Application Security Engineer II - IN ( Night Shift)
India - Remote••December 3, 2025
Position Overview:In this role, you will support Rackspace's application security program by implementing and maintaining security testing capabilities, including static and dynamic application security testing, assisting with application penetration testing, and supporting our bug bounty program. You will work closely with development teams to identify, report, and help remediate security vulnerabilities across our application portfolio. Work Location: 100% remote from within IndiaShift: India Night Shift
Required Experience, Knowledge, Skills, and Abilities:
- 2-4 years in the information security field
- Experience working with application security, security testing, or DevSecOps practices
- Working knowledge of the SDLC, security concepts, and vulnerability assessment methodologies
- Hands-on experience with or understanding of programming and scripting languagesincluding one or more of the following: Python, Java, Node.js, Go, Ruby, PHP; databases such as SQL; and related tools such as Github, Gitlab, Jenkins, and CircleCI
- Understanding of common vulnerabilities, remediation approaches, and industry-standard classification schemes (CVE, CWE, CVSS, OWASP Top 10)
- Familiarity with relevant compliance regulations, such as PCI-DSS, ISO 27001, SOC 2, or HIPAA
- Passion for security and eagerness to learn about new technologies and emerging security vulnerabilities
- Strong communication skills with the ability to work collaboratively across teams
Key Duties and Responsibilities:
- Execute application security testing using both automated tools and manual testing techniques on web applications, APIs, containers, and other software components
- Configure, maintain, and operate SAST, DAST, and other application security testing tools
- Analyze and triage security findings, documenting clear remediation guidance for development teams
- Support the vulnerability reporting process and track findings through to resolution
- Assist with triage and validation of external vulnerability disclosures and bug bounty reports
- Contribute to the development and documentation of application security processes and standards
- Participate in security code reviews and threat modeling exercises
- Help track and report metrics for application security program health
- Collaborate with development and DevOps teams to integrate security into CI/CD pipelines
- Stay current with application security trends, tools, and best practices
- Support time-sensitive security events as needed under guidance of senior team members
Education/Certifications:
- Bachelor's degree (B.Tech/BE/B.Sc) in Computer Science, Information Technology, Cybersecurity, or related technical field
- At least one security certification such as:
- CEH (Certified Ethical Hacker)
- CompTIA Security+
- eWPT (eLearnSecurity Web Application Penetration Tester)
- GIAC certifications (GWAPT, GSEC)
- Offensive Security certifications (OSCP, OSWE)
- (ISC)² certifications (SSCP, CC)
- EC-Council certifications (CEH, ECSA)
