IN at TIAAPune, India–match not yet calculated
  • Application SW Developer (Model-based) for Steering Platform at Bosch (Global Software)Coimbatore, India–match not yet calculated
  • Asset Finance Functional Consultant at Zensar TechnologiesIndia–match not yet calculated

Browse more jobs

  • Functional Consultant jobs in India
  • Technical Consultant jobs in India
  • Solutions Consultant jobs in India
  • Implementation Consultant jobs in India
  • Functional Consultant jobs in United States
  • Functional Consultant jobs in Germany