Atomicwork

Application Security Engineer

Atomicwork · Bengaluru, Karnataka · 2h ago
Type
Full-time
Mode
Hybrid
Experience
2 – 6 yrs
Openings
0 / 1
Salary
Not disclosed
Team
Security Engineering

At a glance

Atomicwork is hiring an Application Security Engineer in Bengaluru — OWASP Top 10, SAST/DevOps pipeline integration, code review.

About the role

## About the Role Atomicwork is hiring an Application Security Engineer for its hybrid Bengaluru office to secure its ITSM platform, covering manual/automated assessment, security code review, and DevOps pipeline security integration. ## Key Responsibilities - Develop and improve tools/processes for discovering and aggregating security vulnerabilities - Perform manual and automated security assessments of Atomicwork applications - Build repeatable, automated security test suites - Perform security-focused code reviews - Integrate and automate SAST in the DevOps pipeline - Support the bug bounty program ## Required Skills & Qualifications - Ability to explain common security flaws (OWASP Top 10) and remediation - Experience identifying security issues through code review - Proficient in at least one CI/CD tool (GitHub Actions, ArgoCD, Jenkins) - Proficient in Java or Python - Familiarity with security libraries/tools (SAST, proxying/pentesting tools) - Good understanding of network/web protocols (TCP, TLS, HTTPS, DNS) - Knowledge of vulnerability classes: XSS, SQL Injection, CSRF, cryptographic weaknesses, code injection ## Nice-to-Have Kubernetes, AWS, Linux proficiency; REST architecture and SQL/NoSQL database understanding. ## Benefits Comprehensive health insurance for entire family, unlimited sick leaves + 24 days off/year, flexible work timings, premium Apple hardware, flexible allowances. ## How to Prepare for This Role ### Core Technical Topics to Master OWASP Top 10 in depth, SAST/DAST tool usage, secure code review techniques, CI/CD pipeline security integration, network protocol security (TLS/HTTPS deep dive). ### Recommended Free Learning Resources - OWASP official documentation and Top 10 project - PortSwigger Web Security Academy (free) - TryHackMe free security modules - Practice: set up a personal bug bounty practice environment (e.g., OWASP Juice Shop) ### Interview Preparation - Common questions: walk through how you'd find and fix an XSS vulnerability, how do you integrate SAST into a CI/CD pipeline, explain a cryptographic weakness you've identified in review - Application asks: years of application security experience, SaaS/ITSM domain experience, and notice period ## How to Apply Apply directly via the official Greenhouse posting. ## Official Links & Resources - Official Job Posting / Apply: https://job-boards.greenhouse.io/atomicwork/jobs/4170696008 - Company: Atomicwork

Skills

OWASP Top 10SASTCI/CD SecurityJavaPythonNetwork Security

Qualifications

  • Experience identifying security issues through code review

Similar jobs