Technology & Intelligence Ref XE-TEC-198 Closes in 4 days

Application Security Engineer

Make security a design input on every build, from threat model to release, including the AI systems we ship.

Illustrative opening — hiring confirms the details before it opens.

Share Email it
Two engineers at a desk discussing code on a monitor, one leaning over the other's shoulder.
The practiceTechnology & Intelligence
Practice
Technology & Intelligence
Location
Remote (India)
Work pattern
Remote
Level
Senior
Type
Full-time
Experience
5+ years
Salary band
₹26–40 lakh a year Indicative
Openings
1
Posted
Closes
4 days left

About the role

You will make sure what we build is secure by design, not by audit. That means threat models before code, scanning in the pipeline, and findings written so developers act on them.

A growing share of the work is AI: red-teaming features for prompt injection and data exfiltration, and helping clients map their controls to the frameworks they report against — ISO/IEC 27001, the DPDP Act, and newer AI-specific ones.

What you will do

  1. Threat-model new products and features with the teams building them
  2. Own SAST, dependency and secrets scanning in CI
  3. Red-team AI features for injection and data exfiltration
  4. Help clients map controls to the frameworks they report against
  5. Write findings that are specific, ranked and fixable

A typical week

Where the hours go in an ordinary week, and which parts agents carry. Whatever an agent drafts or checks, a person decides what happens next.

Application Security Engineer 40 hours in a typical week
  • You24 h · 60%
  • You, with an agent drafting8 h · 20%
  • An agent runs it, you review8 h · 20%
  1. Threat modelling with build teams

    Before code: what could go wrong, and what to build in.

    You8 h

  2. Pipeline scanning and triage

    SAST, dependency and secrets scanners run on every change; you triage what they raise and tune out the noise.

    An agent runs it, you review8 h

  3. Red-teaming AI features

    An agent generates attack variants; you design the attacks that matter and judge the results.

    You, with an agent drafting8 h

  4. Writing findings and fixes

    Specific, ranked and fixable — written for the developer who has to act on them.

    You8 h

  5. Mapping client controls

    ISO/IEC 27001, the DPDP Act and the newer AI frameworks clients report against.

    You8 h

An illustrative split, not a timesheet. The hiring lead walks you through the real one in your first conversation.

What you bring

  • 5+ years in application security or security engineering
  • Hands-on with OWASP ASVS and secure code review
  • Clear written findings that developers act on
  • Familiarity with the DPDP Act and GDPR

Nice to have

  • Cloud security posture tooling
  • ISO 27001 or SOC 2 audits from the delivery side

Never a reason to rule anyone out. If you have most of the list above and none of this, apply.

Tools you will use

Grouped by what they are for. Nobody knows all of them on day one.

Containers, IaC & CI/CD
  • GitHub Actions
  • Kubernetes
Testing & quality
  • SonarQube
Security & identity
  • OWASP
  • Burp Suite
  • Snyk
  • Trivy
  • Vault

Technologies we work with and license — not partnerships.

Your first 90 days

  1. Days 1–30

    Review the pipeline scanning on two live projects and close the gaps you find

  2. Days 31–60

    Run a threat-modelling session for a new client build

  3. Days 61–90

    Red-team one AI feature and turn the findings into eval cases the team keeps

A hand-drawn goal review on dot-grid paper: tallies for weeks one to eleven beside an assess-and-plan column, two pens resting on the page.
The plan is written down before your first day, and you review it with your lead as the weeks go by.

Where you would work

The places this role can be based. Each team agrees its own studio days; remote roles meet in a studio for a team week each quarter.

  • Two people talking over a laptop at a café table on a balcony in Dharamkot, Himachal Pradesh, forested hills behind them.

    Remote

    Anywhere in India

    For roles marked remote: anywhere in India, with a team week in a studio each quarter.

    Pictured: Dharamkot, Himachal Pradesh

How and where we work

What we offer

With every role

  • Health and family

    Medical insurance · Parental leave · Mental health

  • Time

    Paid leave · Winter break · Flexible days

  • Growth

    Learning budget · Growth reviews · Internal moves

  • Setup

    Your own machine · Home office · Team weeks

The full benefits schedule

The team you would join

Technology & Intelligence, the practice behind this role.

Engineers who build websites, platforms, data systems and AI products, with tests, evals and security in the pipeline on every change.

Open roles in this practice
4 on the board
Based in
Remote (India) · New Delhi · Ludhiana

Where this role sits

L4 of 6 · Senior

Owns a workstream. Sets the approach and grows others.

Each level is defined by the scope you own, not years served. Growth reviews twice a year measure you against the six standards at your level.

Ways in, and ways up
  1. L1 Intern A task
  2. L2 Associate A deliverable
  3. L3 Mid A feature
  4. This role L4 Senior A workstream
  5. L5 Lead An engagement
  6. L6 Principal A practice

The rung below

L3 · Mid — A feature. Owns a piece of work end to end.

Next rung

L5 · Lead — An engagement. Leads a team and the client relationship.

How we hire for this role

5 steps, and a reply after every one.

The same five stages we use for every role. Timings are targets; when one slips, we tell you.

  1. Within 5 working days

    Step 1: Read

    A practitioner in the practice reads your application — your links first, your CV second. No keyword filter, no agency.

  2. Week 1 · 45 min

    Step 2: Conversation

    The hiring lead: the role, your work, and the level and salary band — before you invest more time in us.

  3. Week 2 · 2–3 h, paid

    Step 3: Work sample

    A short exercise close to the job, or a deep review of work you have already done. Paid, and never unpaid spec work.

    Work sample · the brief
  4. Week 3 · half a day

    Step 4: Team day

    Meet the people you would work with, in a studio or on video. Ask them anything; they will answer honestly.

  5. Week 3–4

    Step 5: Offer

    In writing, with the level, the salary, the full benefits and a start date that suits you. No exploding deadlines.

What helps an application

  • A link to work you made, with your own part in it named.
  • One project you could talk through for half an hour.
  • If you used AI, a line on how you checked what it produced.
  • Plain words. We read for substance, not polish.

Adjustments. Extra time, questions in advance, captions, a different format — tell us on the form or by email. Asking never counts against you.

Start the application

Application Security EngineerRemote (India) · Remote · Closes in 4 days

Apply for this role

Your move

Not the right role yet? Tell us what you would build here.

A speculative application gets the same read as any other: a practitioner in the practice you choose, and a reply either way.