Enter a job title or keyword

Application Security Specialist

Ramboll


Job Location:

Chennai - India

Monthly Salary: Not provided by the employer
Posted: 23 September 2026 (3 hours ago)
Application Deadline: 21 December 2026
Vacancies: 1 Vacancy

Job Summary

Application Security Specialist India

Are you motivated by turning complex security and compliance risks into clear decisionready insights Do you want to work at the intersection of information security data compliance and governance in a global organisation Are you looking to make a tangible impact on how a leading consultancy manages cyber and datarelated risks

If this sounds like you or youre curious to learn more then this role could be the perfect opportunity. Join our Information Security and Data Compliance department

Your new role

The Application Security Specialist operates at the intersection of Information Security and Assurance (ISA) and DevSecOps ensuring that application security is embedded measurable and compliant across Rambolls global digital landscape and application development.

This role focuses on integrating security into engineering workflows while aligning with enterprise security frameworks such as ISO 12207 /ISO/IEC 27001 / CIS 18 and industry best practices like OWASP.

The Application Security specialist is responsible for identifying analyzing and mitigating security vulnerabilities in applications throughout the software development lifecycle (SDLC). This role works closely with development DevOps and security teams to ensure secure coding practices and compliance with organizational and industry standards. You will work closely with RAMTECH data compliance regulatory and business teams.

Your key responsibilities will be:

Alignment & Assurance

Translate security policies into actionable technical controls for development teams
Ensure alignment with:
    ISO/IEC 27001
    CIS Critical Security Controls
    OWASP Top 10
Support internal/external audits by providing application security evidence andmetrics
Contribute to risk registers control effectiveness reviews and exception handling

DevSecOps Enablement

Embed application security controls into CI/CD pipelines across business units
Drive adoption of security-by-design and shift-left security practices
Integrate and manage tools for:
         oSAST DAST SCA Secrets Scanning
Partner with DevOps teams to standardize secure pipelines globally
Confidential.

Application Risk Management

Perform risk-based vulnerability assessments and prioritize remediation
Align risk ratings aligned with Cyber and Information security risk methodology
Track remediation SLAs and report on risk posture to CISO office.
Conduct threat modeling for critical applications and digital solutions

Security Testing & Validation

Oversee and/or perform:
     o Secure code reviews
     o Penetration testing (manual & automated)
Validate vulnerability fixes and ensure closure meets compliance requirements
Establish baseline security requirements for all applications

Developer Security Advisory

Act as a security champion enabler across distributed engineering teams
Provide secure coding guidance and conduct targeted training sessions
Develop reusable secure design patterns and reference architectures.

Metrics Reporting & Continuous Improvement

Define and track KPIs such as:
      o Vulnerability density
      o Mean Time to Remediate (MTTR)
      o % of applications onboarded to DevSecOps pipelines
Build dashboards for leadership visibility and regulatory reporting
Drive continuous improvement initiatives across global teams


Qualifications :

Required Skills & Qualifications
Technical Skills
Strong understanding of:
              o Web technologies (HTTP REST APIs microservices)
              o Authentication and authorization mechanisms (OAuth JWT SSO)
Knowledge of common vulnerabilities (e.g. SQL Injection XSS CSRF)
Experience with security tools such as:
              o SAST: Checkmarx Fortify
              o DAST: Burp Suite Acunetix
              o SCA: Snyk Black Duck
Familiarity with programming languages (Java Python )

Security Knowledge

Hands-on experience with OWASP Top 10 risks
Understanding of threat modeling methodologies
Experience in bridging policy-to-technical implementation gaps
Knowledge of cloud security (AWS Azure GCP) is a plus

About you

5 years in Application Security Cyber Security or Software Development
Experience working in Agile/DevOps environments
Prior experience in secure coding or vulnerability management preferred
Certifications (Preferred)
        Certified Secure Software Lifecycle Professional (CSSLP)
        Offensive Security Certified Professional (OSCP)
        Certified Information Systems Security Professional (CISSP)
        GIAC Web Application Penetration Tester (GWAPT)

Nice to Have

Experience with bug bounty programs
Knowledge of container security (Docker Kubernetes)
Experience with Infrastructure as Code (IaC) security tools


Additional Information :

What we can offer you
Flexible work environment with the possibility of working from home.
Commitment to your professional and personal development.
Leaders guided by Rambolls Leadership Principles.
A culture that welcomes you as the unique person you are.
The longterm thinking of a foundationowned company.

Ready to join us
Please submit your application and CV online. We invite diversity in all its forms and encourage applicants from all groups to apply.


Remote Work :

No


Employment Type :

Full-time


About Company

Company Logo

Ramboll is a global architecture, engineering and consultancy company founded in Denmark in 1945. Our 18,000+ experts create sustainable solutions across Buildings, Transport, Energy, Environment & Health, Water, Management Consulting and Architecture & Landscape. Across the world ... View more

View Profile View Profile