Application Security Engineer (AppSec)

About the Role

Every line of code that ships in Rubiscape’s platform touches sensitive enterprise data, AI model outputs, and business-critical decisions for Fortune 500 customers. As an Application Security Engineer, you will be the security champion embedded in the software development lifecycle — owning SAST/DAST tooling, secure code review, and developer security enablement across Rubiscape’s six studios. You will transform AppSec from a gate into a growth accelerator, ensuring that Rubiscape ships fast without trading away the security posture that enterprise customers and government deployments require.


Key Responsibilities

· Integrate and operate SAST (SonarQube, Semgrep) and DAST (OWASP ZAP, Burp Suite) tooling into CI/CD pipelines; define severity thresholds and enforce build-break policies.

· Perform security design reviews and secure code reviews for high-risk features including RubiAI prompt injection surfaces, RubiStudio model serving endpoints, and multi-tenant data isolation in RubiSight.

· Maintain and continuously update Rubiscape’s secure development lifecycle (SDL) standards, OWASP Top 10 / API Security Top 10 mappings, and language-specific secure coding guidelines.

· Run bug bounty triage, coordinate responsible disclosure processes, and manage external penetration testing engagements end-to-end.

· Build automated dependency and SCA scanning (Snyk, Dependabot) into the build process; own the third-party library vulnerability backlog and drive resolution within policy SLAs.

· Deliver secure coding workshops, threat modelling training, and security champions programme for Rubiscape’s engineering guilds.

· Produce application-layer security findings for SOC 2, ISO 27001, and customer security audits; liaise with GRC on evidence collection and control mapping.

Nice to Have

· Certifications: OSWE, GWEB, or BSCP (PortSwigger Web Security).

· Experience securing LLM/GenAI application surfaces including prompt injection, model inversion, and data exfiltration via AI APIs.

· Familiarity with supply-chain security standards (SLSA, SBOM generation, Sigstore).

· Prior work on a multi-tenant B2B SaaS platform serving regulated-sector enterprise customers.




About Rubiscape

Rubiscape is India’s leading Decision Intelligence Platform, unifying data engineering, BI, machine learning, and agentic AI in a single governed platform. Built in Pune and trusted by Fortune 500 enterprises across BFSI, manufacturing, healthcare, and government. 8 international innovation patents. 10 Industry-Academia Labs & COEs. From BI to AI — One Platform. Every Decision.



Requirements

Requirements

· 3+ years of application security experience in a product engineering environment with a shipped SaaS or enterprise software product.

· Demonstrated hands-on skill with SAST/DAST tools and CI/CD integration (GitHub Actions, Jenkins, or GitLab CI).

· Strong understanding of OWASP Top 10, API Security Top 10, and common web application vulnerability classes (SQLi, XSS, SSRF, IDOR, prompt injection).

· Ability to read and review code in at least two of: Python, Java, TypeScript/Node.js, Go.

· Experience managing SCA tooling and coordinating remediation of CVEs in third-party dependencies.



See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available