17 Aug
|
BNP Paribas
|
Bengaluru
17 Aug
BNP Paribas
Bengaluru
Working experience: No Experience
Position Purpose: The purpose of this position is to lead a high‐performing, multidisciplinary security team and shape the future of secure software delivery across the organization. Drive tangible impact through measurable security outcomes, automation, and innovation.ResponsibilitiesDirect ResponsibilitiesReview and interpret various application classifications and their architectures (e.g., web apps, APIs, infrastructure, server side, mainframe, Web Sphere).Demonstrate solid knowledge of data in transit and data at rest encryption, TLS (certificates, cipher suites such as RSA and Diffie Hellman), middleware message queues, secure file transfers, and database encryption.Good Understanding of access control concepts, including onboarding, automated provisioning/reconciliation, and privileged access management tools (e.g., Sail Point, Cyber Ark).Good Understanding of authentication best practices and familiarity with strong authentication mechanisms such as SSO, SAML, 2 FA/MFA, Arcot, RSA, etc.Possess a clear grasp of application security testing processes (DAST, SAST, SCA, penetration testing, VAPT) and the end-to-end workflow, even if hands on scanning experience is not required.Good Understanding of payment specific applications (e.g., SWIFT messages), associated encryption of payment flows, mutual authentication, and end to end encryption.Work closely with application/asset owners and technical teams to conduct security compliance reviews, gather functional information, and implement appropriate security controls with documented evidence.Produce concise findings reports and discuss results with relevant Application owners & Stakeholders.Demonstrated team‐management ability,
preparation of management‐level reports, capability to interact with higher ups in management steering committee meetings and skilled in handling cross‐functional meetings to drive decisions and actions.Mentor and onboard current team members through knowledge transfer sessions and hands on shadowing during their initial period.Contributing ResponsibilitiesExtended knowledge of IT infrastructure & Network and Application (Web, Client-Server, Payment Systems) security reviewsProvide consultation and recommendations on application security controls for the central region.Technical & Behavioral CompetenciesStrong knowledge of application security framework and standards (OWASP TOP 10, NIST, SANS, ISO and relevant regulatory requirements)Strong understanding of OWASP top 10, SAST/DAST/SCA, API security, secure coding practices, threat modeling, vulnerability management, cryptography techniques, authentication techniques (SSO, SAML, MFA/2 FA, etc.), secure SDLCGood communication skillsKnowledge of application security controls (Access control mechanisms and Data Security)Should have IT audit backgroundGood knowledge of IT security (defense in depth)Specific Qualifications:Any technical certification (CEH/ISO27001/CISM/CISA/CISSP) will be a value additionSkills Referential (Required knowledge, skills and abilities)Technical Skills:App Sec assessments (Application security compliance review / API Security)Vulnerability management and Remediation techniquesGovernance framework and ReportingBehavioral Skills:Ability to collaborate / TeamworkAbility to deliver / Results drivenCommunication skills Oral & WrittenEducation Level: Bachelor degree or equivalentLocation: Bengaluru/Mumbai
📌 Application security manager (Bengaluru)
🏢 BNP Paribas
📍 Bengaluru