06 Aug
|
Winning Edge
|
India
06 Aug
Winning Edge
India
Role:
We are looking for a Senior Application Security Engineer with strong DevSecOps experience to secure enterprise applications throughout the Software Development Lifecycle. The ideal candidate should have hands-on experience implementing SAST, DAST and SCA within CI/CD pipelines, working with GitHub/GitLab, and collaborating with development teams to remediate security vulnerabilities.
Description:
1. Monitor and Analyze Vulnerabilities:
- Use established scanning tools and processes to identify security issues in mobile and web applications.
- Review scan results, verify risk levels, and recommend remediation strategies to application or engineering teams.
2. Contribute to Security Assessments:
- Participate in ongoing risk-based discussions with product owners, third-party engineers, and other stakeholders about application vulnerabilities.
- Help track and prioritize vulnerabilities according to established timelines and business impact.
3.
Maintain Scanning
Profiles & Policies:
- Follow and apply existing application security scan profiles and policies (containers, SAST, DAST, and crowd-sourced pen testing).
- Onboard new applications into scanning services and ensure adherence to brand-wide security standards.
4. Collaborate on Awareness & Best Practices:
- Support awareness campaigns and training programs to ensure application development teams follow existing security standards.
- Provide input to engineering teams on secure coding and design principles, referencing frameworks like the OWASP Top 10.
5.
Vulnerability
Monitoring & Remediation Support:
- Continuously monitor published vulnerabilities across various applications, operating systems, and databases.
- Assist in determining remediation priorities, coordinate with stakeholders, and re-scan to verify fixes.
- Collaborate with engineers for threat modeling and incident response, offering analytic support in root cause analysis.
6.
Incident Response
Collaboration:
- Work with incident response teams to investigate security incidents affecting applications.
- Help document findings, track remediation progress, and apply lessons learned to future prevention activities.
Basic Qualifications:
- Bachelors degree and at least 7 years of combined experience in cybersecurity and/or software development. (Equivalent experience may be considered in lieu of a degree.)
- Practical understanding of application cybersecurity vulnerabilities, the ability to assess their relevance, and experience planning remediation efforts.
- Strong communication skills to collaborate with technical personnel and third parties on vulnerability findings.
- Familiarity with continuous integration/continuous delivery (CI/CD) platforms.
- Awareness of compliance and data privacy regulations (e.g., PCI DSS, GDPR, CCPA) and their impact on application security.
- General knowledge of common programming languages and paradigms (OOP, functional, concurrent, etc.).
Technical Qualifications:
- Understanding of cloud environment security concepts (secrets management, infrastructure as code, serverless).
- Familiarity with CI/CD build/deployment pipeline technologies.
- Experience with application scanning tools (agile and static techniques) to interpret vulnerabilities and support remediation.
- Basic knowledge of containers and container management tools (e.g., Docker, Kubernetes), with the ability to recognize security findings and escalate them to engineering for remediation.
- Knowledge of HTTP communication fundamentals.
- Awareness of package management tools (npm, pip, apt) for operating systems or development languages.
📌 Senior Application Security Engineer - DevSecOps (India)
🏢 Winning Edge
📍 India