Ramboll · Posted 16 days ago

Application Security Specialist

Chennai

The posting

key requirement, as the employer wrote it

Application Security Specialist India Are you motivated by turning complex security and compliance risks into clear, decision‑ready insights?

Do you want to work at the intersection of information security, data compliance and governance in a global organisation?

Are you looking to make a tangible impact on how a leading consultancy manages cyber and data‑related risks?

If this sounds like you, or you’re curious to learn more, then this role could be the perfect opportunity.

Join our Information Security and Data Compliance department Your new role The Application Security Specialist operates at the intersection of Information Security and Assurance (ISA) and DevSecOps, ensuring that application security is embedded, measurable, and compliant across Ramboll’s global digital landscape and application development.

This role focuses on integrating security into engineering workflows while aligning with enterprise security frameworks such as ISO 12207 /ISO/IEC 27001 / CIS 18 and industry best practices like OWASP.

The Application Security specialist is responsible for identifying, analyzing, and mitigating security vulnerabilities in applications throughout the software development lifecycle (SDLC).

This role works closely with development, DevOps, and security teams to ensure secure coding practices and compliance with organizational and industry standards.

You will work closely with RAMTECH, data compliance, regulatory and business teams.

Your key responsibilities will be: Alignment & Assurance •Translate security policies into actionable technical controls for development teams •Ensure alignment with: ISO/IEC 27001 CIS Critical Security Controls OWASP Top 10 •Support internal/external audits by providing application security evidence andmetrics •Contribute to risk registers, control effectiveness reviews, and exception handling DevSecOps Enablement •Embed application security controls into CI/CD pipelines across business units •Drive adoption of security-by-design and shift-left security practices •Integrate and manage tools for: oSAST, DAST, SCA, Secrets Scanning •Partner with DevOps teams to standardize secure pipelines globally Confidential.

Application Risk Management • Perform risk-based vulnerability assessments and prioritize remediation • Align risk ratings aligned with Cyber and Information security risk methodology • Track remediation SLAs and report on risk posture to CISO office.

•Conduct threat modeling for critical applications and digital solutions Security Testing & Validation • Oversee and/or perform: o Secure code reviews o Penetration testing (manual & automated) • Validate vulnerability fixes and ensure closure meets compliance requirements • Establish baseline security requirements for all applications Developer Security Advisory • Act as a security champion enabler across distributed engineering teams • Provide secure coding guidance and conduct targeted training sessions • Develop reusable secure design patterns and reference architectures.

Metrics, Reporting & Continuous Improvement • Define and track KPIs such as: o Vulnerability density o Mean Time to Remediate (MTTR) o % of applications onboarded to DevSecOps pipelines • Build dashboards for leadership visibility and regulatory reporting • Drive continuous improvement initiatives across global teams

Required Skills & Qualifications Technical Skills • Strong understanding of: o Web technologies (HTTP, REST APIs, microservices) o Authentication and authorization mechanisms (OAuth, JWT, SSO) • Knowledge of common vulnerabilities (e.g., SQL Injection, XSS, CSRF) • Experience with security tools such as: o SAST: Checkmarx, Fortify o DAST: Burp Suite, Acunetix o SCA: Snyk, Black Duck • Familiarity with programming languages (Java, Python, JavaScript, .NET) Security Knowledge • Hands-on experience with OWASP Top 10 risks • Understanding of threat modeling methodologies • Experience in bridging policy-to-technical implementation gaps • Knowledge of cloud security (AWS, Azure, GCP) is a plus About you • 5+ years in Application Security, Cyber Security, or Software Development • Experience working in Agile/DevOps environments • Prior experience in secure coding or vulnerability management preferred • Certifications (Preferred) • Certified Secure Software Lifecycle Professional (CSSLP) • Offensive Security Certified Professional (OSCP) • Certified Information Systems Security Professional (CISSP) • GIAC Web Application Penetration Tester (GWAPT) Nice to Have • Experience with bug bounty programs • Knowledge of container security (Docker, Kubernetes) • Experience with Infrastructure as Code (IaC) security tools

Ramboll

Open roles in India
102
Hiring in
Mumbai, Chennai, Noida, Madhapur, Gurugram, Bengaluru
Applications through
SmartRecruiters

Counted from the roles we read off Ramboll's own hiring page today.

Ramboll

Danish consulting engineering group

Founded
1945
Industry
engineering
Company website

Facts from Wikidata, the open, community-edited database behind Wikipedia — check the link if something looks out of date. Funding rounds, investors and employee ratings are not shown: no free source carries them reliably.

My match scoreApply