Application Security Engineer
S&P Global
- Location
- Virtual Gurugram Haryana
- Work model
- On-Site
- Level
- Mid
- H-1B history
- 10 approvals (FY2023)
- Posted
- Sep 16, 2026
Skills
About this role
About the Role
Grade Level (for internal use): 11 Job Summary We are seeking an experienced and hands-on Application Security professional to strengthen the enterprise Application Security programme. This role will focus primarily on Static Application Security Testing (SAST), security integration within CI/CD pipelines, AppSec automation, secure software development practices, cloud security governance, compliance and vulnerability management. The successful candidate will work closely with application development, DevOps, platform engineering, security architecture and risk teams to embed scalable security controls throughout the software development lifecycle. The role requires strong technical depth in application security, practical experience integrating security tools into enterprise delivery platforms and the ability to build automation that improves coverage without creating unnecessary delivery friction. The Impact Expand and improve SAST coverage across enterprise applications and repositories. Embed risk-based security controls into CI/CD pipelines and developer workflows. Reduce manual effort through reliable AppSec automation and orchestration. Improve the validation, prioritisation and remediation of application security findings. Provide developers with practical, language-specific remediation guidance. Produce dependable metrics and evidence for security governance, cloud compliance, risk and audit requirements. Strengthen governance of application workloads deployed across public cloud environments. What's in It for You Work with enterprise-scale applications, development platforms and security technologies. Influence the direction of a large-scale Application Security programme. Develop reusable security automation adopted across engineering teams. Collaborate with global product, engineering, cloud, DevOps and security stakeholders. Contribute to security standards, developer enablement and Secure SDLC transformation.
Responsibilities
SAST Programme Engineering and Operations Implement, configure, administer and optimise enterprise SAST capabilities. Onboard applications and repositories using repeatable, documented patterns. Configure scanning profiles, policies, presets, exclusions and application-specific settings. Perform detailed analysis of findings across multiple languages and frameworks. Validate false positives, duplicate findings and vulnerability classifications through secure code review. Provide practical remediation guidance and secure coding examples where appropriate. Investigate failed or incomplete scans, performance issues and integration problems. Improve scan quality through query tuning, configuration optimisation and operational metrics. Support tool migration, consolidation or rationalisation initiatives when required. CI/CD Security Integration Design and implement application security controls within CI/CD pipelines. Integrate SAST with source-code repositories, pull requests, build pipelines and developer workflows. Define proportional, risk-based security gates for builds, releases and production deployments. Create and maintain reusable pipeline templates and security components. Troubleshoot authentication, API, repository, build orchestration and scan execution issues. Partner with DevOps and platform engineering teams to improve reliability, scale and maintainability. Ensure secure handling of credentials, service accounts, tokens and secrets used by integrations. Application Security Automation Develop automation using Python, PowerShell, Bash or other suitable languages. Build integrations using REST APIs, webhooks, command-line interfaces and supported SDKs. Automate onboarding, scanning, result retrieval, triage, reporting and workflow updates. Automate finding normalisation, deduplication, enrichment, prioritisation and assignment. Integrate