Alignity Solutions

Application Security Engineer – SAST/DAST & Security Tooling Outage Support

Alignity Solutions · Hyderabad, Telangana, India

IT Services and IT Consulting · 11-50 employees

20 h ago
Senior (5-10 yrs) Contractor India
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The role involves performing SAST and DAST security testing, triaging vulnerabilities, and providing remediation guidance to developers. Additionally, it requires providing hands-on outage support for security tools and managing configurations during patching windows.

What they look for

SAST DAST AppScan Checkmarx Cycode GCP Model Armor Windows Server IIS Manager Azure DevOps Terraform Vulnerability Triage Incident Response CI/CD Infrastructure-as-code Secret-scanning

Requirements

Candidates must have 5-8 years of experience with SAST/DAST tools, Windows Server administration, and cloud security configurations. Proficiency in incident handling, CI/CD pipelines, and strong communication skills for cross-team coordination are essential.

Full description

Do you love a career where you Experience, Grow & Contribute at the same time, while earning at least 10% above the market? If so, we are excited to have bumped onto you.

Learn how we are redefining the meaning of work, and be a part of the team raved by Clients, Job-seekers and Employees.

  • Jobseeker Video Testimonials
  • Employee Glassdoor Reviews

If you are a Application Security Engineer looking for excitement, challenge and stability in your work, then you would be glad to come across this page.

We are an IT Solutions Integrator/Consulting Firm helping our clients hire the right professional for an exciting long-term project. Here are a few details.

Check if you are up for maximizing your earning/growth potential, leveraging our Disruptive Talent Solution.

Role:Application Security Engineer

Experience:5-8Years Location:Hyderabad | Bengaluru | Pune | Chennai

Work Mode:Hybrid

Type:Contract to Hire Notice Period: 0-30 days

Requirements

Role Summary

We are looking for an Application Security Engineer to support Static and Dynamic Application Security Testing (SAST/DAST) scan and triage activities, while also providing hands-on outage support for the security tooling ecosystem — including AppScan, Checkmarx, Cycode, and GCP Model Armor. This role combines day-to-day vulnerability triage and remediation guidance with structured, SOP-driven incident response when scanning tools are degraded or unavailable, including support during scheduled patching windows and off-business-hours coverage.

Key Responsibilities

SAST & DAST Testing and Triage

  • Perform and support

Static (SAST) and Dynamic (DAST) application security testing across in-scope applications.

  • Triage scan findings

across SAST, DAST, SaaS, Secrets, and API security scan results, distinguishing false positives from confirmed vulnerabilities.

  • Provide developers with

clear, actionable remediation guidance for validated vulnerabilities.

  • Support application

onboarding into scan tooling and manage Penalty-Box exception handling and unblock decisions.

  • Provide security support

during production release ACAB reviews and Breakglass approvals.

  • Create, validate, and

drive Vulnerability Information Tracker (VIT) and defect records through to closure.

AppScan & Checkmarx Windows Server Patching Outage Support

  • Provide support during

scheduled monthly Windows Server patching windows to ensure AppScan and Checkmarx remain available and operational after server restarts.

  • Validate application

access for AppScan and Checkmarx following patching.

  • Use RDP to connect to

in-scope management servers for troubleshooting.

  • Check IIS Manager to

confirm required application pools are in Started status; verify all required HCL AppScan and Cx services are in Running status.

  • Start any stopped

services or application pools; reboot the AppScan management server when required for database-related errors.

  • Revalidate application

login pages after restart and escalate unresolved issues via email or Microsoft Teams.

Cycode Tool Outage Support

  • Support Cycode-related

issues, primarily stuck or delayed pull requests during the secret-scanning process.

  • Review incident details

and validate pull request scan history in Cycode; check for missing or delayed pull requests.

  • Coordinate with the E3

team to verify Azure DevOps webhooks and recent ADO changes, and confirm branch policy settings.

  • Validate whether an

actual secret is blocking the pull request and raise a vendor support ticket with Cycode when required.

  • Coordinate unresolved

issues with the appropriate internal teams and Cycode Support until resolution.

GCP Model Armor Support

  • Provide

off-business-hours support for managing Google Cloud Model Armor configurations.

  • Enable or disable Model

Armor for required projects and switch configurations between Inspect Only mode and Inspect and Block mode.

  • Update the necessary

Terraform configuration, create pull requests, coordinate approvals, and trigger pipeline deployments.

  • Approve Terraform runs

in accordance with the SOP, coordinating with reviewers and approvers as needed.

Required Skills & Experience

  • Hands-on experience with

SAST and DAST tools and processes (e.g., Checkmarx, HCL AppScan, or equivalent), including scan triage and false-positive analysis.

  • Basic Windows Server

support knowledge, with experience using RDP for remote troubleshooting.

  • Working knowledge of IIS

Manager and Windows Services, including starting/stopping services and application pools.

  • Basic knowledge of

Cycode or similar secret-scanning tools, Azure DevOps, pull request workflows, webhooks/service hooks, and branch policies.

  • Basic knowledge of

Google Cloud Platform (GCP), Terraform, Git repositories, pull request processes, pipeline deployments, and HCP Terraform workspace approvals.

  • Experience with incident

handling, vendor coordination, and SOP-based outage support procedures.

  • Strong written and

verbal communication skills, including the ability to escalate and coordinate via email and Microsoft Teams.

  • Willingness to support

scheduled patching windows and off-business-hours / on-call activities as needed.

Preferred Qualifications

  • Prior experience in an

Application Security Testing (AST), DevSecOps, or security operations support role.

  • Familiarity with

vulnerability management workflows (VIT/defect lifecycle: creation, validation, closure).

  • Exposure to CI/CD

pipelines and infrastructure-as-code approval workflows.

  • Relevant certifications

(e.g., Security+, GCP Associate/Professional, or vendor-specific tool certifications) are a plus.

Soft Skills

  • Strong attention to

detail when following SOP-based procedures under time pressure.

  • Clear, calm

communication during live outage or incident scenarios.

  • Ability to work

independently during off-hours support windows while knowing when to escalate.

Collaborative mindset for coordinating across internal teams (E3, DevOps, application teams) and external

Benefits

Visit us at http://alignity.io/careers. Alignity Solutions is an Equal Opportunity Employer, M/F/V/D.

CEO Message: Click Here

Clients Testimonial: Click Here