over 1 year ago
Pune, IndiaStaff+
Responsibilities
- Set up, lead, and technically steer the application security team.
- Triage high- and critical-severity findings and drive remediation.
- Identify, approve, and classify high-severity vulnerabilities as true or false positives.
- Support product teams with implementing SAST and SCA in CI/CD pipelines.
- Provide application security consultancy and technical guidance on vulnerability mitigation.
- Identify security risks in application architecture and infrastructure and drive mitigations.
- Contribute to secure SDLC frameworks and automated security control validation during development and deployment.
- Support software engineering teams in addressing vulnerabilities and weaknesses.
- Serve as the technical authority for application security engineers.
- Contribute to Security and Privacy Engineering activities and improve application security processes and capabilities.
Requirements
- Bachelor's degree in computer science, information technology, cybersecurity, or a related field.
- 7+ years of relevant experience, preferably in an enterprise environment.
- Hands-on DevSecOps experience.
- In-depth knowledge of application security technologies and tools including SAST, SCA, and DAST.
- Strong scripting skills and experience developing CI/CD automation.
- Good understanding of Git concepts and vendors such as GitHub and GitLab.
- Deep understanding of OWASP and ASVS.
- Proficiency with vulnerability assessments and automated scanning tools such as Qualys and Polaris.
- Understanding of CVEs, CVSS, and vulnerability databases and familiarity with NVD and CVE frameworks.
- A master's degree or relevant certifications such as CISSP or CSSLP may be preferred.
- Strong communication, reporting, presentation, organizational, prioritization, and interpersonal skills.
