Identify, analyze, and remediate application security vulnerabilities such as XSS, CSRF, session fixation, IDOR, and path traversal issues " Collaborate with security teams to triage and resolve findings from vulnerability scans, penetration testing, and security audits " Implement secure coding practices, including input validation, output encoding, and proper authentication/authorization mechanisms " Update and manage third-party libraries (e.g., Axios, jQuery, Ext.js), ensuring no outdated or vulnerable versions are in use " Configure and enforce web security controls such as CSP headers, secure cookies (HttpOnly, Secure, SameSite), and cache directives " Debug and resolve issues related to HTTP errors (e.g., 500 errors), session management, and application behavior inconsistencies. " At least 3+ years of hands-on experience in application security, including identifying and remediating vulnerabilities such as XSS, CSRF, IDOR, and session-related issues " At least 1+ year of experience working in Agile/Scrum environments, participating in sprint ceremonies and collaborative development.