Lead Application Security (Mumbai)

Lead Application Security (Mumbai)

31 Aug
|
Avensys Consulting
|
Mumbai

31 Aug

Avensys Consulting

Mumbai

Avensys is a reputed global IT professional services company headquartered in Singapore. Our service spectrum includes enterprise solution consulting, business intelligence, business process automation and managed services. Given our decade of success, we have evolved to become one of the top trusted providers in Singapore and service a client base across banking and financial services, insurance, information technology, healthcare, retail and supply chain

Experience :

6–10+ years in Cyber Security with a minimum of 5 years in Application Security

Position Summary

Highly skilled Senior Application Security Engineer to lead Application Security and Secure Software Development initiatives. The ideal candidate possess deep expertise in application security assessments, secure architecture, and security testing technologies, while working closely with development, DevOps, cloud, and infrastructure teams.

This role requires extensive experience in Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Secure-Software Composition Analysis (SCA), secure code reviews, threat modelling, penetration testing, and Secure SDLC guidance.

Candidates holding OSWE and OSCP certifications will be highly preferred.

Key Responsibilities

Application Security

Lead the organization's Application Security program.

Develop and implement secure software development practices across engineering teams.

Conduct secure architecture and design reviews for new and existing applications.

Perform manual web application, API, mobile, and cloud application security assessments.

Conduct source code security reviews to identify vulnerabilities and insecure coding practices.

Perform threat modelling using industry-recognized methodologies

Review authentication, authorization, cryptographic implementations, and session management controls.

Validate remediation efforts and perform security regression testing.

SAST & DAST Program Management





Administer, configure, and optimize and conduct enterprise SAST and DAST activities.

Integrate SAST and DAST into CI/CD pipelines to enable automated security testing.

Tune scanning engines to reduce false positives and improve detection accuracy.

Review scan results, perform risk analysis, and prioritize remediation activities.

Establish application security testing standards for all internally developed applications.

Work closely with development teams to remediate vulnerabilities and improve secure coding practices.

Application Security Testing

Perform and oversee:

Static Application Security Testing (SAST)

Dynamic Application Security Testing (DAST)

Software Composition Analysis (SCA)

API Security Testing

Manual Penetration Testing

Secure Configuration Reviews

Penetration Testing

Conduct manual penetration testing against:

Web Applications

REST APIs

Mobile Applications

Cloud-native Applications

Identify business logic vulnerabilities.

Exploit and validate security weaknesses where appropriate.

Prepare technical and executive-level assessment reports.

Present findings and remediation recommendations to engineering teams.

Vulnerability Management

Triage application vulnerabilities based on exploitability and business impact.

Work directly with development teams to remediate vulnerabilities.

Track remediation activities and report security metrics.

Validate fixes and perform retesting.

Drive continuous improvement of vulnerability management processes.

Required Qualifications





Bachelor's degree in Computer Science, Cyber Security, Information Security, or a related discipline.

6–10+ years of cybersecurity experience.

Minimum 5 years of hands-on Application Security experience.

Extensive experience performing manual web application and API penetration testing.

Experience implementing enterprise SAST and DAST solutions.

Experience conducting secure architecture reviews and threat modelling.

Strong understanding of web targeted attack techniques and secure coding principles.

Excellent report writing and communication skills.

Preferred Certifications

Candidates holding one or more of the following certifications will be highly regarded:

Mandatory / Strongly Preferred

Offensive Security Web Expert (OSWE)

Offensive Security Certified Professional (OSCP)

Soft Skills

Robust analytical and problem-solving skills.

Excellent verbal and written communication.

Ability to communicate technical risks to both technical and executive audiences.

Strong stakeholder management skills.

Ability to influence engineering teams without direct authority.

Self-motivated with a strong sense of ownership.

Ability to mentor junior engineers

WHAT’S ON OFFER

You will be remunerated with an excellent base salary and entitled to attractive company benefits. Additionally, you will get the opportunity to enjoy a fun and collaborative work setting, alongside a strong career progression.

To submit your application, please apply online or email your UPDATED CV to or WhatsApp at +65 6761 9819

Your interest will be treated with strict confidentiality.

CONSULTANT DETAILS:

Consultant Name : Sandeep Kumar

Avensys Consulting Pte Ltd

EA Licence 12C5759

Privacy Statement: Data collected will be used for recruitment purposes only. Personal data provided will be used strictly in accordance with the relevant data protection law and Avensys' privacy policy

📌 Lead Application Security (Mumbai)
🏢 Avensys Consulting
📍 Mumbai

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: lead application security (mumbai) / mumbai

Subscribe to this job alert:

Get the latest job offers by email for: lead application security (mumbai) / mumbai