AppSec Jobs
← Back to all jobs

Sonata Software

Security Engineer – SAST & SCA

Bengaluru, Karnataka, IndiaPosted 2 days agoWebsite
Apply on LinkedIn →

About This Role

Not available in provided data

About Sonata Software

Sonata Software is a prominent Indian information technology services company based in Bengaluru. Founded in 1986, it specializes in modernization engineering, platform-based digital transformation, and IT consulting, generating $1 billion in annual revenue. The company operates globally, with a presence in North America, the UK, Europe, APAC, and ANZ, and is publicly traded on Indian stock exchanges. The core service of Sonata is modernization engineering, utilizing its proprietary Platformation™ framework to support digital businesses through automation and managed services. Its offerings include cloud and data modernization, Microsoft Dynamics modernization, digital contact center management, application development, and various enterprise services. Sonata also provides a range of proprietary digital platforms, such as the Brick & Click Retail Platform© and the Rezopia Digital Travel Platform©, along with capabilities on ISV platforms like Microsoft Dynamics 365 and SAP Hybris. Sonata serves diverse industries, including retail, travel and tourism, manufacturing, and banking. The company has established strategic partnerships with major technology providers like Microsoft, Amazon, and Google, and has earned recognition for its innovation and customer-centric approach.

Industry

information technology & services

Employees

6,100

2783 engineers

Revenue

$1.1B

Website

Visit →

Security at Sonata Software

Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.

3 Intel Signals

Security Philosophy

The stated security philosophy is security by design, zero trust, least privilege, defence in depth, risk-based controls, continuous monitoring, accountability, and stakeholder assurance. Public material describes embedding security from project inception, applying controls according to risk assessment, threat intelligence, and business impact, and using guardrails rather than roadblocks for AI-enabled development. Public evidence supports developer enablement through shift-left practices, CI/CD scanning, secure-by-default systems, design reviews, and developer security training. No public evidence was found for a formal Security Champions program, explicit AppSec sign-off gates, or a named AppSec mission separate from the broader information-security program. Evidence IDs: E-011–E-016.

Security Team

Sonata Software's public security organization is led by Madhu K, Chief Information Security Officer. Public professional profiles also identify Aparna Bhaskar as Digital Architect – Information Security and several security, testing, and cyber-security personnel. The official governance model places the Information Security Management Program under the CISO and says it is supported by domain experts. A reliable total team-size estimate is not publicly available. Two clearly active, relevant security postings were identified as of: Cyber Security Vulnerability Assessment/Management Specialist and Cyber Security Analyst. A SAST/SCA posting was also publicly listed, but its status is inconsistent across job boards. Common requirements include vulnerability management, risk assessment, OWASP Top 10, SAST/SCA/DAST, CI/CD scanning, cloud security, penetration testing, CSPM, scripting, and security reporting. Evidence IDs: E-001–E-006.

Key Initiatives

  • Publicly evidenced workflows and initiatives include: integrating SAST, DAST, SCA, and IaC scanning into CI/CD.
  • Automating security controls and policy checks.
  • Shift-left and developer security enablement.
  • Threat modeling, risk assessments, design reviews, sprint-planning input, secure-by-default architecture, cloud security reviews, annual internal and external penetration testing, OWASP-based web-application assessments, CVSS and business-risk prioritization, remediation-SLA tracking, escalation of overdue critical vulnerabilities, vulnerability KPIs and dashboards, and executive and technical reporting.
  • A recent CISO-authored initiative theme is responsible AI governance, including secure AI adoption, measurable security outcomes, secure-coding standards, insecure-dependency reduction, business and regulatory context, stakeholder accountability, continuous validation, code scanning, and security testing.
  • No formal Security Champions program, bug-bounty intake, named ticketing workflow for AppSec, or specific AppSec remediation SLA was publicly documented.
  • Evidence IDs: E-007–E-010, E-014–E-016.

Preparing for an AppSec interview?

Get the weekly briefing 2,000+ security pros trust.

Interested in this role?

Apply on LinkedIn