- Home
- Jobs
- IT, Security & Infrastructure
- Application Security Engineer

Application Security Engineer at Bottomline Technologies
IndiaFull-timeIT, Security & InfrastructurePosted 13 days ago
Apply with PipelineAbout the Role
<div class="content-intro"><h2>Why Choose Bottomline?</h2>
<p>Are you ready to transform the way businesses pay and get paid? Bottomline is a global leader in business payments and cash management, with over 35 years of experience and moving more than $16 trillion in payments annually. We're looking for passionate individuals to join our team and help drive impactful results for our customers. If you're dedicated to delighting customers and promoting growth and innovation - we want you on our team!</p></div><p> </p>
<table data-tablestyle="MsoTableGrid" data-tablelook="1184">
<tbody>
<tr>
<td data-celllook="4369">
<p><span data-contrast="none">As an Application Security Engineer, you will play a critical role in strengthening the organisation’s application security posture by supporting our penetration testing and application code scanning programmes. This role is responsible for identifying vulnerabilities, analysing security patterns and behaviours, and contributing to the continuous improvement of secure development practices across the software lifecycle.</span><span data-ccp-props="{"335559738":120,"335559739":120}"> </span></p>
<p><span data-contrast="none">You will work closely with Product, Engineering, and Security teams to proactively identify and reduce risk exposure, supporting our threat exposure management approach across all applications. The role requires strong technical expertise combined with the ability to communicate complex security risks clearly and effectively to both technical and non-technical stakeholders.</span><span data-ccp-props="{"335559738":120,"335559739":120}"> </span></p>
<p><span data-ccp-props="{"335559738":120,"335559739":120}"> </span><strong><span data-contrast="none">Essential Functions and Responsibilities: </span></strong><span data-ccp-props="{"335559738":120,"335559739":120}"> </span></p>
</td>
</tr>
<tr>
<td data-celllook="4369">
<ul>
<li data-leveltext="·" data-font="Symbol" data-listid="7" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"·","469777815":"hybridMultilevel"}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="none">Orchestrate application p<strong>enetration testing</strong> across web, API, and service-based architectures</span><span data-ccp-props="{"335559739":0}"> </span></li>
</ul>
<ul>
<li data-leveltext="·" data-font="Symbol" data-listid="7" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"·","469777815":"hybridMultilevel"}" data-aria-posinset="2" data-aria-level="1"><span data-contrast="none">Support application security scanning tools (SAST, SCA, DAST) and CI/CD pipeline integration</span><span data-ccp-props="{"335559739":0}"> </span></li>
</ul>
<ul>
<li data-leveltext="·" data-font="Symbol" data-listid="7" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"·","469777815":"hybridMultilevel"}" data-aria-posinset="3" data-aria-level="1"><span data-contrast="none">Analyse vulnerabilities to identify patterns, behaviours, and root causes, not just individual findings</span><span data-ccp-props="{"335559739":0}"> </span></li>
</ul>
<ul>
<li data-leveltext="·" data-font="Symbol" data-listid="7" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"·","469777815":"hybridMultilevel"}" data-aria-posinset="4" data-aria-level="1"><span data-contrast="none">Support prioritisation and provide guidance for remediation based on risk and threat exposure</span><span data-ccp-props="{"335559739":0}"> </span></li>
</ul>
<ul>
<li data-leveltext="·" data-font="Symbol" data-listid="7" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"·","469777815":"hybridMultilevel"}" data-aria-posinset="5" data-aria-level="1"><span data-contrast="none">Contribute to improving coverage, consistency, and reliability of application security testing</span><span data-ccp-props="{"335559739":120}"> </span></li>
</ul>
<ul>
<li data-leveltext="·" data-font="Symbol" data-listid="7" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"·","469777815":"hybridMultilevel"}" data-aria-posinset="6" data-aria-level="1"><span data-contrast="none">Support multiple projects and initiatives in parallel</span> </li>
</ul>
</td>
</tr>
</tbody>
</table>
<p><strong><span data-contrast="none"> Required Experience & Qualifications</span></strong><span data-ccp-props="{"335559738":120,"335559739":120}"> </span></p>
<ul>
<li data-leveltext="·" data-font="Symbol" data-listid="7" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"·","469777815":"hybridMultilevel"}" data-aria-posinset="7" data-aria-level="1"><span data-contrast="none">3+ years’ experience in <strong>Application Security, Penetration Testing, or Secure Code Scanning</strong></span><span data-ccp-props="{"335559739":0}"> </span></li>
</ul>
<ul>
<li data-leveltext="·" data-font="Symbol" data-listid="7" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"·","469777815":"hybridMultilevel"}" data-aria-posinset="8" data-aria-level="1"><span data-contrast="none">Hands-on experience with p<strong>enetration testing techniques and tools</strong></span><span data-ccp-props="{"335559739":0}"> </span></li>
</ul>
<ul>
<li data-leveltext="·" data-font="Symbol" data-listid="7" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"·","469777815":"hybridMultilevel"}" data-aria-posinset="9" data-aria-level="1"><span data-contrast="none">Experience with application security scanning platforms (SAST, SCA, DAST)</span><span data-ccp-props="{"335559739":0}"> </span></li>
</ul>
<ul>
<li data-leveltext="·" data-font="Symbol" data-listid="7" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"·","469777815":"hybridMultilevel"}" data-aria-posinset="10" data-aria-level="1"><span data-contrast="none">Strong understanding of common <strong>vulnerability patterns</strong> (e.g. OWASP Top 10)</span><span data-ccp-props="{"335559739":0}"> </span></li>
</ul>
<ul>
<li data-leveltext="·" data-font="Symbol" data-listid="7" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"·","469777815":"hybridMultilevel"}" data-aria-posinset="11" data-aria-level="1"><span data-contrast="none">Knowledge of modern environments (APIs, microservices,<strong> CI/CD pipelines</strong>)</span><span data-ccp-props="{"335559739":120}"> </span></li>
</ul>
<ul>
<li data-leveltext="·" data-font="Symbol" data-listid="7" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"·","469777815":"hybridMultilevel"}" data-aria-posinset="12" data-aria-level="1"><span data-contrast="none">Strong analytical, problem-solving, and communication skills</span><span data-ccp-props="{"335559739":120}"> </span></li>
</ul>
<p><span data-ccp-props="{"335559739":0}"> </span><strong><span data-contrast="none">Preferred Experience & Qualifications</span></strong><span data-ccp-props="{"335559738":120,"335559739":120}"> </span></p>
<ul>
<li data-leveltext="·" data-font="Symbol" data-listid="4" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"·","469777815":"hybridMultilevel"}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="none">Experience with platforms such as <strong>Veracode</strong>, Burp Suite, OWASP ZAP, or similar</span><span data-ccp-props="{"335559739":0}"> </span></li>
</ul>
<ul>
<li data-leveltext="·" data-font="Symbol" data-listid="4" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"·","469777815":"hybridMultilevel"}" data-aria-posinset="2" data-aria-level="1"><span data-contrast="none">Understanding of risk-based or threat exposure management models</span><span data-ccp-props="{"335559739":0}"> </span></li>
</ul>
<ul>
<li data-leveltext="·" data-font="Symbol" data-listid="4" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"·","469777815":"hybridMultilevel"}" data-aria-posinset="3" data-aria-level="1"><span data-contrast="none">Experience working with development teams in secure coding practices</span><span data-ccp-props="{"335559739":0}"> </span></li>
</ul>
<ul>
<li data-leveltext="·" data-font="Symbol" data-listid="4" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"·","469777815":"hybridMultilevel"}" data-aria-posinset="4" data-aria-level="1"><span data-contrast="none">Relevant certifications such as:</span> <br><span data-contrast="none">OSCP, OSWE, GWAPT, GPEN, CEH, CSSLP, CISSP or CISM</span><span data-ccp-props="{"335559739":0}"> </span></li>
</ul>
<p><span data-contrast="none"> </span><span class="NormalTextRun SCXW190499575 BCX8">Note</span><span class="NormalTextRun SCXW190499575 BCX8">: This</span><span class="NormalTextRun SCXW190499575 BCX8"> job description is not intended to be an exhaustive list of all duties, responsibilities, or qualifications associated with the position.</span></p><div class="content-conclusion"><p>We welcome talent at all career stages and are dedicated to understanding and supporting additional needs. We're proud to be an equal opportunity employer, committed to creating an inclusive and open environment for everyone.</p></div>
Related Roles
Application Security Analyst
Bottomline Technologies
IndiaData Loss Prevention Analyst II
Bottomline Technologies
IndiaAI Security Architect
Bottomline Technologies
IndiaData Engineer
Bottomline Technologies
IndiaVendor Success Associate
Bottomline Technologies
IndiaCustomer Support Trainer
Bottomline Technologies
India