Associate, Application Development Security Engineer
Job Summary
ABOUT REVANTAGE
Revantage a Blackstone Real Estate portfolio company is a global provider of corporate services.
With a corporate purpose of In Pursuit of Better Revantage delivers value-added services and world-class talent for Blackstone Real Estate portfolio companies spanning diverse asset classes including residential logistics office hospitality and retail sectors. The companys footprint extends across North America Europe and Asia Pacific.
Creating a culture that inspires impact and momentum requires the right team. We know what it takes to lead an industry and are looking for leaders who seek constant growth want to excel and continuously improve upon themselves and the industry.
In addition to supporting Revantage we also recruit for Blackstone Real Estate portfolio companies giving you the unique opportunity to work within a network of best-in-classprofessionals across a broad real estate platform.
India
With offices in Bengaluru and Gurugram our teams in India deliver expertise innovation and operational excellence that support thousands of assets across logistics data centers residential commercial and hospitality.
Whether youre building new capabilities driving critical initiatives or strengthening partnerships youll have the opportunity to trulyBuild What Matters.
ROLE SUMMARY
We are seeking a mid-level Application Development Security Engineer for a Blackstone Real Estate portfolio company and the largest owner manager and developer of high-quality student housing communities in the United States. This role is based in Bengaluru India hired through Revantage India and reports to Chief Information Security Officer (CISO).
The Application Development Security Engineer partners with software engineering DevOps cloud engineering and product teams to integrate security throughout the Software Development Lifecycle (SDLC). The role champions secure-by-design principles through automated security testing secure coding practices CI/CD security controls cloud-native application security and developer enablement helping ensure applications remain resilient against modern threats while enabling rapid and secure software delivery.
Working hours will provide meaningful daily overlap with US Central Time. The role also participates in rotating on-call coverage for US nights and weekends and provides coverage on US and India holidays to support uninterrupted operations.
PRIMARY ROLE
- Coordinate with the broader Information Security team and perform duties that support its primary mission and priorities.
- Integrate security throughout the Software Development Lifecycle using DevSecOps and secure-by-design practices.
- Implement and maintain automated security testing and security controls within CI/CD pipelines.
- Perform static application security testing (SAST) dynamic application security testing (DAST) software composition analysis (SCA) Infrastructure as Code (IaC) API container and secrets-security assessments.
- Conduct application threat modeling secure-design reviews and application-security architecture reviews for new applications and cloud services.
- Identify prioritize and coordinate remediation of application and software-supply-chain vulnerabilities.
- Partner closely with software developers to strengthen secure-coding practices and resolve security findings without unnecessarily slowing delivery.
- Develop and maintain security guardrails for Azure DevOps GitHub GitLab Jenkins and other CI/CD platforms.
- Secure Infrastructure as Code deployments using Terraform ARM/Bicep CloudFormation and similar technologies.
- Assess and secure Kubernetes Docker serverless APIs and other cloud-native workloads.
- Evaluate open-source dependencies and third-party software for supply-chain risk.
- Develop and maintain security standards reusable templates developer guidance and enablement materials.
- Research emerging application-security threats assess their relevance to ACC and recommend practical improvements.
- Participate in incident response with emphasis on application-layer vulnerabilities and coordinate remediation with engineering and operations teams.
- Support a 24x7 operational environment through scheduled rotation and on-call coverage for US nights and weekends US and India holidays incidents critical production events and business-continuity needs.
- Perform other projects and responsibilities as assigned.
QUALIFICATIONS & SKILLS
- Strong understanding of secure software-development principles and common threat frameworks including the OWASP Top 10 CWE and MITRE ATT&CK.
- Experience designing and implementing secure CI/CD pipelines and controls.
- Working knowledge of Azure DevOps GitHub Actions GitLab CI Jenkins and similar platforms.
- Hands-on experience with SAST DAST SCA IaC container API and secrets-scanning tools including Burp Suite SonarQube GitHub CodeQL Snyk Veracode and ShiftLeft.
- Familiarity with Docker Kubernetes Azure Kubernetes Service (AKS) and similar container platforms.
- Experience with scripting and automation using Python PowerShell Bash or JavaScript.
- Working knowledge of cloud platforms including Microsoft Azure Amazon Web Services (AWS) and Google Cloud.
- Strong understanding of OAuth OpenID Connect authentication authorization and secure API development.
- Excellent collaboration and communication skills particularly when working with software-engineering DevOps cloud and product teams.
- Proficiency in the secure and responsible use of generative AI tools such as ChatGPT Claude Microsoft Copilot and Google Gemini.
- Experience integrating AI security into the Secure Software Development Lifecycle including identifying and mitigating risks involving AI models APIs prompt injection data exposure insecure model interactions and third-party AI services.
- Must hold or be capable of passing within one year of the hire date Exam AI-901: Microsoft Azure AI Fundamentals.
- Administrator-level experience with enterprise security tools including Microsoft Defender; CrowdStrike Falcon Complete/MDR Identity Threat Protection Shield Recon Cloud Security and Next-Gen SIEM; Wiz; Zscaler ZIA ZPA ZDX and ZTA; and Proofpoint TAP and DLP.
- Demonstrated ability to extract validate and communicate operational reports and security metrics from these platforms.
EDUCATION & EXPERIENCE
- Bachelors degree in computer science software engineering cybersecurity or a related field or equivalent professional experience.
- Four to six years of application security DevSecOps software-engineering or cloud-security experience.
- Experience integrating security into CI/CD pipelines and applying secure software-development methodologies.
- Experience performing application-security assessments and secure code reviews.
CERTIFICATIONS
- ISC2 Certified Secure Software Lifecycle Professional (CSSLP).
- GIAC Web Application Penetration Tester (GWAPT).
- GIAC Certified Web Application Defender (GWEB).
- Microsoft Certified: Azure Security Engineer Associate.
- Certified Kubernetes Security Specialist (CKS).
- Microsoft Certified: DevOps Engineer Expert.
EEO Statement
The Company is an equal opportunity accordance with applicable law we prohibit discrimination against any applicant employee or other covered person based on any legally recognized basis including but not limited to: veteran status uniformed servicemember status race color caste immigration status religion religious creed (including religious dress and grooming practices) sex gender gender expression gender identity marital status sexual orientation pregnancy (including childbirth lactation or related medical conditions) age national origin or ancestry citizenship physical or mental disability genetic information (including testing and characteristics) protected leave status domestic violence victim status or any other consideration protected by federal state or local law. We are committed to providing reasonable accommodations if you need an accommodation to complete the application process please email
Required Experience:
IC