Overview
Lead Application Security Jobs in Greater Bengaluru Area at Capillary Technologies
Title: Lead Application Security
Company: Capillary Technologies
Location: Greater Bengaluru Area
About the Role :
Capillary Technologies is an enterprise-grade SaaS platform in the loyalty space, enabling global brands to drive customer engagement and business growth.
We are looking for a Lead – Application Security to embed security into our product engineering lifecycle and drive a developer-first security culture. This role goes beyond traditional VAPT and focuses on secure architecture, DevSecOps, and scalable security automation.
What You’ll Do
- Lead application security strategy across product and engineering teams
- Perform secure design reviews, architecture reviews, and threat modeling (STRIDE, etc.)
- Drive secure SDLC practices across Agile/DevOps teams
- Integrate and scale SAST, DAST, SCA, and secrets scanning into CI/CD pipelines
- Partner closely with backend/frontend engineers to fix vulnerabilities and improve secure coding practices
- Build and automate security testing frameworks and pipelines
- Analyze security findings, reduce false positives, and prioritize risk-based remediation
- Own application security posture for web apps, APIs, and cloud-native services
- Evaluate and onboard security tools and vendors
- Stay updated with OWASP Top 10, API Security, cloud security, and emerging threats
What We’re Looking For
- 6+ years in Application Security / Product Security / DevSecOps
- Strong development background (Java / Python / Node.js or similar)
- Hands-on experience in secure coding & code reviews
- Experience working in SaaS / cloud-native environments (AWS/GCP/Azure)
- Strong exposure to:
- Secure SDLC & DevSecOps practices
- SAST, DAST, SCA tools (e.g., Checkmarx, Fortify, Burp, etc.)
- API security, authentication, cryptography basics
- Experience with CI/CD pipelines (Jenkins, GitHub Actions, etc.)
- Understanding of microservices architecture & distributed systems
- Exposure to threat modeling and risk assessment frameworks
- Ability to work closely with developers and influence engineering decisions
Good to Have
- Experience with cloud security (IAM, containers, Kubernetes security)
- Knowledge of security standards like ISO 27001, SOC 2, PCI-DSS, GDPR
- Experience in automating security workflows or building internal tools
- Contributions to open-source security tools / research
Why Join Us?
- Work on large-scale SaaS systems used by global brands
- Opportunity to shape security architecture at scale
- Collaborate with strong product & engineering teams
- Drive real impact beyond compliance (build vs audit mindset)