Lead Application Security Engineer
InvestCloud, Inc. · Bengaluru
- Experience7–8 yrs
- SalaryNot disclosed
- Work modeonsite
- Posted3 Oct 2026
About InvestCloud, Inc.
InvestCloud, Inc. is hiring in Bengaluru in financial services. This role looks for around 7+ years of experience.
Skills
- Python
- SQL
- pytest
- Snyk
- Semgrep
- SonarQube
- Burp Suite
- OWASP ZAP
- Wiz
- Rapid7
- Tenable
- SARIF
- SBOM
- VEX
- CVSS
- EPSS
- CISA KEV
- SSVC
- Jira Assets
- GitLab CI
- REST
- GraphQL
- Datadog
- application security
- vulnerability management
- threat exposure management
- security engineering
- policy-as-code
- attack path analysis
The role
An application security engineer at a financial services product company. Builds deterministic exposure prioritization using Python and policy-as-code, correlating application security evidence with threat intelligence and attack paths to rank remediation actions. Also applies CVSS and EPSS to explain risk and guide remediation.
Full job description
SECURITY ENGINEERING AT INVESTCLOUD
At InvestCloud, we are building an intelligent security response capability that determines what to fix first based on the actual risk to our clients and business, not a scanner's native severity.
Traditional vulnerability management produces disconnected findings and long backlogs. It often misses whether vulnerable code is deployed, reachable by an attacker, connected to a critical service, capable of lateral movement, or already being exploited. We are solving that problem by combining threat intelligence, runtime and deployment evidence, configuration management data, attack path analysis, business criticality, and validation results.
The platform will ingest findings from infrastructure, cloud, application, software supply chain, secrets, containers, infrastructure as code, and adversarial testing. It will reconcile them to a canonical asset and service model, deduplicate them into unique exposures, and rank the remediation actions that remove the most risk.
The product is being built in Python on AWS with source-controlled connectors, deterministic policy code, an AI reasoning layer, human approval gates, complete audit evidence, and closed-loop validation. Large language models (LLMs) can correlate evidence, recommend remediation, and explain decisions. They do not calculate the authoritative priority score.
This is not another scanner or dashboard. It is a security decision and remediation platform that must answer one question reliably: what is the single next action that will remove the most material risk, why is it first, who owns it, and how will we verify the risk is gone? Every engineer on this team will build production software, operate what they build, and own the product after the initial consultant implementation.
THE ROLE
As our Application Security & Triage Engineer, you will own the deterministic risk intelligence layer that decides what InvestCloud fixes first. You will convert observations from infrastructure and code scanners into unique exposures, enrich them with threat, deployment, reachability, attack path, client, and business context, then map them to the remediation actions that remove the most risk.
Your output is not a bucket of critical, high, and medium findings. It is one explainable action queue that identifies the single next action, the risk it removes, the affected services and clients, the accountable owner, and the evidence required for closure. The authoritative ranking must be versioned policy code, not an LLM opinion.
What You Will Own
Exposure Correlation & Deduplication: Correlate Wiz, Rapid7 or Tenable, Snyk, SAST, SCA, DAST, secrets, container, infrastructure as code, and adversarial testing observations into unique exposures. Treat corroborating tools as evidence, not separate risk.Deterministic Prioritization Engine: Implement and maintain the policy-as-code scoring model, tier triggers, normalized inputs, reason codes, missing data handling, and version history. Make every score reproducible, testable, explainable, and traceable to source evidence.Reachability, Attack Path & Blast Radius: Evaluate production presence, network and application reachability, authentication requirements, source-to-sink paths, privileges, lateral movement, service dependencies, adjacent systems, client impact, and compensating controls.Code & Software Supply Chain Risk: Assess code findings by demonstrated outcome, including remote code execution, authentication bypass, privilege escalation, injection, server-side request forgery, arbitrary write, sensitive read, and valid secrets. Use repository, commit, pipeline, SBOM, VEX, artifact, deployment, and runtime evidence rather than scanner severity alone.Remediation Action Prioritization: Group the exposures resolved by each action, estimate fix coverage and confidence, calculate the total risk removed, and rank actions by tier, risk reduction, highest exposure, deadline, and verification confidence. Effort is only a final tie-breaker.Calibration & Developer Guidance: Backtest rankings against real findings and expert judgment, monitor false positives and drift, refine policy safely, and translate results into concise remediation guidance that product and platform teams can act on without a security translator.
What We Are Looking For
7+ years in application security, vulnerability management, threat exposure management, or security engineering, with evidence that you have owned risk-based prioritization at enterprise scale.Production Python and strong data reasoning. You can implement scoring mathematics, policy logic, unit and regression tests, data analysis, APIs, and SQL-based relationship queries yourself.Deep application security across SAST, SCA, DAST, API testing, secrets, containers, infrastructure as code, and software supply chain risk. You can distinguish a theoretical finding from a reachable and exploitable path.Threat and vulnerability intelligence depth, including CVSS, EPSS, CISA KEV, SSVC, VEX, exploit evidence, vendor advisories, fixed versions, malicious packages, source provenance, and freshness.Practical attack path analysis across network, identity, cloud, application, and software dependencies. You understand how an initial foothold can reach control planes, critical services, sensitive data, clients, and adjacent assets.Experience designing or calibrating deterministic risk models, correlation rules, confidence measures, and explainability. You preserve unknown data rather than silently treating it as zero.A subject matter expert who can go deep, explain the result concisely to nonexperts, show self-directed technical work, use AI responsibly to improve output, and win the cooperation of developers and service owners.
CORE TOOLING & TECHNOLOGIES
Python
SQL pytest Snyk Semgrep / SonarQube Burp Suite OWASP ZAP Wiz Rapid7 / Tenable SARIF SBOM / VEX CVSS / EPSS / KEV / SSVC Jira Assets GitLab CI REST / GraphQL Datadog
WHY JOIN THIS TEAM
You will own the logic that differentiates this platform from a scanner. Without precise correlation and contextual ranking, the organization still has a larger backlog, not a better decision.
With this layer working, InvestCloud can state exactly which action should happen next and show the evidence behind it. Your judgment, code, and calibration will determine whether the team consistently removes the most material risk first.