Vacancy description
finalsite
Chennai, भारत
The Senior Application Security Engineer is responsible for identifying, triaging, and remediating security vulnerabilities across Finalsite’s web applications and proprietary software systems. Working closely with the core development and quality assurance teams, this role modifies and refactors application code, implements secure coding practices, and ensures robust security controls across internal pipelines, cloud integrations, and student data environments. The position plays a direct role in maintaining compliance with educational data privacy laws (FERPA/COPPA) and international standards (GDPR/UK GDPR) while defending Finalsite applications against modern cyber threats.
Key Responsibilities
Vulnerability Triage & Assessment: Conducts technical triage on security vulnerabilities identified across web applications via Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), penetration testing reports, and bug bounty programs.
Code Remediation & Refactoring: Modifies and refactors .NET/C# code to remediate identified security vulnerabilities in accordance with established risk prioritization schedules.
Secure SDLC & Frameworks: Develops, maintains, and enforces secure coding standards across development teams; implements reusable secure coding patterns (e.g., Object-Relational Mapping (ORM), output encoding frameworks) to catch vulnerabilities early in the software development life cycle.
Developer Assistance & Code Reviews: Directly assists software developers with code reviews to verify adherence to secure coding guidelines and remediate complex security flaws.
Threat Monitoring: Stays current on emerging web application threats, exploit techniques, and iterations of the OWASP Top 10.
Data Privacy & Compliance Support: Ensures application security controls comply with central, state, and international Data Protection Laws
Qualifications and Skills
Required:
Education: Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
Experience: Minimum 7+ years of dedicated hands-on experience in application security.
Development Expertise: Strong, hands-on software development experience with .NET/C# refactoring and remediation.
Security Knowledge: In-depth understanding of web application vulnerabilities, remediation techniques, and the OWASP Top 10.
Testing Tools & Programs: Direct experience working with SAST, DAST, third-party penetration testing reports, and bug bounty management.
Soft Skills: Excellent problem-solving skills, analytical capabilities, and strong cross-functional communication and collaboration skills.
Preferred:
Cloud Security: Experience securing applications deployed in multi-cloud environments (e.g., AWS, GCP, Azure).
Regulatory Familiarity: Knowledge of educational and data privacy frameworks, including FERPA, COPPA, GDPR, and SOC 2 standards.
Certifications: Professional security certifications such as CASE, GWAPT, GWEB, or Certified Ethical Hacker (CEH) are a plus.
RESIDENCY REQUIREMENT
Finalsite offers 100% fully remote employment opportunities, however, these opportunities are limited to permanent residents of India. Current residency, as well as continued residency, within India is required to obtain (and retain) employment with Finalsite.
DISCLOSURES
Finalsite is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to equal employment opportunities regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. EEO is the Law. If you have a disability or special need that requires accommodation, please contact Finalsite's People Operations Team. Finalsite is committed to the full inclusion of all qualified individuals. As part of this commitment, Finalsite will ensure that persons with disabilities or special needs are provided a reasonable accommodation. Ensure your Finalsite job offer is legitimate and don't fall victim to fraud. Ask your recruiter for a phone call or other type of verbal communication and ensure all email correspondence is from a https://jobeax.com/link/aU5G6a6AewBeZU4O email address. For added security, where possible, apply through our company website at https://jobeax.com/link/ULwVF6B9iumoc19g