Ovii Job Board

Senior Security Engineer (Application Security)

Tekion

Bengaluru, India • Onsite - Bengaluru, India • Full-Time • 6-9 years

Posted 2026-08-17 Tech & Engg

Apply on employer site

Job Description

Ovii's Interpretation of the Role

Tekion seeks a Senior Security Engineer to embed application security throughout the software development lifecycle of its cloud‑native automotive platform. The role partners with engineering teams to drive secure‑by‑design practices, threat modeling, and DevSecOps automation across web, mobile, API, and cloud services.

Role Snapshot

  • Senior Application Security Engineer
  • On‑site, Bangalore HQ
  • Full‑time individual contributor
  • 6‑9 years of security engineering experience
  • Leads threat modeling and security automation

Must-Have Requirements

  • Application security
  • Secure SDLC
  • Threat modeling
  • DevSecOps
  • Security automation in CI/CD pipelines
  • Proficiency in at least one programming/scripting language (Python, Bash, Java, JavaScript, Go)
  • application security
  • product security
  • Bachelor's degree in Computer Science, Cybersecurity, or related field
  • Master's degree in Computer Science, Cybersecurity, or related field

Nice-to-Have Signals

  • OWASP Top 10 and ASVS knowledge
  • API security expertise
  • Penetration‑testing experience
  • Industry‑recognized security certifications
  • Familiarity with IaC, serverless, IAM
  • OWASP frameworks
  • penetration testing

Work Setup

  • Location: Bangalore, India
  • Work mode: ONSITE
  • Employment type: Full-Time

Not Specified in JD

  • Salary range
  • Visa sponsorship
  • Remote eligibility

What You'll Likely Work On

  • Integrate security controls and guardrails across all SDLC phases
  • Lead threat modeling and architecture reviews for high‑impact services
  • Build and maintain security automation in CI/CD pipelines (SAST, DAST, SCA, secrets, IaC, API security)
  • Prioritize and guide remediation of application security findings
  • Create secure coding guidance, reusable patterns, and developer‑focused best practices
  • Partner with product, engineering, cloud security, and infrastructure teams to reduce risk early

Good Fit If You Have

  • Familiarity with IaC, serverless, and IAM concepts
  • Experience with OWASP Top 10, ASVS, and API security
  • Penetration‑testing exposure is a plus
  • Industry‑recognized security certifications are advantageous
  • Strong collaborative mindset and solution‑oriented approach

Skills

  • Application security
  • Secure SDLC
  • Threat modeling
  • DevSecOps
  • SAST/DAST/SCA tooling
  • CI/CD pipeline security
  • Python, Bash, Java, JavaScript, Go
  • Collaboration & communication