Application Security Engineer – SAST/DAST & Security Tooling Outage Support
Alignity Solutions · Hyderabad, Telangana, India
IT Services and IT Consulting · 11-50 employees
About the role
The role involves performing SAST and DAST security testing, triaging vulnerabilities, and providing remediation guidance to developers. Additionally, it requires providing hands-on outage support for security tools and managing configurations during patching windows.
What they look for
Requirements
Candidates must have 5-8 years of experience with SAST/DAST tools, Windows Server administration, and cloud security configurations. Proficiency in incident handling, CI/CD pipelines, and strong communication skills for cross-team coordination are essential.
Full description
Do you love a career where you Experience, Grow & Contribute at the same time, while earning at least 10% above the market? If so, we are excited to have bumped onto you.
Learn how we are redefining the meaning of work, and be a part of the team raved by Clients, Job-seekers and Employees.
- Jobseeker Video Testimonials
- Employee Glassdoor Reviews
If you are a Application Security Engineer looking for excitement, challenge and stability in your work, then you would be glad to come across this page.
We are an IT Solutions Integrator/Consulting Firm helping our clients hire the right professional for an exciting long-term project. Here are a few details.
Check if you are up for maximizing your earning/growth potential, leveraging our Disruptive Talent Solution.
Role:Application Security Engineer
Experience:5-8Years Location:Hyderabad | Bengaluru | Pune | Chennai
Work Mode:Hybrid
Type:Contract to Hire Notice Period: 0-30 days
Requirements
Role Summary
We are looking for an Application Security Engineer to support Static and Dynamic Application Security Testing (SAST/DAST) scan and triage activities, while also providing hands-on outage support for the security tooling ecosystem — including AppScan, Checkmarx, Cycode, and GCP Model Armor. This role combines day-to-day vulnerability triage and remediation guidance with structured, SOP-driven incident response when scanning tools are degraded or unavailable, including support during scheduled patching windows and off-business-hours coverage.
Key Responsibilities
SAST & DAST Testing and Triage
- Perform and support
Static (SAST) and Dynamic (DAST) application security testing across in-scope applications.
- Triage scan findings
across SAST, DAST, SaaS, Secrets, and API security scan results, distinguishing false positives from confirmed vulnerabilities.
- Provide developers with
clear, actionable remediation guidance for validated vulnerabilities.
- Support application
onboarding into scan tooling and manage Penalty-Box exception handling and unblock decisions.
- Provide security support
during production release ACAB reviews and Breakglass approvals.
- Create, validate, and
drive Vulnerability Information Tracker (VIT) and defect records through to closure.
AppScan & Checkmarx Windows Server Patching Outage Support
- Provide support during
scheduled monthly Windows Server patching windows to ensure AppScan and Checkmarx remain available and operational after server restarts.
- Validate application
access for AppScan and Checkmarx following patching.
- Use RDP to connect to
in-scope management servers for troubleshooting.
- Check IIS Manager to
confirm required application pools are in Started status; verify all required HCL AppScan and Cx services are in Running status.
- Start any stopped
services or application pools; reboot the AppScan management server when required for database-related errors.
- Revalidate application
login pages after restart and escalate unresolved issues via email or Microsoft Teams.
Cycode Tool Outage Support
- Support Cycode-related
issues, primarily stuck or delayed pull requests during the secret-scanning process.
- Review incident details
and validate pull request scan history in Cycode; check for missing or delayed pull requests.
- Coordinate with the E3
team to verify Azure DevOps webhooks and recent ADO changes, and confirm branch policy settings.
- Validate whether an
actual secret is blocking the pull request and raise a vendor support ticket with Cycode when required.
- Coordinate unresolved
issues with the appropriate internal teams and Cycode Support until resolution.
GCP Model Armor Support
- Provide
off-business-hours support for managing Google Cloud Model Armor configurations.
- Enable or disable Model
Armor for required projects and switch configurations between Inspect Only mode and Inspect and Block mode.
- Update the necessary
Terraform configuration, create pull requests, coordinate approvals, and trigger pipeline deployments.
- Approve Terraform runs
in accordance with the SOP, coordinating with reviewers and approvers as needed.
Required Skills & Experience
- Hands-on experience with
SAST and DAST tools and processes (e.g., Checkmarx, HCL AppScan, or equivalent), including scan triage and false-positive analysis.
- Basic Windows Server
support knowledge, with experience using RDP for remote troubleshooting.
- Working knowledge of IIS
Manager and Windows Services, including starting/stopping services and application pools.
- Basic knowledge of
Cycode or similar secret-scanning tools, Azure DevOps, pull request workflows, webhooks/service hooks, and branch policies.
- Basic knowledge of
Google Cloud Platform (GCP), Terraform, Git repositories, pull request processes, pipeline deployments, and HCP Terraform workspace approvals.
- Experience with incident
handling, vendor coordination, and SOP-based outage support procedures.
- Strong written and
verbal communication skills, including the ability to escalate and coordinate via email and Microsoft Teams.
- Willingness to support
scheduled patching windows and off-business-hours / on-call activities as needed.
Preferred Qualifications
- Prior experience in an
Application Security Testing (AST), DevSecOps, or security operations support role.
- Familiarity with
vulnerability management workflows (VIT/defect lifecycle: creation, validation, closure).
- Exposure to CI/CD
pipelines and infrastructure-as-code approval workflows.
- Relevant certifications
(e.g., Security+, GCP Associate/Professional, or vendor-specific tool certifications) are a plus.
Soft Skills
- Strong attention to
detail when following SOP-based procedures under time pressure.
- Clear, calm
communication during live outage or incident scenarios.
- Ability to work
independently during off-hours support windows while knowing when to escalate.
Collaborative mindset for coordinating across internal teams (E3, DevOps, application teams) and external
Benefits
Visit us at http://alignity.io/careers. Alignity Solutions is an Equal Opportunity Employer, M/F/V/D.
CEO Message: Click Here
Clients Testimonial: Click Here