2 days ago
Mumbai, IndiaSenior
Responsibilities
- Drive application security across design, development, deployment, and production.
- Conduct security assessments and identify vulnerabilities across web, mobile, API, backend, and other application components.
- Perform and support SAST, DAST, SCA, API security testing, and penetration testing.
- Conduct threat modeling and security reviews and provide remediation recommendations.
- Partner with engineering and product teams to implement secure-by-design and secure-by-default practices.
- Review application architecture, designs, and code for security weaknesses and recommend controls.
- Define and maintain secure coding standards, application security guidelines, and security best practices.
- Triage, prioritize, and remediate vulnerabilities based on severity, business impact, and exploitability.
- Integrate security tools and automated checks into CI/CD pipelines for continuous security testing.
- Develop automation and tooling to scale application security assessments.
- Assess third-party libraries, dependencies, APIs, and open-source components for security risks.
- Support incident investigations through analysis of application logs, attack patterns, vulnerabilities, and potential compromise areas.
- Address risks involving authentication, authorization, session management, encryption, data protection, and API security.
- Prepare security documentation, risk assessments, remediation reports, and audit evidence.
- Monitor emerging application security threats and translate them into security improvements.
Requirements
- Hands-on experience in application security, product security, or software security engineering.
- Strong understanding of web, mobile, API, and backend application security.
- Knowledge of OWASP Top 10, OWASP API Security Top 10, secure coding practices, and common application vulnerabilities.
- Experience with SAST, DAST, SCA, API security testing, and penetration testing methodologies and tools.
- Experience with threat modeling, security architecture reviews, and secure SDLC practices.
- Familiarity with authentication, authorization, encryption, API security, and data protection principles.
- Experience integrating security controls into CI/CD and DevSecOps workflows.
- Strong scripting or programming skills in Python, Shell, Java, JavaScript, or similar languages.
- Experience with vulnerability management, security risk assessment, and remediation tracking.
- Strong analytical, troubleshooting, problem-solving, communication, and collaboration skills.
- Bachelor’s degree in Computer Science, Information Security, Engineering, or a related technical field.
- 3–6 years of experience in Application Security, Product Security, Security Engineering, or a related field.
- Experience securing consumer-facing web, mobile, API, or large-scale digital products is preferred.
- Experience with fast-paced product engineering teams or media/OTT platforms is an advantage.
- OSCP, CEH, CSSLP, or equivalent security certifications are a plus.
Tech Stack
Categories
About Hotstar
We’ve moved! 🌟 Follow us on @JioHotstar for all the latest stories, updates & more.
