Application Security Engineer

Mercedes Benz Leasing Deutschland — Germany · Posted ~2 weeks ago

Mid Full-time Hybrid Visa History ✓

Skills

application security DevSecOps Azure security SAST DAST SCA IaC scanning CI/CD OWASP Top 10 Python Azure Coverity JFrog Xray BlackDuck Polaris Wiz PowerShell Bash Docker Kubernetes

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary

Join a global R&D security team to embed security throughout the software development lifecycle. You will integrate security tools into CI/CD pipelines, perform threat modeling and risk assessments, secure Azure cloud environments and AI/ML systems, and collaborate closely with development and operations teams to drive DevSecOps best practices.

Highlights

Security engineering role focused on DevSecOps, Azure cloud security, AI/ML security practices, modern security tooling, hybrid work, and continuous learning in a global R&D environment.

Description

Application Security Engineer | Mercedes-Benz > Karriere > Jobsuche > Stellenausschreibungen DE EN HU Anbieter/DatenschutzUnternehmenTechnologieNachhaltigkeitKarriereInvestorenPresse ProdukteKarriereJobsucheApplication Security EngineerTätigkeitsbereich:IT/TelekommunikationFachabteilung:Security Architecture & GRCGesellschaft:Mercedes-Benz Research and Development India Private LimitedStandort:Mercedes-Benz Research and Development India Private Limited, BangaloreStartdatum:sofortVeröffentlichungsdatum:20.05.2026Stellennummer:MER00040M4Arbeitszeit:Vollzeit BewerbenAufgabenAbout MBRDIMercedes-Benz Research and Development India (MBRDI), headquartered in Bengaluru with a satellite office in Pune, is the largest R&D center for Mercedes-Benz Group AG outside of Germany. Our mission is to drive innovation and excellence in automotive engineering, digitalization, and sustainable mobility solutions, shaping the future of mobility.Job Title: Application Security Engineer Job Overview We are seeking a highly motivated and experienced Application Security Engineer with 4+ years of hands-on technical experience to join our team and drive DevSecOps initiatives. In this role, you will be instrumental in embedding security throughout the software development lifecycle, from design to deployment and operations. You will leverage your expertise in application security, Azure cloud security, and DevSecOps practices to protect our applications and infrastructure. A strong understanding of cloud-native security principles, particularly within the Azure ecosystem, and experience with security tools like Coverity, Jfrog (Xray), BlackDuck, Polaris, and Wiz is essential. Familiarity with the security implications and best practices for Artificial Intelligence (AI) and Machine Learning (ML) systems is also highly valued. Key Responsibilities: Integrate security tools and processes into the CI/CD pipeline to automate security checks (SAST, DAST, SCA, IaC scanning) using tools like Coverity, Jfrog Xray, BlackDuck, and Polaris.Conduct security reviews, threat modeling, and risk assessments for new and existing applications and services, with a focus on Azure-based deployments and AI/ML components.Collaborate with development and operations teams to implement security best practices and remediate identified vulnerabilities.Utilize Wiz to monitor and improve the security posture of our Azure cloud environments and cloud-native applications.Develop and maintain secure coding guidelines, security standards, and DevSecOps best practices, including those specific to AI/ML systems.Provide security expertise and guidance to development teams throughout the software development lifecycle.Participate in security architecture reviews to ensure security by design for new systems and features, particularly those deployed in Azure and involving AI/ML technologies.Support vulnerability management efforts, including scanning, analysis, prioritization, and tracking of remediation activities.Assist in the evaluation and selection of new security technologies and tools to enhance our DevSecOps capabilities.Stay up-to-date with the latest security threats, vulnerabilities, and industry trends, including advancements in AI/ML security. QualifikationenQualifications: 4+ years of experience in application security, DevSecOps, or a related field.Strong understanding of secure software development lifecycle (SSDLC) and integrating security into CI/CD pipelines.Proven experience with Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), and Infrastructure as Code (IaC) security.Hands-on experience with security tools such as Coverity (SAST), Jfrog (specifically Xray for SCA and artifact security), BlackDuck (SCA), Polaris (for security orchestration/scanning), and Wiz (for cloud-native security and posture management).Solid understanding of cloud security principles and best practices, with significant experience in Azure.Familiarity with common application security vulnerabilities (e.g., OWASP Top 10) and mitigation strategies.Understanding of security challenges and best practices related to AI/ML models, data, and pipelines (e.g., adversarial attacks, data poisoning, model theft, privacy).Experience with scripting languages (e.g., Python, PowerShell, Bash) for automation of security tasks.Excellent problem-solving skills and meticulous attention to detail.Ability to work independently and collaboratively within a dynamic team environment.Must possess strong interpersonal skills, including effective communication, constructive feedback, decision-making, and a high sense of responsibility. Preferred Qualifications:Relevant security certifications such as CSSLP, Azure Security Engineer Associate, AWS Certified Security - Specialty, or equivalent DevSecOps certifications.Experience with threat modeling methodologies and tools.Knowledge of security frameworks and compliance standards (e.g., ISO 27001, NIST, SOC 2, GDPR) as they apply to application and Azure cloud security.Familiarity with container security (e.g., Docker, Kubernetes) and serverless security within Azure (e.g., Azure Kubernetes Service, Azure Functions).Experience securing AI/ML development and deployment workflows (MLOps security).Experience with security incident response processes related to application vulnerabilities. Why Join Us?• Be part of a purpose-driven organization that is shaping the future of mobility• Work on cutting-edge technologies and global projects• Thrive in a collaborative, diverse, and inclusive environment• Access world-class infrastructure and continuous learning opportunitiesEqual Opportunity StatementAt MBRDI, we are committed to diversity and inclusion. We welcome applications from all qualified individuals, regardless of gender, background, or ability.Benefits Mit­arbeiter­rabatte möglich Gesund­heits­maß­nahmen Mit­arbeiter­handy möglich Essens­zulagen Betrieb­liche Alters­ver­sorgung Hybrides Arbeiten möglich Mobilitäts­angebote Mit­arbeiter Events Coaching Flexible Arbeits­zeit möglich Park­platz Betriebs­arzt Gute An­bindung Barriere­frei­heit Kinder­betreuung Kantine, Café KontaktMercedes-Benz Research and Development India Private LimitedBrigade Tech Gardens, Katha No. 119560037 BengaluruDetails zum StandortMBRDI Recruitment E-Mail: mbrdi_recruitment@mercedes-benz.com BewerbenDie Mercedes-Benz Group.Die Mercedes-Benz Group AG (ehemals Daimler AG) ist eines der erfolgreichsten Automobilunternehmen der Welt. Mit der Mercedes-Benz AG gehören wir zu den größten Anbietern von Premium- und Luxus-Pkw und Vans. Die Mercedes-Benz Mobility AG bietet Finanzierung, Leasing, Fahrzeugabos und –miete, Flottenmanagement, digitale Services rund um Laden und Bezahlen, die Vermittlung von Versicherungen sowie innovative Mobilitätsdienstleistungen an.Mehr erfahrenTechnische Support-HotlineKontaktStandorteAnbieterRechtliche HinweiseEinstellungenDatenschutzLizenzhinweise DritterAllgemeine Geschäftsbedingungen© 2026. Mercedes-Benz AG. Alle Rechte vorbehalten (Anbieter)