NextRaiseNextRaiseFind jobs
Sign inSign up free
Jobs / Security Engineer in India
18 days ago
Apply with autofill
Apply with autofill
EXL·18 days ago
18 days ago

Manager - AppSec/DevSecOps Security Engineer

Delhi NCR, IndiaHybridMid · 5-10 yearsSecurity Engineer

Sign up free to see how well your resume matches this role.

Boost your chances at EXL

How you compare FREE

?
Your scoreYour score: not yet known
→
62
Top 10%Top 10%: 62 out of 100

Top 10% of NextRaise users matched against Security Engineer roles in India.

Must-have skills for this role

  • owasp
  • java
  • python
  • javascript

PDF or DOCX · no account needed

Apply faster with autofill FREEThe NextRaise extension autofills your application in one click.careers.example.com/applyAutofillingFull namePriya SharmaEmailpriya.sharma@example.comPhone+49 30 1234567LocationBerlGet the extension

About this role

Leadership & Programme Management

  • Own and evolve the application security strategy, testing roadmap, and service catalogue aligned to business and regulatory requirements.
  • Lead, and mentor a team of AppSec engineers and penetration testers; manage workload, quality, and career development.
  • Act as the primary escalation point for application security risk decisions across engineering and product leadership.
  • Drive continuous improvement in AppSec tooling, methodologies, and coverage metrics.
  • Represent the AppSec function in client discussions, audits, risk committees, and vendor assessments.

Web Application Penetration Testing

  • Oversee and conduct advanced web application penetration testing including complex business logic, authentication/authorisation flaws, API abuse, and chained attack scenarios.
  • Define and maintain testing methodology aligned to OWASP Testing Guide, PTES, and client-specific requirements.
  • Review and quality-assure penetration test reports produced by the team before delivery to clients or stakeholders.
  • Drive responsible disclosure and coordinated vulnerability management for critical findings.

Mobile Application Security

  • Lead mobile security assessments for Android and iOS—static/dynamic analysis, reverse engineering, and runtime manipulation (Frida, objection, Drozer).
  • Establish and maintain mobile security standards aligned to OWASP MASVS and MSTG across product teams.
  • Guide development teams on secure mobile architecture: certificate pinning, secure storage, and inter-process communication security.

Source Code Review

  • Conduct and oversee manual source code security reviews across multiple languages (Java, Python, JavaScript/TypeScript, Go, C#, and others).
  • Define code review standards and integrate SAST tooling (Semgrep, Checkmarx, Veracode, SonarQube) into development workflows.
  • Provide actionable, developer-centric findings with clear severity ratings and remediation guidance.
  • Track remediation SLAs and report on code security posture trends over time.

DevSecOps Integration

  • Lead integration of security tooling (SAST, DAST, SCA, container scanning, API security) into CI/CD pipelines (Jenkins, GitHub Actions, and similar).
  • Define pipeline security gates, policy-as-code standards, and developer feedback loops to shift security left.
  • Oversee IaC security (Terraform, CloudFormation), secrets management, and supply-chain security controls.
  • Collaborate with platform and cloud engineering on secure architecture, baseline hardening, and runtime protection.

Governance, Risk & Compliance

  • Own the application security risk register; track, prioritise, and report on vulnerability posture to senior leadership.
  • Ensure AppSec activities align with OWASP ASVS, NIST 800-53, ISO 27001, PCI-DSS, and SOC 2.
  • Define and track AppSec KPIs: mean time to remediation, critical findings per release, and coverage rates.
  • Translate regulatory and client security requirements into testable engineering controls.

AI / GenAI Security

  • Assess and mitigate risks in AI/GenAI applications: LLM-based apps, RAG pipelines, agentic workflows (OWASP LLM Top 10, prompt injection, data leakage).

Incorporate AI security testing into standard AppSec assessment methodologies.

Company

EXL
Delhi NCR, India

Company facts come from this company's own listings. We only show what the postings themselves carry.

Sourced from EXL's careers site·first seen 2 Sept 2026·last verified 8 Sept 2026·How we source jobs

Similar jobs

  • Product Security Engineer at smithnephewPune, India–match not yet calculated
  • Senior Security Engineer at kestraEurope, India–match not yet calculated
  • L2 Security Engineer at HPE (Hewlett Packard Enterprise)Bengaluru, India–match not yet calculated
  • Network and Security Engineer at skillsoftHyderabad, India–match not yet calculated
  • Senior Security Engineer at ambient.aiBengaluru, India–match not yet calculated

Browse more jobs

  • Security Engineer jobs in India
  • Security Analyst jobs in India
  • Cloud Security Engineer jobs in India
  • Penetration Tester jobs in India
  • Security Engineer jobs in United States
  • Security Engineer jobs in United Kingdom