06 Sep
|
SuperOps
|
Chennai
Job Description As a Senior Application & Cloud Security Engineer (IC3), you will take end-to-end technical ownership of our application security posture across Web, Mobile (iOS/Android), and Cloud (AWS) environments. You will be responsible for threat modeling, conducting deep-dive vulnerability assessments (VAPT), embedding automated security gates into CI/CD pipelines, engineering advanced AWS WAF custom rules & perimeter defenses, and leveraging Observability/SIEM platforms for proactive threat detection and incident monitoring. Key Responsibilities & Core Scope Web & Mobile Application Security (AppSec) Web Application Security: Conduct comprehensive manual and automated vulnerability assessments (VAPT) across web platforms and microservice APIs based on OWASP Top 10 and OWASP API Security Top 10. Mobile Application Security (iOS & Android): Perform static and dynamic security assessments aligned with OWASP Mobile Application Security (MASVS)
— auditing secure data storage, certificate pinning, biometric authentication, deep linking, reverse-engineering resistance, and third-party SDK security. Secure SDLC & DevSecOps Automation: Integrate, tune, and scale SAST, DAST, and SCA tools (e.g., Semgrep, Checkmarx, Veracode, Snyk, SonarQube, OWASP ZAP, Burp Suite) inside GitHub Actions / GitLab CI pipelines with minimal developer friction. Threat Modeling: Lead team-oriented threat modeling sessions (STRIDE / MITRE ATT&CK;) with developers and architects during sprint planning and architectural design phases. Vulnerability Remediation: Work directly with product engineering teams to provide code-level remediation guidance, root-cause analysis, and verification testing. AWS Security Hardening: Architect and maintain hardened AWS multi-
📌 Lead Cyber Security (Chennai)
🏢 SuperOps
📍 Chennai