Alaan
Posted 1mo ago

Application Security Engineer

Alaan
Bengaluru, Karnataka, India
HybridFull Time
Responsibilities
  • securing applications
  • reviewing configurations
  • triaging incidents
Requirements
  • 3+ years in application/product security
  • OWASP Top 10 knowledge
  • Threat modeling
  • Secure code reviews, IAM
  • Logging
  • Secrets management
  • Experience with SAST/SCA/DAST/IaC scanning and cloud security (AWS/GCP) preferred
Technical tools mentioned
AWSGCPSASTSCADASTIaC scanningSIEM

Job description


About the role

We are looking for an Application or Product Security Engineer with ~3–5 years of hands-on experience in securing web and mobile applications, APIs and cloud infrastructure. 

In this role, you will take ownership of securing our Applications, APIs and cloud resources, working closely with Development teams to continuously harden our applications and infrastructure in alignment with industry leading standards.


What you'll do
  • Secure Web & Mobile applications, APIs by performing application security reviews/testing, identifying vulnerabilities, and working with engineering teams on remediation.
  • Support security of AWS and GCP environments, including access reviews, network security, storage security, logging, and encryption best practices. 
  • Review cloud and infrastructure configurations to identify misconfigurations
  • Support investigations during incidents triaging by reviewing security logs and alerts
  • Contribute to security guidelines, standards, and continuous improvement of the security posture.
What we are looking for
  • 3–5 years of experience in Application Security or Product Security roles. 
  • Practical experience securing web applications and APIs, with a solid understanding of OWASP Top 10 and common attack vectors. 
  • Experience in threat modeling & secure code reviews.
  • Good understanding of authentication & authorization flows.
  • Understanding of secrets management and prevention of credential leaks.
  • Working knowledge of IAM, networking, logging, and storage security. 
  • Experience using security scanning tools (SAST, SCA, DAST, IaC scanning) and validating findings.
  • Ability to collaborate effectively with engineering teams and communicate security risks clearly.

Bonus

  • Experience of AWS or GCP security.
  • Experience working in Financial, Banking, NBFC, FinTech or regulated environments.
  • Basic understanding of logs and usage of SIEM tools for alert triage and investigation.
  • Familiarity with compliance frameworks such as ISO 27001, SOC 2, or PCI DSS.
What's in it for you
  • Contribute to building the Middle East’s most beloved fintech brand from the ground up
  • Benefit from a role with significant ownership and accountability
  • Thrive in a flexible hybrid culture with ample work-life balance
  • Participate in exciting offsite events
  • Competitive salary and equity
  • Enjoy additional perks like travel allowances, gym memberships, and more

About Alaan

Alaan is the Middle East’s first AI-powered spend management platform, built to help businesses save time and money.
Our all-in-one solution combines smart corporate cards, real-time expense tracking, AI-powered automation, seamless accounting integrations, and deep financial insights- designed to simplify finance operations and maximize control over company spend.

Founded in 2022, Alaan is already the trusted partner of over 2000 leading businesses across the UAE and KSA, including G42, Careem, McDonald’s, Tabby, Al Barari, Rove Hotels, Rivoli, and CarSwitch. Together, our customers have saved over AED 100 million with Alaan.

In just three years, Alaan has become the #1 expense management platform in the Middle East- and we’ve done it while becoming profitable.

Backed by Y Combinator and top global investors- including founders and executives of leading startups- Alaan is built by a world-class team from McKinsey, BCG, Goldman Sachs, Barclays, Zomato, Careem, Rippling, and other high-growth companies.

We’re not just building software. We’re reimagining how finance works for modern businesses across the region.

About Alaan

Corporate card and spend management platform for businesses.

Year founded
2021
Employees
200
Organization type
Private
Latest investment
Raised $48.00M Series A (2025) — led by Peak XV Partners
Headquarters
AE

Similar jobs

Application Security Engineer roles near Bengaluru, Karnataka
1d
Save
Mark Applied
Hide
Application Security Engineer
Bengaluru or Kochi
OnsiteFull Time
UST
UST: Global provider of digital transformation and IT services.
5+ YOERequires 5+ years in software security using two or more languages, web applications, web services, and service-oriented architectures, with SCA, SAST, DAST, cloud, and vulnerability remediation experience.
AWS, Angular, Go, Python, Fortify, SAST, DAST, OWASP Top 10, Git, SCA, Veracode, Checkmarx
6d
Save
Mark Applied
Hide
ERP Specialist
Bangalore, Karnataka, India
OnsiteFull Time
HCLTech
HCLTechNational Stock Exchange of India: HCLTECH: Global technology providing digital, engineering, and cloud services.
6+ YOEBachelor's degree in IT, IT Security, or related field; 6+ years in application security; secure coding, vulnerability remediation, Python, YAML, CI/CD, Azure DevOps, SAST, secret scanning, and English proficiency.
Python, YAML, Azure DevOps, GitHub, SAST, CI/CD, Azure, OWASP Top 10
1w
Save
Mark Applied
Hide
Senior Engineer, Application Security
Pune or Bangalore
OnsiteFull Time
Danaher
DanaherNYSE: DHR: Develops scientific instruments and diagnostic tools for healthcare markets.
5+ YOEBachelor's degree in cybersecurity, computer science, software engineering, or related field; 5+ years in application or product security; AppSec testing, secure design, threat modeling, and CI/CD tooling experience.
SAST, DAST, SCA, IaC, SBOM, OSS, CI/CD, Snyk, Veracode, Checkmarx, Semgrep, GitHub Advanced Security, Kubernetes, AI, LLM
3w
Save
Mark Applied
Hide
Application Security Engineer - ADR, AVP
Bangalore or Hyderabad
HybridFull Time
State Street
State StreetNYSE: STT: Provides investment servicing and management to institutional investors.
11+ YOEExpertise in application security, ADR/RASP/WAAP, threat detection, secure SDLC, DevSecOps, cloud (Azure/AWS), modern development stacks, and automation; relevant security certifications preferred.
Java, .NET, Python, Node.js, Azure, AWS, SAST, DAST, SCA, API Security, Container Security, Runtime Application Self-Protection (RASP), Web Application and API Protection (WAAP), OWASP Top 10, Ansible, Terraform, Kubernetes, CI/CD, DevOps, Infrastructure as Code (IaC), Agile Development
3w
Save
Mark Applied
Hide
Staff Application Security Engineer
Bengaluru, Karnataka, India
HybridFull Time
Publicis Groupe
Publicis GroupeEuronext Paris: PUB: Global communications, advertising, and digital transformation holding.
2+ YOE2+ years application security or associate degree, experience with Veracode/SonarQube/Wiz, Bash/Ansible/Terraform, Microsoft Office, strong collaboration, analytical and coaching skills, and experience embedding AI into engineering workflows.
Veracode, SonarQube, Wiz, Microsoft Outlook, Microsoft Excel, Microsoft Word, Microsoft PowerPoint, Bash, Ansible, Terraform
3w
Save
Mark Applied
Hide
Staff Application Security Engineer
Bengaluru, Karnataka, India
OnsiteFull Time
Publicis Groupe
Publicis GroupeEuronext Paris: PUB: Global advertising and digital transformation agency holding.
2+ YOEProvide strategic oversight of application security platforms, guide teams on findings and remediation, embed AI-enabled secure development practices, and coach engineering teams on secure coding.
Veracode, SonarQube, Wiz, Microsoft Outlook, Microsoft Excel, Microsoft Word, Microsoft PowerPoint, Bash, Ansible, Terraform
3w
Save
Mark Applied
Hide
Assistant Manager | Web/Mobile/API Application Security | Bengaluru | Cyber Defense & Resilience | A
Bengaluru, Karnataka, India
OnsiteFull Time
Deloitte
Deloitte: Professional services firm providing audit, consulting, and advisory services.
2+ YOE2+ years application security experience; perform web/mobile/API assessments, validate vulnerabilities, use Burp Suite/OWASP ZAP/MobSF/Postman, strong auth/session/encryption knowledge, secure SDLC experience.
Burp Suite, OWASP ZAP, MobSF, Postman
1mo
Save
Mark Applied
Hide
Senior Application Security Engineer
Bangalore, Karnataka, India
HybridFull Time
Jumio
Jumio: Automated identity verification and KYC compliance software solutions.
10+ YOE10+ years in security engineering focused on application and cloud security; experience with pen testing, threat modeling, IaC, containers, and cloud services; strong communication skills.
Linux, Amazon AWS, GCP, EC2, ECS, Lambda, RDS, Docker, Kubernetes, OWASP, CWE 25, SAST, DAST, IAST, SCA, Python, AWS DevOps, Github Actions, Jenkins, LLMs