06 Aug
|
Utthunga Technologies
|
Bengaluru
06 Aug
Utthunga Technologies
Bengaluru
- Solid experience implementing and monitoring IEC 62443-4-1 Secure Development Lifecycle requirements.
- Strong understanding of Secure Development Lifecycle processes, software security assurance, and cybersecurity compliance.
- Hands-on experience conducting STRIDE Threat Modelling and secure architecture reviews.
- Strong experience performing penetration testing for Web Applications, Mobile Applications, and Thick Client/Desktop Applications.
- Strong understanding of OWASP Top 10, secure coding principles, application security testing methodologies, and common software vulnerabilities.
- Strong knowledge of vulnerability assessment, vulnerability management, and industry-standard risk scoring methodologies such as CVSS.
- Hands-on experience with application security tools such as Burp Suite, OWASP ZAP, SonarQube, Black Duck, Wireshark, and common Kali Linux security tools.
- Good understanding of software development and secure development practices using one or more technologies such as .NET/C#, Java, Python, or C++.
- Strong understanding of web technologies, REST APIs, authentication and authorization mechanisms, encryption, secure communications, and networking concepts including HTTP, HTTPS, TCP/IP, and TLS.
- Good understanding of security controls such as encryption, secure authentication, secure session management, defense-in-depth, least privilege, and Zero Trust principles.
- Experience working in Agile/Scrum development environments with cross-functional software engineering teams.
- Experience developing and reviewing security documentation, standards, procedures, and compliance evidence.
- Excellent analytical, problem-solving, communication, and stakeholder management skills.
- Ability to mentor junior engineers and promote secure development best practices across project teams.
Minimum Qualification
- Bachelor’s degree in computer science, Information Technology, Electronics, Cybersecurity, or a related Engineering discipline.
- 3–5 years of experience in Application Security/Product Security (preferred over network security).
- Professional cybersecurity certifications such as CEH, CompTIA Security+, CompTIA PenTest+, or equivalent are preferred.
Roles and Responsibilities
- Drive and monitor Secure Development Lifecycle (SDL) implementation across software development projects in compliance with prescribed cybersecurity standards.
- Ensure project compliance with IEC 62443-4-1 Secure Development Lifecycle requirements by creating/maintaining compliance artifacts and client-defined cybersecurity processes.
- Contribute to all stages of the Secure Development Lifecycle, including Security Requirements Analysis, Secure Design, Secure Implementation, Security Testing, and Secure Deployment.
- Support STRIDE-based Threat Modelling activities for software products and collaborate with architects and development teams to identify and mitigate security risks.
- Ensure project teams adhere to secure coding standards by supporting manual code reviews and automated security scanning activities.
- Coordinate and analyze Static Application Security Testing (SAST) and Software Composition Analysis (SCA) results using approved security tools,
and work with development teams to remediate identified findings.
- Develop security test plans covering penetration testing, security requirements verification, threat validation testing, vulnerability assessment, and regression testing.
- Design and maintain comprehensive security test cases and test suites aligned with project requirements and cybersecurity standards.
- Perform manual penetration testing of web applications, mobile applications, and thick client applications, validate identified vulnerabilities, and verify remediation effectiveness.
- Review, analyze, document, and track security defects through successful closure while ensuring timely reporting and retesting.
- Perform vulnerability analysis for internally identified issues, automated scan findings, third-party disclosures, and customer-reported vulnerabilities using industry-standard risk assessment methodologies.
- Participate in Agile sprint planning to identify, estimate, and track security-related activities and user stories.
- Collaborate closely with software developers, testers, and project teams to embed security throughout the software development lifecycle.
- Participate in customer discussions and technical reviews to communicate project security posture, compliance status, security risks, and remediation activities.
- Represent projects during internal quality audits and external cybersecurity assessments by providing compliance evidence and addressing audit observations.
- Conduct security awareness sessions and technical guidance for development teams on secure development practices and emerging security threats.
- Continuously stay updated with evolving cybersecurity threats, vulnerabilities, tools, technologies, and industry best practices.
📌 Senior Cybersecurity Engineer | 4-6 years Experience (Bengaluru)
🏢 Utthunga Technologies
📍 Bengaluru