Application Security Engineer

Security and Compliance Pune, MH

Job Summary

Join us in building a secure platform supporting Avalara’s expanding business. In this role you will have the opportunity to engage with the best and brightest engineers and architects as they build our future application and service capabilities, while ensuring our current generation solutions continue to deliver the trust and reliability our customers expect. If you want to make a big difference in a fast-moving environment without endless meetings, if you want to set your direction instead of having it set for you, if you want to have all of the benefits of startup and an established company, we want to talk to you.

Our ideal application security engineer has experience working on a variety of platforms and technologies and is passionate about identifying and managing risks. Security can be complex, so you will be responsible to make it simple, but make its impact significant in our engineering organizations. You will provide guidance, training, and support. You will be able to talk tech and business. You will work hard to find the right solution, not the first solution. You thrive on challenge and you are not afraid to dig in, all while having fun and not getting too serious.

Job Duties

  • Set strategic direction for application security within Avalara, including processes, tools, metrics, and reporting
  • Perform code and design reviews of internal and customer-facing software products and solutions
  • Provide training, education, awareness, and communication to development and engineering groups
  • Develop and implement manual and automated security tests
  • Design, develop, and implement software development policies, standards, procedures, and technical controls
  • Participate in penetration testing activities, managing relationships with third party assessors 
  • Participate in incident handling and response
  • Participate in M&A due diligence and integration processes


  • 5+ years’ experience performing manual code review and analysis
  • 5+ years’ experience with application security tools such as HP Fortify, Checkmarx CxSAST, or BlackDuck OSS
  • Deep technical knowledge and experience identifying, triaging, and remediating application vulnerabilities including the OWASP Top 10
  • Experience working with a variety of development tools, languages, and environments, including .NET, Java, PHP, Node.js, Ember, SQL Server, and Amazon Web Services
  • Experience working in a multi-tenant SaaS environment, service-oriented architecture and web service security
  • Experience with agile software development processes and methodologies
  • Working knowledge of source code repositories including Git
  • Experience developing and securing applications in AWS
  • Preferred Qualification
  • Bachelor’s Degree in Computer Science, Engineering, or related field
  • Experience working with web vulnerability scanners such as Acunetix WVS or NTO Spider
  • Security certifications including CISSP, CSSLP, and GIAC GWAPT
  • Knowledge of regulatory and compliance standards including PCI, SSAE18 SOC 1/2, SOX, and GDPR
  • Hands on experience in a continuous integration/continuous deployment environment

The perks of working at Avalara go beyond amazing physical spaces and a Tiki Bar. We’re committed to continued progress in diversity and inclusion. As an employee at Avalara, you’ll have the opportunity to join resource groups focused on diversity of thought, engage with your local or global community about topics that matter to you and the organization and receive continued education around inclusion and development. As Avalara grows, so do the voices within it. It’s time to hear your voice.