09 Aug
|
Creospan Private
|
India
09 Aug
Creospan Private
India
We are looking for an Application security to support enterprise secrets management and application security governance initiatives. The ideal candidate will have experience in secrets scanning, SAST governance, remediation tracking, and stakeholder coordination across development, platform, risk, and compliance teams.
Exp Level- 5-8 yrs
Job Location- Pune_ Kharadi
Key Responsibilities
- Govern and track secrets scanning findings across repositories and ensure remediation within defined SLAs.
- Coordinate with development, platform, risk, and compliance teams on remediation, exceptions, deferrals, and risk acceptance.
- Review secrets scanning outputs, validate remediation evidence, and identify false positives.
- Monitor remediation progress, drive escalations for overdue findings, and provide governance support.
- Maintain governance documentation, audit-ready artefacts, dashboards, metrics, and executive reports.
- Act as the primary point of contact for developer and stakeholder queries related to security findings and governance.
- Analyze security tool findings and support continuous improvement of governance processes.
- Fine-tune secrets scanning rule sets to reduce false positives and improve detection accuracy.
Required Skills
- Strong understanding of secrets exposure risks (API keys, tokens, passwords, certificates).
- Experience reviewing secrets scanning results and validating remediation actions.
- Working knowledge of SAST concepts and application security governance.
- Familiarity with GitHub and CI/CD environments.
- Strong documentation, reporting, stakeholder management, and communication skills.
- Experience with Checkmarx or similar application security tools.
- Familiarity with ServiceNow or other enterprise tracking tools.
- Exposure to Security Governance, Risk, and Compliance processes.
- Experience preparing audit evidence, dashboards, and governance reports.
Valuable to Have
- Knowledge of DevSecOps practices.
- Experience working in enterprise or regulated environments.
- Understanding of secure software development lifecycle (SSDLC) and vulnerability management.
If interested, please share your updated resume.
📌 Senior Application Security Specialist (India)
🏢 Creospan Private
📍 India