Responsibilities
• Conduct secure code reviews and vulnerability assessments.
• Collaborate with development teams to implement secure coding practices.
• Use tools like SAST/DAST/IAST for automated security testing.
• Develop and enforce application security policies and standards.
• Integrate security practices into DevOps workflows and CI/CD pipelines.
• Automate security testing using tools like GitHub Dependabot or Snyk.
• Monitor container and infrastructure security.
• Perform manual and automated penetration tests on networks, applications, and systems.
• Simulate cyberattacks to identify security weaknesses.
• Develop detailed reports on findings and remediation recommendations.
• Stay updated with emerging threats and exploit techniques.
• Provide oversight of application security control metrics
• Communicate security risks and recommendations to senior management and other stakeholders.
• Conduct detailed threat modeling exercises for applications, systems, and architectures.
Skills/Requirement
• 4+ years’ experience in the domain of application security in web and mobile and development experience preferably in Java/python/.net
• Strong understanding of OWASP Top 10, secure SDLC, and common vulnerabilities.
• Hands-on experience with tools like Veracode, Checkmarx, or SonarQube.
• Collaborate with DevOps teams to secure CI/CD pipelines.
• Manage the lifecycle of vulnerabilities from detection to resolution.
• Knowledge of CVSS scoring and prioritizing vulnerabilities.
• Familiarity with patch management processes.
• Proficiency in tools like Jenkins, Docker, and Kubernetes.
• Strong scripting knowledge for automating tasks.
• Proven experience in application security, with a strong understanding of web application vulnerabilities (OWASP Top 10, etc.).
• Strong understanding of threat modeling methodologies like STRIDE, DREAD, or PASTA.
Interested applicants may submit your detailed resume to [email protected] .
We regret to inform that only shortlisted candidates will be contacted.