
Senior Security Engineer (Application Security)
Tekion
Posted 2026-08-17
Tech & Engg
Job Description
Ovii's Interpretation of the Role
Tekion seeks a Senior Security Engineer to embed application security throughout the software development lifecycle of its cloud‑native automotive platform. The role partners with engineering teams to drive secure‑by‑design practices, threat modeling, and DevSecOps automation across web, mobile, API, and cloud services.
Role Snapshot
- Senior Application Security Engineer
- On‑site, Bangalore HQ
- Full‑time individual contributor
- 6‑9 years of security engineering experience
- Leads threat modeling and security automation
Must-Have Requirements
- Application security
- Secure SDLC
- Threat modeling
- DevSecOps
- Security automation in CI/CD pipelines
- Proficiency in at least one programming/scripting language (Python, Bash, Java, JavaScript, Go)
- application security
- product security
- Bachelor's degree in Computer Science, Cybersecurity, or related field
- Master's degree in Computer Science, Cybersecurity, or related field
Nice-to-Have Signals
- OWASP Top 10 and ASVS knowledge
- API security expertise
- Penetration‑testing experience
- Industry‑recognized security certifications
- Familiarity with IaC, serverless, IAM
- OWASP frameworks
- penetration testing
Work Setup
- Location: Bangalore, India
- Work mode: ONSITE
- Employment type: Full-Time
Not Specified in JD
- Salary range
- Visa sponsorship
- Remote eligibility
What You'll Likely Work On
- Integrate security controls and guardrails across all SDLC phases
- Lead threat modeling and architecture reviews for high‑impact services
- Build and maintain security automation in CI/CD pipelines (SAST, DAST, SCA, secrets, IaC, API security)
- Prioritize and guide remediation of application security findings
- Create secure coding guidance, reusable patterns, and developer‑focused best practices
- Partner with product, engineering, cloud security, and infrastructure teams to reduce risk early
Good Fit If You Have
- Familiarity with IaC, serverless, and IAM concepts
- Experience with OWASP Top 10, ASVS, and API security
- Penetration‑testing exposure is a plus
- Industry‑recognized security certifications are advantageous
- Strong collaborative mindset and solution‑oriented approach
Skills
- Application security
- Secure SDLC
- Threat modeling
- DevSecOps
- SAST/DAST/SCA tooling
- CI/CD pipeline security
- Python, Bash, Java, JavaScript, Go
- Collaboration & communication