Application security engineers work upstream of the breach — threat modelling during design, reviewing code, running static and dependency analysis, and building security checks into the pipeline. The role requires reading code fluently as well as understanding attacks, and that combination is scarce in India, which keeps supply tight relative to demand at product companies and fintech. It is generally reached from either a development background or a penetration testing background rather than entered directly.