ingrid.fyi India's software hiring trends, explained.
Sign in to ingrid.fyi with Google
Your Google account
name@gmail.com
Continue with Google
Home / Product companies / I · Networking, infrastructure and security / Cybersecurity / Application and API security
On this page
Application and API security Checking the software while it is being built, from the code to its APIs Say you are a software engineer at a company that builds a food-delivery app. You finish a feature and open a pull request. Before it can merge, a scanner reads your code. The open-source library you imported is checked against the security flaws that somebody found last week. The container your code ships in is inspected. And once the app is running, someone tries to break in through its API before an attacker does.

Every Market Segment so far in Industry Vertical 4 defends something that already exists: the inbox, the login, the laptop, the network. This one defends software while it is being written. It is the part of security that a developer meets first and most often. The industry calls it application security, or AppSec. Moving security checks earlier, into the developer's everyday work, is called shifting left.

Most of the application code in the world now comes from libraries the developer did not write. Most of the breaches that start in code start there too. So this Market Segment is as much about other people's software as your own. The buyers are companies that build software.

Every company named here has posted software engineering jobs in India. Famous companies that don't actively hire software engineers in India are left out.

This Market Segment has two sub-segments:

Scanning the code and its parts: the scanners that read the code and its libraries before the software ships. This is the established half of the business, and the one with the most job postings. Testing the running application: the tools that attack the application once it is running, especially its API. Also the newer layer that sits above every scanner and tells a security team which of ten thousand findings to fix first. Your pull request, checked twice. Before it ships, it is scanned: static analysis reads the code, software composition analysis checks the libraries, and the container image is inspected, with tools from companies such as Black Duck, Checkmarx, Sonatype and Endor Labs. Once it runs, it is attacked on purpose through its API, by services such as Astra Security and Qodex. Moving these checks into the developer's everyday work is called shifting left.Your pull request, checked twice. Before it ships, it is scanned: static analysis reads the code, software composition analysis checks the libraries, and the container image is inspected, with tools from companies such as Black Duck, Checkmarx, Sonatype and Endor Labs. Once it runs, it is attacked on purpose through its API, by services such as Astra Security and Qodex. Moving these checks into the developer's everyday work is called shifting left.

Keep reading, free

Two more sections are on this page: Scanning the code and its parts and Testing the running application. Sign in to read them here, in full.

Continue with Google
  • Scanning the code and its parts
  • Testing the running application
Scanning the code and its parts Static analysis, software composition analysis, the software bill of materials, container images

Back to your pull request from the start of this Market Segment. Two kinds of scanner read it before it merges:

Static application security testing (SAST)reads the source code for patterns that become vulnerabilities. Examples are unchecked user input, or a password written into the code, called a hard-coded secret. Software composition analysis (SCA)reads the list of libraries the code depends on. It matches them against databases of known security flaws and of licences.

SCA became the faster-growing of the two after two events. In 2021, a serious flaw was found in Log4j, a logging library used in a huge number of Java programs, and companies scrambled to find where they used it. And regulators began to demand a software bill of materials (SBOM) for every piece of software: a list of every library inside it.

What is inside your software. An app is your own code plus many open-source libraries you did not write. Software composition analysis matches those libraries against databases of known flaws and licences, and the software bill of materials lists every library inside. The 2021 Log4j flaw sent companies looking for where they used it.What is inside your software. An app is your own code plus many open-source libraries you did not write. Software composition analysis matches those libraries against databases of known flaws and licences, and the software bill of materials lists every library inside. The 2021 Log4j flaw sent companies looking for where they used it. Black Duckis the largest company in this Market Segment, and the clearest example of this category's history. Synopsys, the chip-design company, built a software-security business by buying companies. In 2024 it spun that business out again as Black Duck. The new company took with it Coverity, the static analyser that a generation of C and Java teams ran, and the composition analysis Black Duck is named for. It has engineers in Bengaluru. Checkmarxfrom Israel, is the other established name in static analysis. It has engineers in Pune. Sonatyperuns the repository that most Java developers download their libraries from. It sells composition analysis built on the history of that repository. Its India centre is in Hyderabad. Revenerain Bengaluru, looks at the same libraries from the licensing side. It checks whether the open-source code in a product is licensed for the way the product uses it. That is a legal risk before it is a security one. Endor Labsis a newer company. It asks which of the flagged libraries the code actually reaches and uses, so teams fix ten things instead of a thousand. It now also governs the code that AI assistants write. RapidFortlooks at the container image the software ships in: the packaged file that holds the app and everything it needs to run. It strips out the parts that are never used, which removes their vulnerabilities with them.

One company here comes from the place where finished software is stored:

JFrogsells an artifact repository, the store for the built software, called binaries, ready to deploy. More and more scanning happens there. Its Xray product is composition analysis built into the place the binaries live.

JFrog is covered mainly in Market Segment 6.1, DevOps and CI/CD tools (in Industry Vertical 6, Devtools companies). Black Duck, Checkmarx and Revenera also appear there, where security runs as a step in the developer's pipeline.

Testing the running application Dynamic testing and penetration testing as a service, API security, and the posture layer above the scanners

Back to the food-delivery app from the start of this Market Segment. It is now live. The other way to find a flaw is to attack the running app the way an intruder would. This is called dynamic testing. When skilled people try to break in on purpose, with the owner's permission, it is called penetration testing.

The modern version is a service: automated scanning that runs all the time, with human testers behind it. It is sold as a subscription, rather than as a test once a year. (More on the attackers a company invites in, in Market Segment 4.11, Vulnerability management and penetration testing.)

Astra Securitywith engineers in Bengaluru, sells penetration testing as a service, with its own scanner. Qodexstarted in Bengaluru and now has a US office in San Francisco. It is a young company doing the same for the API alone. The API is the interface most modern apps expose, and the one most attacks now target. Qodex's scanner writes and runs the tests itself.

Above all the scanners sits a problem of its own. A large company runs a dozen scanners and drowns in their findings.

ArmorCodewith engineers in Delhi NCR, sells the layer that collects every finding from every tool. It removes the duplicates, scores each finding by how much it matters to the business, and hands the developer a short list. The industry now calls this application security posture management (ASPM). Too many findings, one short list. The code scanner, the library scanner, the container scanner and the API tests all send their findings to ArmorCode, which removes the duplicates, scores each finding by how much it matters to the business, and hands the developer a short list.Too many findings, one short list. The code scanner, the library scanner, the container scanner and the API tests all send their findings to ArmorCode, which removes the duplicates, scores each finding by how much it matters to the business, and hands the developer a short list.

One company here does the same work on a different target, the phone app:

Zimperiumis here for its mobile app security. Its tools protect a company's own phone app against tampering and against reverse engineering, which means taking the app apart to see how it works. (More on it in Market Segment 4.4, Endpoint security and device management.) Securing the code the model wrote.

A growing share of new code is written by AI assistants. They import libraries nobody chose, and repeat the flaws in the code they learned from. So the scanners are being rebuilt to read that code, and the assistant's suggestions, as they appear. Endor Labs sells this as AI code governance. Black Duck, Checkmarx and Sonatype are shipping the same. The same kind of AI can find a weak point in an API on its own, which is exactly what an attacker wants. Qodex and Astra are building it for the defence.

So your pull request from the start of this Market Segment is checked twice. It is scanned as code and libraries before it ships. Then it is attacked, on purpose, as a running app.
Who they hire

Who these companies hire, and for what, is on What cybersecurity hires for.

Privacy Terms Refunds and cancellation Shipping and delivery © 2026 ingrid.fyi · Payments by Razorpay
You're browsing as a guest. Sign in free to follow links for five minutes, once an hour.