* Examine the products in detail to discover vulnerabilities and collaborate
with the other security engineers to practically demonstrate the
exploitability and risk factors.
* Be on the forefront of emerging vulnerabilities/threats that could affect
Cashfree products through independent research and study.
* Engage with the developers in developing workarounds/mitigation plans and
ensure they are implemented per policy.
* Threat Modelling: Engage with the development teams to conduct secure design
reviews/threat modeling exercise to enumerate threats and mitigation
strategies.
* Enable the developers with knowledge of threat modeling by conducting focused
workshops.
* Secure Coding: Priorities critical defects and ensure these are identified
and mitigated during the sprint.
* Integration and automation of SAST in the DevOps pipeline.
* Build secure coding principles and propagate them across the development
community.
* Be the to-go person for developers in solving critical issues relating to
secure product development.
* Build and enhance secure coding / security assessments training contents for
developers and QA team.
* Deliver training programs at various levels in the organizations.
* Conduct workshops/security tech-talks to disseminate security knowledge and
awareness. Qualifications.
* Positive knowledge in multiple classes of vulnerabilities that includes
cross-site scripting, SQL Injection, CSRF, cryptographic related weakness,
and code injection.
* Good knowledge of any programming/scripting languages such as Java, Ruby, and
Python.
* Good knowledge relating to services/technology relating to the cloud.
* Ability to automate security testing and improve productivity in security
assessments.
* Ability to communicate and interpret security vulnerabilities to various
audiences such as development and management teams.
Requirements:
* You have great interpersonal skills, deep technical ability, and a history of
successful execution in the ass