Senior Application Security Engineer
This role has been designed as 'Hybrid' with an expectation that you will work on average 2 days per week from an HPE office.
Who We Are:
Hewlett Packard Enterprise is the global edge-to-cloud company advancing the way people live and work. We help companies connect, protect, analyze, and act on their data and applications wherever they live, from edge to cloud, so they can turn insights into outcomes at the speed required to thrive in today's complex world. Our culture thrives on finding new and better ways to accelerate what's next. We know varied backgrounds are valued and succeed here. We have the flexibility to manage our work and personal needs. We make bold moves, together, and are a force for good. If you are looking to stretch and grow your career our culture will embrace you. Open up opportunities with HPE.
Job Description:
About Our Cybersecurity Team:
Are you ready to make an impact at one of the world's leading tech companies? HPE's Cybersecurity team is where you can do just that! We're looking for an Expert level Cybersecurity Incident Response Analyst to join our Incident Command team in Bangalore.
As an expert you will be responsible for leading the detection, analysis, containment, and remediation of cybersecurity incidents across the organization. This role demands a deep technical understanding of cyber threats, advanced incident handling skills, and the ability to act decisively in high-pressure situations. You will work closely with other cybersecurity teams to ensure a coordinated and effective response to security incidents, helping to minimize the impact on the organization. Within the scope of the role will be mentoring junior team members and contributing to the continuous improvement of the organization's incident response capabilities.
What You'll Do:
Key Responsibilities:
- Secure SDLC & DevSecOps Integration – Partner with engineering and DevOps teams to embed security into the entire software delivery process.
- Software Delivery Pipeline (CI/CD) Security –
- Design and implement security controls for build and release pipelines (GitHub Actions, Jenkins, GitLab, Azure DevOps, etc.).
- Ensure code integrity via signing, artifact scanning, and build provenance.
- Automate SAST, DAST, SCA, and container image scanning as part of the software delivery pipeline.
- Identify and remediate misconfigurations in pipeline environments and access control.
- Web & API Security – Design, implement, and monitor WAF rules and API protections, perform API risk assessments, and champion secure design patterns.
- Code Review & Testing – Conduct secure code reviews and support automation of testing pipelines.
- Vulnerability Management – Triage, prioritize, and track security issues identified in code, pipelines, and deployed environments.
- Threat Modeling & Risk Assessment – Facilitate threat modeling sessions for applications, APIs, and pipeline workflows.
- Tooling & Automation – Expand security automation coverage, including API discovery, dependency scanning, SBOM generation, and secrets detection.
- Security Champion Enablement – Mentor developers and DevOps engineers on secure pipeline and coding practices.
- Collaboration & Advisory – Act as a trusted partner to product, platform engineering, and DevOps leaders, translating security risk into business impact.
- Incident Support – Collaborate with SOC/IR teams in response to software supply chain or pipeline compromises.
What You Need To Bring:
Qualifications Required:
- 5–8+ years of experience in Application Security, Product Security, or Secure Software Development.
- Hands-on experience securing software delivery pipelines (CI/CD) and source code repositories (GitHub, GitLab, Jenkins).
- Knowledge of supply chain security frameworks and controls (e.g., SLSA, NIST SSDF).
- Familiarity with secrets management, artifact signing (Sigstore, Cosign), and build integrity practices.
- Hands-on experience with WAF tuning, API security controls, and vulnerability remediation.
- Proficiency with one or more programming languages (Python, Java, Go, JavaScript/Node.js).
- Experience with SAST, DAST, SCA, and container image scanning tools.
- Cloud security experience with AWS, Azure, or GCP.
- Deep understanding of OWASP Top 10 (Web + API), CWE, and secure coding practices.
Preferred:
- Experience integrating SBOM generation and software composition analysis into software delivery pipelines.
- Knowledge of runtime protection tools (API security, RASP, EDR for containers).
- Familiarity with GitOps, Infrastructure as Code (IaC) scanning (Terraform, CloudFormation), and policy-as-code solutions.
- Experience responding to pipeline compromises or dependency poisoning incidents.
- Relevant certifications: OSWE, CSSLP, GPCS, GIAC GWEB, GIAC Cloud Security Automation (GCSA).
Soft Skills:
- Excellent communication skills with the ability to influence developers, DevOps engineers, and leadership.
- Strong problem solving mindset with an automation first approach.
- Collaborative, outcome oriented, and able to balance security with speed of delivery.
What We Can Offer You:
Health & Wellbeing:
We strive to provide our team members and their loved ones with a comprehensive suite of benefits that supports their physical, financial and emotional wellbeing.
Personal & Professional Development:
We also invest in your career because the better you are, the better we all are. We have specific programs catered to helping you reach any career goals you have — whether you want to become a knowledge expert in your field or apply your skills to another division.
Unconditional Inclusion:
We are unconditionally inclusive in the way we work and celebrate individual uniqueness. We know varied backgrounds are valued and succeed here. We have the flexibility to manage our work and personal needs. We make bold moves, together, and are a force for good.