
10,000+ employees
Founded 1860
đź Consulting
đŚ Logistics
đŁ Marketing
Consulting ⢠Logistics ⢠Marketing
S&P Global is a leading provider of market intelligence, ratings, analytics, and benchmark indices. The company offers comprehensive insights across various domains including finance, commodities, mobility, and sustainability. Renowned for its data-driven solutions, S&P Global assists organizations in navigating complex market trends, evaluating credit risk, and understanding the implications of artificial intelligence and energy transitions. Its diverse offerings, such as S&P Global Market Intelligence, S&P Global Ratings, and S&P Dow Jones Indices, provide critical data and analytics to businesses, government entities, and investors worldwide.
đĽ 18 hours ago
đŽđł India â Remote
â° Full Time
đĄ Mid-level
đ Senior
đť Application Engineer
đť Ghost score 10%
Improve your chances of getting an interview by checking your resume score before you apply.

10,000+ employees
Founded 1860
đź Consulting
đŚ Logistics
đŁ Marketing
Consulting ⢠Logistics ⢠Marketing
S&P Global is a leading provider of market intelligence, ratings, analytics, and benchmark indices. The company offers comprehensive insights across various domains including finance, commodities, mobility, and sustainability. Renowned for its data-driven solutions, S&P Global assists organizations in navigating complex market trends, evaluating credit risk, and understanding the implications of artificial intelligence and energy transitions. Its diverse offerings, such as S&P Global Market Intelligence, S&P Global Ratings, and S&P Dow Jones Indices, provide critical data and analytics to businesses, government entities, and investors worldwide.
⢠Implement, configure, administer and optimise enterprise SAST capabilities ⢠Onboard applications and repositories using repeatable, documented patterns ⢠Configure scanning profiles, policies, presets, exclusions and application-specific settings ⢠Analyse findings across multiple languages and frameworks; validate false positives, duplicates and vulnerability classifications ⢠Provide remediation guidance and secure coding examples ⢠Investigate failed or incomplete scans, performance issues and integration problems ⢠Design and implement application security controls within CI/CD pipelines ⢠Integrate SAST with repositories, pull requests, build pipelines and developer workflows ⢠Define risk-based security gates for builds, releases and production deployments ⢠Create reusable pipeline templates and security components ⢠Develop AppSec automation using Python, PowerShell, Bash or other suitable languages ⢠Build REST API, webhook, CLI and SDK integrations ⢠Automate onboarding, scanning, result retrieval, triage, reporting and workflow updates ⢠Automate finding normalisation, deduplication, enrichment, prioritisation and assignment ⢠Integrate AppSec platforms with ticketing, reporting, source-control and collaboration systems ⢠Prioritise, validate, track and remediate vulnerabilities through closure or risk acceptance ⢠Apply cloud security governance principles to application workloads, services and delivery pipelines ⢠Support cloud control assessments, evidence collection, exception management, remediation tracking and audit readiness ⢠Map AppSec and CI/CD controls to enterprise policies, regulatory obligations and recognised security frameworks ⢠Embed security requirements across design, development, testing and release processes ⢠Support threat modelling and security reviews for high-risk applications ⢠Create standards, checklists, onboarding guides, runbooks and technical documentation ⢠Deliver technical enablement for developers, DevOps engineers and security champions ⢠Maintain programme records, coverage metrics, remediation data and audit evidence ⢠Collaborate with application development, DevOps, platform engineering, security architecture, risk, cloud and compliance teams
⢠Bachelor's or Master's degree in Computer Science, Information Security, Engineering or a related discipline, or equivalent practical experience ⢠Five or more years of relevant experience in Application Security, Product Security, DevSecOps or software security engineering ⢠Hands-on experience with enterprise SAST platforms, secure code analysis and vulnerability validation ⢠Experience integrating security scanning into CI/CD pipelines and source-control workflows ⢠Experience with GitHub, GitHub Actions, Azure DevOps, Jenkins, GitLab CI or equivalent technologies ⢠Strong scripting or development skills using Python, PowerShell, Bash, Java, C#, JavaScript or similar languages ⢠Experience building integrations with REST APIs, webhooks, service accounts and modern authentication mechanisms ⢠Strong understanding of OWASP Top 10, CWE classifications, secure coding and vulnerability remediation ⢠Ability to review source code and validate findings in at least one major programming language ⢠Understanding of web applications, APIs, microservices, containers and cloud-native architectures ⢠Working knowledge of cloud security governance, security control implementation, compliance evidence and exception management ⢠Understanding of cloud IAM, encryption, secrets management, logging, monitoring and secure configuration principles ⢠Strong analytical, troubleshooting, documentation and stakeholder communication skills ⢠Preferred/current vendor certifications, OSCP, CSSLP, CASE, GWAPT, OSWE, eWPTX or relevant cloud security certifications are advantageous ⢠Knowledge of NIST CSF, NIST SP 800-53, ISO/IEC 27001, SOC 2 or PCI DSS is beneficial ⢠Experience with SCA, secrets scanning, API security, Infrastructure as Code scanning or container security is beneficial ⢠Experience developing reusable CI/CD components and producing AppSec dashboards and metrics is beneficial
⢠Health care coverage designed for the mind and body ⢠Generous time off ⢠Continuous learning resources and career development opportunities ⢠Competitive pay ⢠Retirement planning ⢠Continuing education program ⢠Company-matched student loan contribution ⢠Financial wellness programs ⢠Family benefits and perks ⢠Retail discounts ⢠Referral incentive awards
Apply Nowđ September 8
Application Security Engineer securing Sun Kingâs mobile, API, cloud, and AI product platform. Driving threat modeling, testing, vulnerability management, and secure engineering practices.
Android
AWS
Cloud
Cyber Security
Firebase
Google Cloud Platform
Kubernetes
Python
đ August 25
Senior Security Engineer researching DevSecOps, AI, and cloud-native security technologies at Practical DevSecOps. Creating hands-on training content, lab infrastructure, and learner support for security professionals.
Cloud
Python
SDLC
Go
đ August 13
Application Engineer integrating enterprise IT systems and automating identity, access, and provisioning workflows. Supporting HighLevelâs AI-powered business operating system through secure APIs and SaaS integrations.
đŽđł India â Remote
đ° Series A on 2021-11
â° Full Time
đĄ Mid-level
đ Senior
đť Application Engineer
ITSM
Java
Python
ServiceNow
đ July 17
Senior Application Engineer responsible for designing and managing Zuora Billing solutions at Twilio. Collaborating with cross-functional teams in a fully remote role based in India.
ERP
Oracle
Oracle ERP
đ July 2
Lead Teamcenter Application Engineer overseeing PLM support and development for Convatec's medical products. Managing Teamcenter solutions and compliance in a regulated environment.
AWS
Azure
Java
SDLC