- Location
- IND-Pune-Smartworks, India
- Workplace
- Hybrid
- Type
- Full-time
- Department
- Engineering
- Experience
- 3+ years
- Education
- Bachelor
- Closing date
- Today
- Source
- Workday
Description
Position Summary
We are seeking a highly motivated AppOps Security Engineer to join our Health AppOps team. The successful candidate will play a critical role in strengthening the security, compliance, and operational resilience of enterprise applications. This role is responsible for security and compliance analysis, vulnerability management and remediation, automation of operational and security processes, and ensuring applications meet operational readiness standards.
The candidate will also actively support internal and external audits, including SOC 2, PCI DSS, and NIST-based assessments, while partnering with application owners, infrastructure teams, security teams, and business stakeholders to drive continuous improvement across the application landscape.
Key Responsibilities
Security & Vulnerability Management
- Analyze application security risks and identify vulnerabilities across the application portfolio.
- Coordinate and drive remediation activities for identified security findings.
- Track vulnerabilities through their lifecycle and ensure timely closure in accordance with organizational SLAs.
- Collaborate with development, infrastructure, and security teams to implement corrective actions.
- Review security scan reports and validate remediation efforts.
Compliance & Governance
- Support application compliance initiatives aligned with organizational policies and industry standards.
- Participate in compliance assessments and audits, including:
- SOC 2
- PCI DSS
- NIST Framework
- Internal and external regulatory audits
- Gather, review, and maintain audit evidence and documentation.
- Track and manage compliance-related action items and remediation plans.
Operational Readiness & Application Governance
- Participate in Operational Readiness Review (ORR) checkpoints for applications transitioning into production.
- Validate that applications meet operational, security, monitoring, backup, and support requirements.
- Ensure operational controls and documentation are complete and maintained.
- Identify operational risks and recommend mitigation strategies.
Automation & Continuous Improvement
- Develop and maintain automation solutions to improve security, compliance, and operational processes.
- Automate vulnerability tracking, compliance reporting, monitoring, and operational workflows where possible.
- Drive process optimization initiatives to improve efficiency and reduce manual effort.
- Contribute to the development of dashboards and reports for management visibility.
Stakeholder Collaboration
- Work closely with Application Owners, Security Teams, Infrastructure Teams, and Audit Partners.
- Provide updates on security posture, compliance status, and remediation progress.
- Participate in governance meetings and review forums.
Required Qualifications
- Bachelor's Degree in Engineering, Computer Science, Information Technology, or a related field.
- 3–4 years of experience in Application Operations, IT Operations, Security Operations, Compliance, or related domains.
- Good understanding of application security concepts and vulnerability management practices.
- Experience supporting compliance frameworks such as SOC 2, PCI DSS, and NIST.
- Familiarity with audit processes, controls testing, and evidence collection.
- Experience with scripting and automation using tools such as PowerShell, Python, Shell scripting, or similar technologies.
- Strong analytical, problem-solving, and troubleshooting skills.
- Excellent communication and stakeholder management abilities.
- Familiarity with cloud environments (Azure, AWS, or GCP).
Preferred Qualifications
- Knowledge of vulnerability management tools such as Tenable, Qualys, Rapid7, or similar platforms.
- Experience with ServiceNow, Jira, or other ITSM/GRC platforms.
- Understanding of operational risk management and governance processes.
- Security-related certifications such as Security+, SSCP, or equivalent are advantageous.
- Exposure to DevSecOps and secure application lifecycle practices.
Key Competencies
- Security and Risk Management
- Compliance and Audit Readiness
- Vulnerability Assessment & Remediation
- Process Automation
- Operational Governance
- Problem Solving and Analytical Thinking
- Cross-functional Collaboration
- Documentation and Reporting
- Continuous Improvement Mindset
Success Measures
The successful candidate will:
- Reduce security vulnerabilities through timely remediation and tracking.
- Improve audit readiness and compliance posture across applications.
- Increase operational efficiency through automation initiatives.
- Ensure applications successfully pass Operational Readiness Reviews.
- Deliver accurate and timely compliance and security reporting.
Role Level: Individual Contributor
Function: Application Operations (AppOps)
Experience: 3–4 Years
Employment Type: Full-Time
Our Interview Practices
To maintain a fair and genuine hiring process, we kindly ask that all candidates participate in interviews without the assistance of AI tools or external prompts. Our interview process is designed to assess your individual skills, experiences, and communication style. We value authenticity and want to ensure we’re getting to know you—not a digital assistant. To help maintain this integrity, we ask to remove virtual backgrounds and include in-person interviews in our hiring process. Please note that use of AI-generated responses or third-party support during interviews will be grounds for disqualification from the recruitment process.
Applicants may be required to appear onsite at a Wolters Kluwer office as part of the recruitment process.