Your browser cookies must be enabled in order to apply for this job. Please contact support@jobscore.com if you need further instruction on how to do that.

Senior Application Security Engineer - India

Security | Remote, India | Full Time

Job Description

Job Description

Finalsite is the preferred website, communications, enrollment, and marketing platform of more than 7,000 schools and school districts in 119 countries around the world. The company’s people, products and services transform how schools connect and engage with their community, recruit students and staff, and fundraise; while managing the complex requirements around data privacy, accessibility, hosting and security. Finalsite products and services include award-winning website designs, a robust content management system, mass communications tools, a powerful enrollment management system, innovative inbound marketing tools, data integration, training, support and marketing consulting. Finalsite is headquartered in Glastonbury, CT, USA with employees who work remotely in nearly every state in the U.S. as well as Europe, South America, and Asia. For more information, please visit www.finalsite.com.

Vision

To build innovative solutions that elevate school engagement.


Location

Remote, India. Full time employment for this role.

Finalsite is a global company and to enable strong collaboration, we have established common core working hours. Candidates should be comfortable working from 11:30-21:00 IST, with core working hours being 18:00-21:00 IST


Summary of Responsibility

The Senior Application Security Engineer is responsible for identifying, triaging, and remediating security vulnerabilities across Finalsite’s web applications and proprietary software systems. Working closely with the core development and quality assurance teams, this role modifies and refactors application code, implements secure coding practices, and ensures robust security controls across internal pipelines, cloud integrations, and student data environments. The position plays a direct role in maintaining compliance with educational data privacy laws (FERPA/COPPA) and international standards (GDPR/UK GDPR) while defending Finalsite applications against modern cyber threats.


Key Responsibilities

  • Vulnerability Triage & Assessment: Conducts technical triage on security vulnerabilities identified across web applications via Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), penetration testing reports, and bug bounty programs.

  • Code Remediation & Refactoring: Modifies and refactors .NET/C# code to remediate identified security vulnerabilities in accordance with established risk prioritization schedules.

  • Secure SDLC & Frameworks: Develops, maintains, and enforces secure coding standards across development teams; implements reusable secure coding patterns (e.g., Object-Relational Mapping (ORM), output encoding frameworks) to catch vulnerabilities early in the software development life cycle.

  • Developer Assistance & Code Reviews: Directly assists software developers with code reviews to verify adherence to secure coding guidelines and remediate complex security flaws.

  • Threat Monitoring: Stays current on emerging web application threats, exploit techniques, and iterations of the OWASP Top 10.

  • Data Privacy & Compliance Support: Ensures application security controls comply with central, state, and international Data Protection Laws


Qualifications and Skills

Required:

  • Education: Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.

  • Experience: Minimum 7+ years of dedicated hands-on experience in application security.

  • Development Expertise: Strong, hands-on software development experience with .NET/C# refactoring and remediation.

  • Security Knowledge: In-depth understanding of web application vulnerabilities, remediation techniques, and the OWASP Top 10.

  • Testing Tools & Programs: Direct experience working with SAST, DAST, third-party penetration testing reports, and bug bounty management.

  • Soft Skills: Excellent problem-solving skills, analytical capabilities, and strong cross-functional communication and collaboration skills.

Preferred:

  • Cloud Security: Experience securing applications deployed in multi-cloud environments (e.g., AWS, GCP, Azure).

  • Regulatory Familiarity: Knowledge of educational and data privacy frameworks, including FERPA, COPPA, GDPR, and SOC 2 standards.

  • Certifications: Professional security certifications such as CASE, GWAPT, GWEB, or Certified Ethical Hacker (CEH) are a plus.


RESIDENCY REQUIREMENT

Finalsite offers 100% fully remote employment opportunities, however, these opportunities are limited to permanent residents of India. Current residency, as well as continued residency, within India is required to obtain (and retain) employment with Finalsite.

DISCLOSURES

Finalsite is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to equal employment opportunities regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. EEO is the Law. If you have a disability or special need that requires accommodation, please contact Finalsite's People Operations Team. Finalsite is committed to the full inclusion of all qualified individuals. As part of this commitment, Finalsite will ensure that persons with disabilities or special needs are provided a reasonable accommodation. Ensure your Finalsite job offer is legitimate and don't fall victim to fraud. Ask your recruiter for a phone call or other type of verbal communication and ensure all email correspondence is from a finalsite.com email address. For added security, where possible, apply through our company website at finalsite.com/jobs.