Application Security Engineer II

Jifflenow
Jifflenow

India · Gurugram, Haryana, India

Posted on Jun 30, 2026
Overview:

Cvent is a leading meetings, events, and hospitality technology provider with more than 5,000+ employees and 24,000+ customers worldwide, including 60% of the Fortune 500. Founded in 1999, Cvent delivers a comprehensive event marketing and management platform for marketers and event professionals and offers software solutions to hotels, special event venues and destinations to help them grow their group/MICE and corporate travel business. Our technology brings millions of people together at events around the world. In short, we’re transforming the meetings and events industry through innovative technology that powers the human connection.

Cvent's strength lies in its people, fostering a culture where everyone is encouraged to think like entrepreneurs, taking risks and making decisions confidently. We value diverse perspectives and celebrate differences, working together with colleagues and clients to build strong connections.

AI at Cvent: Leading the Future

Are you ready to shape the future of work at the intersection of human expertise and AI innovation? At Cvent, we’re committed to continuous learning and adaptation—AI isn’t just a tool for us, it’s part of our DNA. We’re looking for candidates who are eager to evolve alongside technology. If you love to experiment boldly, share your discoveries, and help define best practices for AI-augmented work, you’ll thrive here. Our team values professionals who thoughtfully integrate AI into their daily work, delivering exceptional results while relying on the human judgment and creativity that drive real innovation

Throughout our interview process, you’ll have the chance to demonstrate how you use AI to learn, iterate, and amplify your impact. If you’re excited to be part of a team that’s leading the way in AI-powered collaboration, we’d love to meet you.

Disclaimer: Beware of Recruitment Scams – Legitimate Cvent recruiting communications will always come from an official ‘name@cvent.com email. We never request any payments or ask for sensitive personal or financial information via chat or social media platforms. For more information, please visit: https://www.cvent.com/en/notice-recruitment-fraud

Who are you? You're a hands-on Application Security Engineer who is energized by the intersection of security and AI. You like to build, not just review — you write automation, wire up agents, and turn repetitive security work into self-serve tooling that developers actually use. You're comfortable across the core of AppSec (threat modeling, secure design and code review, penetration testing, vulnerability remediation) and you bring a builder's mindset that multiplies your impact. You're looking to grow your technical depth while contributing to a security program that treats AI as a first-class engineering capability, not an afterthought. You're required to be in the office 2 days/week.


In This Role, You Will:

  • Build and maintain AI-powered security automation — agents, skills, and pipelines that automate threat modeling, vulnerability triage, finding deduplication, and report generation across diverse tech stacks.
  • Develop and extend agentic workflows that integrate LLMs into security tooling through APIs and MCP (Model Context Protocol) connectors to systems like Jira, Confluence, and cloud security platforms.
  • Integrate and run security tooling across the SDLC — embedding SAST, DAST, and SCA into CI/CD pipelines and improving signal quality with AI-assisted triage.
  • Perform threat modeling, secure code and design reviews, and targeted penetration testing for new and existing features, including cloud-native, GenAI, and AI/ML systems.
  • Apply AI security frameworks in practice — OWASP LLM Top 10, OWASP AI Testing Guide, and MITRE ATLAS — to assess prompt injection, model abuse, data exposure, and agent-misuse risks.
  • Write internal tools and scripts (Python, TypeScript, JavaScript, Bash) to automate security testing and governance, including support for cloud-native apps on AWS.
  • Partner with engineering teams to remediate vulnerabilities surfaced through scans, manual testing, or AI-assisted analysis, and clearly communicate risk to technical audiences.

Here's What You Need:

  • 3–5 years of hands-on experience in application security or secure software development.
  • Solid scripting/programming skills — able to automate tasks and build internal tools in Python, JavaScript/TypeScript, or Bash.
  • Working experience integrating security tools into CI/CD pipelines and the SDLC.
  • Familiarity with at least one major cloud platform (AWS preferred; GCP or Azure acceptable) and cloud-native security principles.
  • Proficiency with common security testing and cloud security tools (e.g., Burp Suite, Checkmarx, Mend, Veracode, ZAP, Wiz).
  • Strong grasp of AppSec fundamentals — OWASP Top 10, CWE, secure coding practices, and common web/API vulnerability classes. This is the hard floor for the role.
  • Exposure to LLMs and AI agents and a genuine drive to build with them — you've experimented with AI tooling and want to do it professionally. You do not need to have shipped production AI tooling; that's what you'll grow into here.
  • Hands-on experience building with LLM APIs, AI agents, or automation frameworks (e.g., Claude, MCP, function/tool calling), or exposure to securing AI/ML and GenAI features.
  • DevSecOps, IaC security, or supply-chain experience, and relevant certifications (e.g., AWS Security – Specialty, OSCP, GWAPT)

Why You’ll Love This Role

  • You'll build AI-driven security automation that scales across hundreds of apps and services and see it adopted by real developers.
  • You'll join the ASRE team and grow your skills at the leading edge of AI-assisted Application Security.
  • You'll work alongside engineers who take security seriously and give you the room to ship and iterate.
  • You'll have a clear runway to grow into a Senior role as your technical depth and ownership expand.