Application Security Principal
About the role

In this role you will help secure the software we build and deliver across our platforms. Working closely with engineering teams, you will integrate security practices into the development process and ensure applications are designed and delivered with strong security foundations.

You will focus on embedding security into the software development lifecycle, helping teams identify risks early and remediate vulnerabilities without slowing down delivery. The role combines hands‑on security engineering with collaboration across architecture, engineering, product, and IT security.

What you'll do
  • Embed security practices across the software development lifecycle (SSDLC), working closely with engineering teams.

  • Define and introduce security checkpoints, such as threat modelling and secure design reviews for critical features.

  • Maintain secure coding guidelines and reference architectures that support engineering teams.

  • Integrate application security tooling into CI/CD pipelines, particularly within GitLab-based workflows.

  • Implement scanning and testing capabilities such as SAST, DAST, container scanning, and secret detection.

  • Configure policy-as-code controls to prevent critical vulnerabilities from reaching production.

  • Review and triage findings from automated security scans and third‑party tools.

  • Work with engineering leadership to prioritise vulnerability remediation and manage application risk.

  • Track vulnerability metrics and contribute to security reporting and risk visibility.

  • Provide guidance to engineers on secure coding practices and remediation approaches.

  • Contribute to internal security awareness, documentation, and developer training.

  • Act as a technical point of contact for application security during audits, reviews, and security assessments.

What you'll bring
  • Experience working in application security, DevSecOps, or software engineering roles.

  • Strong understanding of secure coding principles and common vulnerabilities such as those described in the OWASP Top 10 and CWE.

  • Practical experience integrating security tooling into CI/CD pipelines, particularly GitLab CI/CD.

  • Familiarity with tools used for application security testing such as Snyk, Semgrep, Checkmarx, or similar.

  • Experience reviewing application code and infrastructure-as-code (preferably Terraform) for security issues.

  • Understanding of modern cloud-native architectures and their security considerations, including containers, APIs, and microservices.

  • Familiarity with identity and access management concepts across cloud platforms such as AWS, Azure, or GCP.

  • Ability to work collaboratively with engineering teams and influence secure development practices.

  • Strong communication skills and a pragmatic, solution‑oriented mindset.

  • Curiosity and willingness to stay current with evolving application security threats and practices.

  • Relevant certifications are a plus (e.g. CSSLP, OSCP).

Contact

Connect with us for partnerships or services today. Reach out to discuss how our engineering and creative studios can power your business, expand your portfolio, and scale global operations seamlessly.

Email

sales@spinfishentertainment.com

© 2026 Spinfish Entertainment Pvt. Ltd. All rights reserved.