Application Security Engineer
Find the flaws in client applications before an attacker does, and help the engineers who built them fix the cause, not only the finding.
- Location
- Hyderabad
- Practice
- Application Security
- Type
- Full time
- Experience
- 3 to 6 years
- Posted
- September 2026
Findings that engineers act on, and controls that keep them fixed.
Our clients ship software several times a day, depend on hundreds of third-party components and increasingly write code with AI assistance. A penetration test before go-live no longer describes what runs in production. Our Application Security practice works at the speed of delivery: threat modelling at design, review and testing during build, and controls in the pipeline that hold release after release.
You will test web, mobile and API surfaces by hand, read the code behind what you find, and write it up so a developer can fix it and a manager can prioritise it. Then you will help engineer the checks that stop the same class of flaw coming back. Because our people move between delivery and platform engineering, you will also help review the security of Rhinexa's own products.
What you will do
- Test web applications and APIs by hand and with tools, against the OWASP Top 10:2025 and the OWASP API Security Top 10, going beyond scanner output to business logic and authorisation flaws.
- Review source code and dependencies with static analysis, software composition analysis and your own reading, and separate real risk from noise.
- Run threat-modelling sessions with client architects and engineers, and keep each model current as the system changes.
- Engineer security gates, secrets handling and software supply chain controls into client CI/CD pipelines, under the client's change process.
- Write findings that state the root cause, the evidence and the fix, then retest and confirm closure.
- Treat AI-assisted code as untrusted input: review and test it, and help clients decide how coding assistants are used.
- Contribute to security reviews of Rhinexa Niyantran, Rhinexa NMS and Rhinexa Sentinel.
What you bring
- Hands-on experience testing web applications and APIs, by hand and not only with scanners.
- Fluency with an intercepting proxy such as Burp Suite, and working knowledge of at least one static analysis tool and one software composition analysis tool.
- Enough fluency in at least one of Java, C#, JavaScript or TypeScript, Python or Go to trace a flaw to its cause and propose the fix.
- A working understanding of authentication and authorisation (OAuth 2.0, OpenID Connect, JSON Web Tokens, sessions) and of how each one fails.
- Experience with at least one CI/CD platform, such as GitHub Actions, GitLab CI, Jenkins or Azure DevOps.
- Clear written English, and the judgement to rate a finding by its business impact, not by its CVSS score alone.
Useful, not essential
- Mobile application testing on Android and iOS against the OWASP MASVS.
- Testing applications built on large language models, against the OWASP Top 10 for LLM Applications.
- Software bills of materials (CycloneDX or SPDX) and artefact signing.
- Certifications such as OSCP, OSWE, BSCP, CEH or CRTA. We weigh what you can do over what you hold.
What happens after you apply.
Rhinexa never asks candidates for payment at any stage. Report any such request to us.
Application
We review every application and reply either way.
Conversation
A call with the hiring lead about the role and your experience.
Practical
A practical exercise relevant to the work, discussed with the team.
Offer
References, offer and a planned first month.