At a glance
Atomicwork is hiring an Application Security Engineer in Bengaluru — OWASP Top 10, SAST/DevOps pipeline integration, code review.
About the role
## About the Role
Atomicwork is hiring an Application Security Engineer for its hybrid Bengaluru office to secure its ITSM platform, covering manual/automated assessment, security code review, and DevOps pipeline security integration.
## Key Responsibilities
- Develop and improve tools/processes for discovering and aggregating security vulnerabilities
- Perform manual and automated security assessments of Atomicwork applications
- Build repeatable, automated security test suites
- Perform security-focused code reviews
- Integrate and automate SAST in the DevOps pipeline
- Support the bug bounty program
## Required Skills & Qualifications
- Ability to explain common security flaws (OWASP Top 10) and remediation
- Experience identifying security issues through code review
- Proficient in at least one CI/CD tool (GitHub Actions, ArgoCD, Jenkins)
- Proficient in Java or Python
- Familiarity with security libraries/tools (SAST, proxying/pentesting tools)
- Good understanding of network/web protocols (TCP, TLS, HTTPS, DNS)
- Knowledge of vulnerability classes: XSS, SQL Injection, CSRF, cryptographic weaknesses, code injection
## Nice-to-Have
Kubernetes, AWS, Linux proficiency; REST architecture and SQL/NoSQL database understanding.
## Benefits
Comprehensive health insurance for entire family, unlimited sick leaves + 24 days off/year, flexible work timings, premium Apple hardware, flexible allowances.
## How to Prepare for This Role
### Core Technical Topics to Master
OWASP Top 10 in depth, SAST/DAST tool usage, secure code review techniques, CI/CD pipeline security integration, network protocol security (TLS/HTTPS deep dive).
### Recommended Free Learning Resources
- OWASP official documentation and Top 10 project
- PortSwigger Web Security Academy (free)
- TryHackMe free security modules
- Practice: set up a personal bug bounty practice environment (e.g., OWASP Juice Shop)
### Interview Preparation
- Common questions: walk through how you'd find and fix an XSS vulnerability, how do you integrate SAST into a CI/CD pipeline, explain a cryptographic weakness you've identified in review
- Application asks: years of application security experience, SaaS/ITSM domain experience, and notice period
## How to Apply
Apply directly via the official Greenhouse posting.
## Official Links & Resources
- Official Job Posting / Apply: https://job-boards.greenhouse.io/atomicwork/jobs/4170696008
- Company: Atomicwork
Skills
OWASP Top 10SASTCI/CD SecurityJavaPythonNetwork Security
Qualifications
- Experience identifying security issues through code review