Role Description
Conduct application security testing in order to comply with corporate policies, and regulatory requirements. Coordinate and execute application security tests, communicate the results to relevant stakeholders, and help application developers understand how to fix code security issues.
Responsibilities
Conduct thorough application security penetration tests Work effectively with a cross-functional team to plan, execute, and communicate findings from application security testing Work with application owners to improve their knowledge and practical application of information security best practices, including but not limited to threat assessment, vulnerability prevention and secure coding practices.
Partner with DevOps team to ensure application security tools such as SAST and DAST are performing well and generating accurate testing results.
Flexibility to change direction and manage conflicting demands.
Experience
10 -12 years progressive Information Technology experience or equivalent specialized skills with 5+ years of application security experience.
Experience in running & administrating static analysis (SAST), agile analysis (DAST), and Software Composition Analysis (SCA) tools and processes
Experience in conducting and training application penetration testing
Experience in Cloud Security.
Experience and strong understanding of DevSecOps processes, tools, and integrations.
Qualifications
Strong knowledge and ability to work with DevOps teams on the processes and integrations.
Strong web application security knowledge with thorough understanding of web, mobile, and API testing Knowledge of application security architecture and ability to perform threat modeling and risk assessments on identified applications.
Knowledge of DevSecOps processes and ability to work with the stakeholders to deliver the results for security integrations in DevOps.
Development background in .Net, Java, and/or Python a plus Robust knowledge of Security
📌 Principle Engineer (Bengaluru)
🏢 UST
📍 Bengaluru