Application Security Engineer
Who we are
DigiCert is a global leader in intelligent trust. We protect the digital world by ensuring the security, privacy, and authenticity of every interaction. Our AI-powered DigiCert ONE platform unifies PKI, DNS, and certificate lifecycle management, to secure infrastructure, software, devices, messages, AI content and agents. Learn why more than 100,000 organizations, including 90% of the Fortune 500, choose DigiCert to stop today’s threats and prepare for a quantum-safe future at
Job summary
As an Application Security Engineer within our cybersecurity team, you will help safeguard the company’s web applications and services by supporting the integration of security practices into the Software Development Life Cycle (SDLC). You will collaborate with development, DevOps, and security teams to identify, assess, and remediate vulnerabilities, contribute to secure coding practices, and assist in implementing DevSecOps tooling and processes. This role is ideal for someone with a strong technical foundation who is eager to grow within the product/application security space.
What you will do
- Support the integration of security controls and best practices across various phases of the SDLC.
- Assist in security assessments, including static and dynamic code analysis, open-source dependency analysis, and limited penetration testing.
- Participate in manual and automated code reviews to identify potential vulnerabilities and coding flaws.
- Collaborate with software engineers to promote secure development practices, including the use of security testing tools in CI/CD pipelines.
- Contribute to the evaluation, deployment, and tuning of DevSecOps tools such as SAST, DAST, and SCA platforms.
- Help maintain secure deployment workflows and support security automation efforts.
- Participate in cross-functional security reviews of new features and systems with guidance from senior engineers.
- Stay up to date on current security threats, vulnerabilities, and best practices in application security.
- Assist with triaging vulnerabilities from internal scans, bug bounty submissions, or external assessments.
- Document processes and playbooks to support consistent and scalable security practices.
- Provide input to the development of internal security standards and reference architectures.
- Support remediation efforts in collaboration with engineering teams.
- Participate in promoting a security-first culture across the organization.
- Other duties and responsibilities as assigned.
What you will have
- Bachelor’s degree in computer science, cybersecurity, or a related technical field.
- 2+ years of experience in cybersecurity, software engineering, or DevOps, with at least 1+ years focused on application or product security.
- Experience with programming/scripting languages such as Python, JavaScript, or Java.
- Familiarity with DevSecOps tools (SAST, DAST, SCA) and secure SDLC methodologies. - nice to have if they have a solid understanding of common web application vulnerabilities (e.g., OWASP Top 10, CWE).
- Solid understanding of common web application vulnerabilities (e.g., OWASP Top 10, CWE) and remediation strategies.
- Ability to analyze code and spot security issues with guidance.
- Strong communication and collaboration skills.
- Strong attention to detail and willingness to learn new technologies.
Nice to have
- Hands-on experience with CI/CD pipelines (e.g., GitHub Actions, GitLab CI, Jenkins).
- Familiarity with security standards and frameworks such as NIST, OWASP SAMM, ISO 27001, or PCI DSS.
- Experience working in a regulated environment (e.g., financial services, healthcare, or government).
- Professional certifications such as Security+, CEH, eJPT, or equivalent (OSCP or similar preferred but not required).
- Exposure to cloud platforms such as AWS, Azure, or GCP.
- Experience contributing to or managing a bug bounty triage process.
Benefits
- Generous time off policies
- Top shelf benefits
- Education, wellness and lifestyle support
To protect candidate information and maintain a secure hiring process, all applications must be submitted through our careers portal. Resumes or CVs sent directly via email will not be reviewed or considered.
#LI-SS1
As published by greenhouse
First Name, Last Name, Email, Phone, Resume/CV, Cover Letter, Location
- Have you completed secondary education or its equivalent? choose one · optional
- Are you legally authorized to work in the country in which this role is located? choose one
- Please confirm the Country in which you currently reside? choose one
- If the country you currently live in is NOT listed in the question above, please confirm in which country you live? optional
- What state are you currently located in? choose one
- If the state you currently live in is not listed above, please confirm which state you reside in. Please complete this only if you selected ‘State Not Listed’ above. optional
- What is your annual salary expectations for this role?
- Were you referred for this position? choose one
- If you were referred for this position, please provide the full name of the referrer optional
- Were you encouraged to apply to this role by an DigiCert employee? If yes, please kindly state the full name
- Can you please share the total number of years of experience you have in the industry?
- Is your current location in Bangalore?
- Can you please provide the details of your current CTC, including the fixed, variable, and RSU/ESOP components? written answer
- what are the major tech stacks you have majorly worked upon?
- What is the duration of your notice period?
- What are the reasons for your job change? written answer
- Please provide a link to your LinkedIn profile.
- As part of the employment process, all candidates are subject to employment and education verification, as well as a comprehensive background check, in accordance with applicable laws and company policies. I understand that I will be provided with additional information and asked to provide authorization before any such checks are conducted. choose one
- I understand that all information provided in my application must be accurate and truthful, and that any misrepresentation may result in disqualification from the hiring process or termination of employment if discovered after hire. choose one
- I acknowledge that DigiCert and its service providers may collect and process my image and related identity verification information to verify my identity, prevent fraud, maintain security, and administer the hiring process. I understand that this information will be used only for these purposes and retained in accordance with DigiCert's applicable policies and legal obligations. If I choose not to provide the information required to complete identity verification, DigiCert may be unable to continue processing my application. Do you acknowledge and agree? choose one