Job DescriptionSenior Application Security EngineerBasic PurposeWe are seeking an experienced Senior Application Security Engineer with strong expertise in application security testing, vulnerability management, and DevSecOps advisory services. The successful candidate will lead security assessments, support vulnerability remediation efforts, advise development teams on secure software development practices, and contribute to application security governance, risk, and compliance initiatives.Key ResponsibilitiesSecurity Testing & AssessmentPerform and support application security assessments, including SAST, DAST, SCA, penetration testing, API security testing, and manual security reviews.Conduct security testing of web, API, cloud, and enterprise applications using industry-standard tools and techniques.Validate findings, perform false-positive analysis, and execute retesting to verify remediation effectiveness.Identify and assess security weaknesses related to authentication, authorization, input validation, business logic, insecure design, and vulnerable components.Vulnerability Management & DevSecOpsLead vulnerability management activities, including identification, prioritization, remediation tracking, and reporting.Prioritize findings using business impact, exploitability, exposure, threat intelligence, and organizational risk criteria.Advise development teams on secure coding practices, remediation strategies, and secure SDLC implementation.Support integration of security testing and vulnerability management processes into CI/CD pipelines and DevSecOps practices.Governance, Risk & ReportingSupport application security policies, standards, risk assessments, threat modeling, and secure design reviews.Assist with security compliance and audit-related activities.Develop security dashboards and metrics covering vulnerability trends, remediation SLAs, MTTR, and testing coverage.Communicate security risks and remediation priorities to technical and non-technical stakeholders.Qualifications & ExperienceRequiredBachelor's or Master's degree in Computer Science, Cybersecurity, Information Technology, or related discipline, or equivalent experience.10+ years of experience in Application Security, Security Testing, Vulnerability Management, or related cybersecurity disciplines.Strong hands-on experience with: SASTDASTSCAPenetration TestingAPI Security TestingManual Security AssessmentsExtensive experience using Burp Suite for web and API security testing.Hands-on experience with tools such as: Burp SuiteHCL AppScanSonatype Nexus IQ/LifecycleFortifySonarQubeBlack Duck (or similar SCA tools)Strong understanding of OWASP Top 10, CWE, OWASP ASVS, Secure SDLC, vulnerability management, and risk-based prioritization.Experience collaborating with development teams to drive remediation and improve security maturity.Strong written, verbal, and stakeholder communication skills.PreferredExperience with Azure Cloud and Azure DevOps.Experience with ServiceNow for vulnerability or incident management workflows.Experience creating security dashboards and reports using Power BI.Knowledge of NIST, MITRE ATT&CK, CIS Benchmarks, threat modeling, and application security governance practices.Experience with AI-assisted security solutions, security automation, or agentic AI technologies.Preferred CertificationsCISSPCSSLPGWAPTGWEBOSCP / OSWESecurity+SSCPMicrosoft Azure Security Certifications (AZ-500 or equivalent)OverviewInfosys is a global leader in next-generation digital services and consulting. We enable clients in more than 50 countries to navigate their digital transformation.With over four decades of experience in managing the systems and workings of global enterprises, we expertly steer our clients through their digital journey.
We do it by enabling the enterprise with an AI-powered core that helps prioritize the execution of change. We also empower the business with agile digital at scale to deliver unprecedented levels of performance and customer delight. Our always-on learning agenda drives their continuous improvement through building and transferring digital skills, expertise, and ideas from our innovation ecosystem.All aspects of employment at Infosys are based on merit, competence and performance.
We are committed to embracing diversity and creating an inclusive environment for all employees. Infosys is proud to be an equal opportunity employer.Work LocationBucharest, Cluj-Napoca, Sibiu, Targu Mures, County Mures, Timisoara, County TimisCountryRomaniaState / Region / ProvinceBucharest, County Mures, County Timis, Wisconsin (ROU)CompanyIL Romania Interest GroupInfosys Limited Job RoleTechnical Test LeadRole Designation descriptionTechnical Test LeadAuto req ID: BR
Senior Application Security Engineer in madison at Unknown Company
This position is listed as full time and onsite.