04 Aug
|
ICICI Bank
|
Mumbai
Essential Services: Role & Location Fungibility:
While the role descriptions give you an overview of the responsibilities, it is only directional and guiding in nature. At ICICI Bank, we believe in serving our customers beyond our role definition, product boundaries, and domain limitations through our philosophy of customer 360-degree. In essence, this captures our belief in serving the entire banking needs of our customers as One Bank, One Team.
To achieve this, employees at ICICI Bank are expected to be role and location-fungible with the understanding that Banking is an essential service. About the Role:
We are looking for a skilled professional to join our Information Security Team as a Application special resource (SME). We are looking for candidate with a strong knowledge in application security testing, vulnerability management, and understanding of the BFSI domain, the candidate is well-equipped to lead security initiatives in organizations while adhering to regulatory standards and frameworks. The combination of technical skills, team leadership, and effective communication sets the stage for successful collaboration and implementation of enhanced security measures.
Roles & Responsibilities Proficient in various application security testing methods such as Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Interactive Application Security Testing (IAST).
Solid understanding of security testing tools (e.g., OWASP ZAP, Burp Suite, Fortify) and their application in identifying vulnerabilities in software applications.
Experienced in establishing and managing a vulnerability management lifecycle, including vulnerability scanning, assessment, prioritization, and remediation.
Knowledge of remediation strategies and risk assessment methodologies to effectively mitigate vulnerabilities.
Skilled in reviewing security assessment reports for accuracy and completeness, ensuring that findings are actionable and comprehensible to technical and non-technical stakeholders.
Strong ability to write detailed reports and documentation that communicate security risks and mitigation strategies.
Proven experience in leading and mentoring cross-functional teams in security assessment activities, fostering a collaborative and high-performance culture.
Ability to manage team dynamics and facilitate knowledge sharing among team members to enhance overall skill levels.
In-depth knowledge of industry-standard frameworks such as: NIST Cybersecurity Framework, OWASP Top Ten, SANS 25 (Top 25)
Experience implementing above frameworks to bolster the security posture of applications.
Expertise in security vulnerability exception handling
Create Security Test Plans and Dashboards
Support application team to perform application vulnerability assessments and document vulnerabilities which were found and provide recommendations for remediation according to BFSI guidelines and industry best practices
Prioritizing security vulnerabilities identified during assessment and its severity, impact identification
Hands on experience in Network Penetration testing, system vulnerability assessment and configuration review
Lead analysis on Quality review findings performed to discern trends and focus areas for appropriate management
Participate in additional key risk and control projects related to the enhancement of technology risk assessment and measurement programs Requirements / Key Skills: Expertise in application security testing methodologies and tools.
In-depth knowledge of vulnerability management processes.
Proficient in reviewing and analyzing security reports to identify critical vulnerabilities.
Strong ability to lead and manage teams focused on application security initiatives.
Experience in managing and documenting application security exceptions.
Effective communicator with the ability to present security findings and recommendations clearly and concisely.
Previous experience in the BFSI (Banking, Financial Services, and Insurance) domain.
Knowledge of RBI (Reserve Bank of India) application security guidelines and compliance requirements.
In-depth understanding on Common Vulnerability Exposure (CVE)/ Cert advisory database
Knowledge of Network Security technology in areas of Firewall, IPS, VPN, Gateway security solutions (proxy, web filtering) Desired Candidate Profile:
Engineering Graduate in CS,IT, EC or InfoSec , CyberSec or MCA equivalent
Certifications Preferred: OSCP, CRTP, CEH, CISSP
Strong organizational, teamwork, multitasking & time management skills
10+ years of relevant working experience
Outstanding communication abilities. Ability to effectively communicate the required recommendations
Ability to work under pressure & Fast paced environment
Strong attention to detail with an analytical mindset & outstanding problem solving skills
Great Awareness of cyber security trends & hacking techniques About the Business Group:
The Information Security Group at ICICI Bank believes in providing services to its customers in the safest and secure manner keeping in mind that data protection for its customers is as important as providing quality banking services across the spectrum. The CIA triad of Confidentiality, Integrity, and Availability is at the heart of building a comprehensive information security framework. The Bank also lays emphasis on customer elements like protection from phishing, adaptive authentication, awareness initiatives, and provide easy to use protection and risk configuration ability in the hands of customers.
The Bank also undertakes campaigns to create awareness among customers on security aspects while banking through digital channels.
📌 Application Security Manager (Mumbai)
🏢 ICICI Bank
📍 Mumbai