Lead Application Security (Mumbai)

Lead Application Security (Mumbai)

30 Aug
|
Avensys Consulting
|
Mumbai

30 Aug

Avensys Consulting

Mumbai

Avensys is a reputed global IT professional services company headquartered in Singapore. Our service spectrum includes enterprise solution consulting, business intelligence, business process automation and managed services. Given our decade of success, we have evolved to become one of the top trusted providers in Singapore and service a client base across banking and financial services, insurance, information technology, healthcare, retail and supply chain
Experience :
6–10+ years in Cyber Security with a minimum of 5 years in Application Security
Position Summary
Highly skilled Senior Application Security Engineer to lead Application Security and Secure Software Development initiatives. The ideal candidate possess deep expertise in application security assessments, secure architecture, and security testing technologies, while working closely with development, DevOps, cloud, and infrastructure teams.
This role requires extensive experience in Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Secure-Software Composition Analysis (SCA), secure code reviews, threat modelling, penetration testing, and Secure SDLC guidance.
Candidates holding OSWE and OSCP certifications will be highly preferred.
Key Responsibilities
Application Security
Lead the organization's Application Security program.
Develop and implement secure software development practices across engineering teams.
Conduct secure architecture and design reviews for new and existing applications.
Perform manual web application, API, mobile, and cloud application security assessments.
Conduct source code security reviews to identify vulnerabilities and insecure coding practices.
Perform threat modelling using industry-recognized methodologies
Review authentication, authorization, cryptographic implementations, and session management controls.
Validate remediation efforts and perform security regression testing.
SAST & DAST Program Management
Administer,



configure, and optimize and conduct enterprise SAST and DAST activities.
Integrate SAST and DAST into CI/CD pipelines to enable automated security testing.
Tune scanning engines to reduce false positives and improve detection accuracy.
Review scan results, perform risk analysis, and prioritize remediation activities.
Establish application security testing standards for all internally developed applications.
Work closely with development teams to remediate vulnerabilities and improve secure coding practices.
Application Security Testing
Perform and oversee:
Static Application Security Testing (SAST)
Dynamic Application Security Testing (DAST)
Software Composition Analysis (SCA)
API Security Testing
Manual Penetration Testing
Secure Configuration Reviews
Penetration Testing
Conduct manual penetration testing against:
Web Applications
REST APIs
Mobile Applications
Cloud-native Applications
Identify business logic vulnerabilities.
Exploit and validate security weaknesses where appropriate.
Prepare technical and executive-level assessment reports.
Present findings and remediation recommendations to engineering teams.
Vulnerability Management
Triage application vulnerabilities based on exploitability and business impact.
Work directly with development teams to remediate vulnerabilities.
Track remediation activities and report security metrics.
Validate fixes and perform retesting.
Drive continuous improvement of vulnerability management processes.
Required Qualifications
Bachelor's degree in Computer Science, Cyber Security,



Information Security, or a related discipline.
6–10+ years of cybersecurity experience.
Minimum 5 years of hands-on Application Security experience.
Extensive experience performing manual web application and API penetration testing.
Experience implementing enterprise SAST and DAST solutions.
Experience conducting secure architecture reviews and threat modelling.
Strong understanding of web targeted attack techniques and secure coding principles.
Excellent report writing and communication skills.
Preferred Certifications
Candidates holding one or more of the following certifications will be highly regarded:
Mandatory / Strongly Preferred
Offensive Security Web Expert (OSWE)
Offensive Security Certified Professional (OSCP)
Soft Skills
Strong analytical and problem-solving skills.
Excellent verbal and written communication.
Ability to communicate technical risks to both technical and executive audiences.
Strong stakeholder management skills.
Ability to influence engineering teams without direct authority.
Self-motivated with a strong sense of ownership.
Ability to mentor junior engineers
WHAT’S ON OFFER
You will be remunerated with an excellent base salary and entitled to attractive company advantages. Additionally, you will get the opportunity to enjoy a fun and collaborative work environment, alongside a strong career progression.
To submit your application, please apply online or email your UPDATED CV to [email protected] or WhatsApp at +65 6761 9819
Your interest will be treated with strict confidentiality.
CONSULTANT DETAILS:
Consultant Name : Sandeep Kumar
Avensys Consulting Pte Ltd
EA Licence 12C5759
Privacy Statement: Data collected will be used for recruitment purposes only. Personal data provided will be used strictly in accordance with the relevant data protection law and Avensys' privacy policy

📌 Lead Application Security (Mumbai)
🏢 Avensys Consulting
📍 Mumbai

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: lead application security (mumbai) / mumbai