06 Aug
|
Adani Group
|
Ahmedabad
06 Aug
Adani Group
Ahmedabad
Purpose/Objective
The Application Security Executive is responsible for supporting the application security program, focusing on ensuring that applications are secure from development to deployment.
This role involves collaborating with development teams to enforce secure coding practices, conducting vulnerability assessments, and assisting with the implementation of security solutions throughout the software development lifecycle (SDLC).
The Application Security Executive will help to identify and mitigate security risks, ensuring that applications meet the organization’s security standards and compliance requirements.
Key Responsibilities of Role
Application Security Executive Application Security Support: Assist in the implementation of the application security program across the organization, ensuring secure development practices are followed.
Work closely with the development teams to ensure that applications are designed, coded, and tested with security in mind.
Help with the integration of security practices into the software development lifecycle (SDLC), including code reviews, threat modeling, and security testing.
Vulnerability Management: Conduct regular vulnerability assessments, including static and energetic application security testing (SAST/DAST), to identify security flaws within applications.
Assist in managing and mitigating vulnerabilities found during testing by working with development teams to prioritize and address issues.
Help maintain a vulnerability management system to track vulnerabilities from discovery to remediation.
Security Code Reviews: Perform or assist with security code reviews to identify and remediate security flaws in source code and third-party libraries.
Enforce secure coding guidelines and work with developers to correct coding errors related to security vulnerabilities.
Support the identification of common vulnerabilities such as SQL injection, cross-site scripting (XSS), and insecure direct object references (IDOR).
Security Testing and Tools: Assist in the execution and management of security testing tools, such as SAST, DAST, and IAST,
to scan applications for vulnerabilities.
Help develop and maintain automated security testing within the continuous integration/continuous deployment (CI/CD) pipeline.
Work with security tools and platforms to monitor the security status of applications and provide insights into areas of improvement.
Threat Modeling and Risk Analysis: Support the process of threat modeling to identify potential threats, vulnerabilities, and risks associated with new applications or features.
Assist in performing risk assessments to evaluate the likelihood and impact of identified threats and vulnerabilities, recommending mitigation strategies.
Collaboration and Training: Collaborate with cross-functional teams, including IT, product development, and DevOps, to ensure security is integrated into all stages of the SDLC.
Provide security awareness training for developers and other stakeholders, educating them on secure coding practices and security threats.
Foster a security-first mindset across development teams and assist in promoting a culture of secure software development.
Incident Response Support: Assist in investigating application-related security incidents, gathering information and supporting the identification of root causes.
Work with incident response teams to implement remedial actions and prevent the recurrence of similar security issues in applications.
Compliance and Standards: Ensure that applications adhere to security standards and industry best practices, including OWASP Top 10, PCI-DSS, and other relevant security frameworks.
Assist in the compliance of application security with regulatory requirements, such as GDPR, HIPAA, or other applicable laws.
Reporting and Metrics:
Provide regular reports on the status of application security efforts, including vulnerability assessments, remediation efforts, and overall risk posture.
Track metrics related to application security testing, remediation progress, and effectiveness of security controls.
Continuous Learning and Improvement: Stay up-to-date with the latest trends, threats, and vulnerabilities in application security and the wider cybersecurity landscape.
Continuously evaluate and improve the application security processes and tools, ensuring the team is using the most effective techniques and solutions available.
Key Stakeholders - Internal Business Unit Heads and Department Heads Application Security Lead / Head of Cybersecurity Information Security and IT teams Risk Management Teams Engineering & Development Teams Product Management and Operations Teams Key Stakeholders - External Regulatory Authorities Third-Party Service Providers
Technical Competencies
Application Security Management-CYS,Cybersecurity Governance & Compliance-CYS,IT Support & Infrastructure Security-CYS,Identity & Access Management-CYS,Network Security & Perimeter Defense-CYS,Research and Innovation-CYS
Qualifications and Experience
Educational Qualification: Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
Advanced degree (e.
g.
, Master's, MBA) in Cybersecurity, Information Assurance, or a relevant discipline is highly desirable.
Certification: Certifications: Industry certifications such as OSCP / CEH / CHFI or similar are preferred.
Experience with application security tools, such as CheckMarx, Fortify, Burpsuite, Acunetix, Appscan, Tenable, and static code analysis tools.
and experience on Industry application secuiry asesssment frameowrk e.
g.
, (OWASP, NIST, PCI DSS) and DevSecOps platforms e.
g.
, GitLab, Github etc.
Work Experience (Range of years): 2+ years of relevent experience in application security and secure software development lifecycle including hybrid platform
📌 Deputy Manager - Cyber Security (Ahmedabad)
🏢 Adani Group
📍 Ahmedabad