
Lead - Application Security SSDLC
Reserve Bank Information Technology Pvt Ltd7 months ago
Bengaluru, IndiaStaff+
Responsibilities
- Conduct internal and third-party SSDLC security risk assessments for business-critical assets and processes.
- Coordinate with project teams to enforce the security framework across all SSDLC phases.
- Prepare security effectiveness reports for management.
- Test applications and systems against SSDLC frameworks and RBI/ReBIT information security practices.
- Ensure new applications undergo SSDLC assessments before data-center induction.
- Track remediation of identified gaps and escalate unresolved issues when necessary.
- Define and enhance application security requirements and standards for agile development and traditional application architectures.
- Assist the DevSecOps team with secure, predictable CI/CD pipeline processes and secure application development capabilities.
Requirements
- University degree in computer science or IT.
- At least 6 years of information security experience.
- At least 4 years of software development lifecycle and project-lifecycle security review experience.
- Experience evaluating control environments through architecture, software design reviews, and threat modeling.
- Hands-on experience with Static Application Security Testing and Dynamic Application Security Testing.
- Experience standardizing application security tools and methodologies.
- Familiarity with OWASP, SANS Institute, ISACA, GAO, FISCAM, NSA, NIST, and IETF best practices.
- Experience with SAST, DAST, SCA, IAST, RASP, threat modeling, and software/application analysis tools.
- Any two of CISSP, CSSLP, cloud security certifications, or DevSecOps automation certifications.