---
title: "Senior Application Security Engineer at Hyland"
canonical: https://careercto.dev/jobs/senior-application-security-engineer-hyland
---

# Senior Application Security Engineer at Hyland

> Hyderabad, Telangana, India · hybrid · full-time

## About the role

Job ID 2026-14144\. A hands-on application security role in Legal & Information Security, hybrid with three days a week in the Hyderabad office\. You help build and mature the application security programme, embedded across engineering, and you help engineers deal with the security questions that AI-assisted development brings\. Mention the job ID when you send your resume\.

## What you'll do

Work with engineering, product and DevOps teams to build security into the software lifecycle, with a focus on cloud-native environments and automated pipelines\. Build and maintain security gates in CI/CD covering SAST, DAST, SCA, secrets detection and container scanning\. Improve the security posture of cloud-native environments on AWS, GCP or Azure, including Kubernetes, serverless and managed services\. Own threat modelling, code review and manual penetration testing\. Triage and fix findings from scanners and the bug bounty programme\. Write secure coding standards and developer-facing documentation\. Advise on LLM risks such as prompt injection, insecure output handling and data leakage\. Respond to application-layer security incidents and mentor engineers\.

## Looking for

5\+ years in application security, software security engineering or a close role\. Hands-on experience securing cloud-native environments on AWS, GCP or Azure, including containers, Kubernetes, IAM and serverless\. Proven experience automating SAST, DAST, SCA and secrets scanning in CI/CD such as GitHub Actions or Jenkins\. A strong command of OWASP Top 10, secure design and common vulnerability classes\. Proficiency with tools such as Checkmarx, Burp Suite, Trivy, Checkov and Veracode\. The ability to read code in at least one of Python, JavaScript/TypeScript, Java, Go or \.NET \(C\#\)\. Clear communication of risk to technical and non-technical people\.

## Nice to have

Infrastructure-as-code security with Terraform, CloudFormation or Helm, and policy-as-code such as OPA\. Familiarity with AI and LLM security risks and the OWASP Top 10 for LLMs\. Securing AI-assisted development workflows and reviewing AI-generated code\. One or more of OSCP, CISSP, CEH, GWEB or CCSP\. Prior experience in a product-led tech or SaaS environment\.


## Details

- Skills: Application Security, OWASP Top 10, SAST and DAST, threat modelling, Kubernetes, AWS, Terraform
- Published: 2026-07-14T00:00:00Z
- Apply: mailto:abhisar.garg@hyland.com
