yoinka

Application Security Engineer

IHS Markit

RemoteVirtual, Gurgaon, India; Hyderabad, IndiaFull TimeSenior
Sign in to applyVerified 1h ago
Location
Virtual, Gurgaon, India; Hyderabad, India
Employment
Full Time
Work model
On-Site
Level
Senior
Posted
Sep 16, 2026

Skills

AWSAzureCI/CDCybersecurityGCPGitGitHub ActionsJavaJavaScriptJenkinsPythonRESTShell

About this role

About the Role

Grade Level (for internal use): 11 Job Summary   We are seeking an experienced and hands-on Application Security professional to strengthen the enterprise Application Security programme. This role will focus primarily on Static Application Security Testing (SAST), security integration within CI/CD pipelines, AppSec automation, secure software development practices, cloud security governance, compliance and vulnerability management.   The successful candidate will work closely with application development, DevOps, platform engineering, security architecture and risk teams to embed scalable security controls throughout the software development lifecycle. The role requires strong technical depth in application security, practical experience integrating security tools into enterprise delivery platforms and the ability to build automation that improves coverage without creating unnecessary delivery friction.   The Impact   Expand and improve SAST coverage across enterprise applications and repositories.   Embed risk-based security controls into CI/CD pipelines and developer workflows.   Reduce manual effort through reliable AppSec automation and orchestration.   Improve the validation, prioritisation and remediation of application security findings.   Provide developers with practical, language-specific remediation guidance.   Produce dependable metrics and evidence for security governance, cloud compliance, risk and audit requirements.   Strengthen governance of application workloads deployed across public cloud environments.   What's in It for You   Work with enterprise-scale applications, development platforms and security technologies.   Influence the direction of a large-scale Application Security programme.   Develop reusable security automation adopted across engineering teams.   Collaborate with global product, engineering, cloud, DevOps and security stakeholders.   Contribute to security standards, developer enablement and Secure SDLC transformation.

Responsibilities

SAST Programme Engineering and Operations   Implement, configure, administer and optimise enterprise SAST capabilities.   Onboard applications and repositories using repeatable, documented patterns.   Configure scanning profiles, policies, presets, exclusions and application-specific settings.   Perform detailed analysis of findings across multiple languages and frameworks.   Validate false positives, duplicate findings and vulnerability classifications through secure code review.   Provide practical remediation guidance and secure coding examples where appropriate.   Investigate failed or incomplete scans, performance issues and integration problems.   Improve scan quality through query tuning, configuration optimisation and operational metrics.   Support tool migration, consolidation or rationalisation initiatives when required.   CI/CD Security Integration   Design and implement application security controls within CI/CD pipelines.   Integrate SAST with source-code repositories, pull requests, build pipelines and developer workflows.   Define proportional, risk-based security gates for builds, releases and production deployments.   Create and maintain reusable pipeline templates and security components.   Troubleshoot authentication, API, repository, build orchestration and scan execution issues.   Partner with DevOps and platform engineering teams to improve reliability, scale and maintainability.   Ensure secure handling of credentials, service accounts, tokens and secrets used by integrations.   Application Security Automation   Develop automation using Python, PowerShell, Bash or other suitable languages.   Build integrations using REST APIs, webhooks, command-line interfaces and supported SDKs.   Automate onboarding, scanning, result retrieval, triage, reporting and workflow updates.   Automate finding normalisation, deduplication, enrichment, prioritisation and assignment.   Integrate

Listing verified 1h ago. Applications go through the company's official careers site.

← Back to Yoinka

Application Security Engineer at IHS Markit, Virtual, Gurgaon, India; Hyderabad, India | Yoinka