03 Sep
|
Larsen u0026 Toubro Infotech Ltd (LTI)
|
Bengaluru
03 Sep
Larsen u0026 Toubro Infotech Ltd (LTI)
Bengaluru
Specialist - Architecture Heres the with companyspecific references removed Key Responsibilities Issue Triage and Validation Review incoming security findings from whatever source they arrive application scanning vulnerability scanning cloud posture tools attack surface monitoring manual reports and work them against agreed turnaround targets Validate findings by examining the underlying code configuration or exposed asset and determine whether existing controls already mitigate the reported issue Assess whether a finding is actually exploitable in practice not just theoretically possible Confirm ownership of affected systems and assets so findings land with the team that can actually fix them Document the reasoning behind every disposition clearly enough that another analyst could follow it and reach the same conclusion Vulnerability Management and Attack Surface Track vulnerabilities across infrastructure cloud and application layers from discovery through remediation keeping an eye on SLA and aging Monitor the external attack surface for newly exposed assets services and misconfigurations and confirm whether exposure is intentional or needs to be addressed Support periodic risk reviews and help prioritize remediation based on severity exploitability and business impact rather than raw scanner output Work with asset and application owners to close visibility gaps including unscanned systems unknown assets and stale inventory Secure Code Review Perform manual review to confirm or rule out automated findings across the languages and frameworks in use Look for issues automated tools tend to miss including access control problems insecure deserialization weak cryptography and similar patterns Map confirmed issues back to standard classifications such as CWE and the OWASP Top 10 for consistent reporting Provide remediation guidance developers can actually use with codelevel detail where it helps Ticketing Routing and Remediation Tracking Create and enrich tickets with the detail an engineering team needs to act on affected system reproduction steps severity impact and remediation guidance Keep severity priority and other tracking fields accurate and consistent to support reliable reporting Follow tickets through their lifecycle chase down stalled items answer questions from engineering and confirm remediation before closing anything out Manage exceptions and suppressions with a documented reason approver and expiration date and revisit them before they expire Reporting Tuning and Automation Flag noisy rules and scan configurations that are driving unnecessary volume and work with the team to tune them Build small pieces of automation where they save real time things like bulk updates deduplication or ownership lookups Put together regular reporting on finding volume false positive rates time to triage time to remediate and backlog age Help bring recent systems applications and accounts into scanning and monitoring coverage and confirm theyre reporting correctly Collaboration and Documentation Keep triage runbooks and decision guides current so the process doesnt live in one persons head Send a regular written handoff covering queue status escalations and open items Join standups and working sessions with the broader security team Escalate anything serious right away instead of waiting for a scheduled checkin including confirmed critical findings live exposures or active credentials Handle vulnerability data source code and any customer or employee data encountered in the course of the work with strict confidentiality Additional Qualifications Required 3 years of handson experience in security analysis vulnerability management or application security Experience triaging findings from at least one security scanning or monitoring platform with the ability to explain how a finding was confirmed or dismissed Ability to read and reason about production code in at least two common languages such as Java JavaScriptTypeScript Python Go or C Working knowledge of the OWASP Top 10 CWE CVE and CVSS as applied to prioritization Practical understanding of core security concepts including authentication session management input validation network exposure and encryption fundamentals Comfortable using GitGitHub to pull code context and working a ticketing system such as Jira day to day Strong written English since most collaboration happens asynchronously Reliable highspeed internet a secure work environment and willingness to work on companyprovided or approved systems under the companys security and data handling policies Preferred Experience with a CNAPP ASPM or vulnerability management platform such as Wiz Qualys Tenable or Rapid7 Familiarity with application security tooling such as Checkmarx Semgrep Snyk or
📌 Application Security Specialist (Bengaluru)
🏢 Larsen u0026 Toubro Infotech Ltd (LTI)
📍 Bengaluru