Position Purpose: A security champion is a developer or security enthusiast inside the development team(s) that formally represents the local security team, thus bridging the dev-security gap. Their duties can include, but are not restricted to, educating the engineering team in secure development, adding and improving security checks in the developer workflow, questioning where engineering team decisions are not including security, giving the security team visibility into the practices and state of the development team they are in. He will be a member of a growing community of application security experts, take part in workshops and be on a specific training path designed to acquire the skillset necessary to be a security champion.
Responsibilities
Direct Responsibilities
Plan and Design
Contributes to Security Requirement Definition in Design Phase
Contributes to Secure Software Design / Security Architecture
Use of Threat Modeling to anticipate security issues during design phase
Development and Build
Responsible for the correct implementation of application security requirements
Participate in code reviews
Use of Application Security Testing solutions (SCA, SAST) to scan the code for security defects
Assists developers in fixing Security Defect
Links between central IT Security Team and Development Team
Vulnerability Management & Reporting
Manage the lifecycle of the issues raised by the Application Security Testing solutions (triage, prioritization, risk cards)
Responsible for continuous Monitoring of Library and Framework Security in terms of Security Requirements
Responsible for reporting the development team’s application security KPIs to the management.
Contributing Responsibilities
Promote application security best practices in the development team.
Perform Security Watch for newly detected and published application security vulnerabilities.
Co
📌 DevSecOps Engineer (Chennai)
🏢 BNP Paribas
📍 Chennai
Reply to this offer
Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.