Company Name: VARITE India Private Limited
About The Client
A global IT services and consulting company, multinational information technology (IT), headquartered in Tokyo, Japan. The Client offers a wide array of IT services, including application development, infrastructure management, and business process outsourcing. Their consulting services span business and technology, while their digital solutions focus on transformation and user experience design.
It excels in data and intelligence services, emphasizing analytics, AI, and machine learning. Additionally, their cybersecurity, cloud, and application services round out a comprehensive portfolio designed to meet the diverse needs of businesses worldwide.
Essential Job Functions:
- Highly qualified Senior Application Security & Vulnerability Management Engineer with experience in Qualys-based server and workstation vulnerability scanning, enterprise vulnerability management.
- Should be one who can operate as a technical owner for application security, Qualys vulnerability scanning, enterprise vulnerability management, GCP cloud vulnerability remediation, and DevSecOps security enablement.
- GCP cloud vulnerability analysis, penetration testing, automation, and DevSecOps pipeline integration.
- Improving the security posture of enterprise applications, APIs, GCP cloud services, servers, workstations, and supporting infrastructure across Enterprise Financial Systems (EFS) and Enterprise Technologies (ENT).
- The candidate must be able to independently manage the full vulnerability lifecycle, including discovery, scan analysis, validation, prioritization, dispatch, remediation coordination, verification, and executive-level reporting.
- This position requires a strong blend of application security expertise, Qualys vulnerability management experience, cloud security knowledge, scripting and automation capability, technical troubleshooting, and cross-functional communication.
- Conducting dynamic and static application security testing (DAST/SAST), penetration testing,
and security governance across the technology landscape.
Qualifications:
- Exp - 8 - 12 Years
Security Testing & Tools
- Proven expertise in DAST and SAST web application and API security testing is essential.
- Demonstrated experience with Netsparker/Invicti for dynamic application security testing of web apps, APIs, and web services is required.
- Strong proficiency with Qualys for server and workstation vulnerability scanning, patch validation, DoS vulnerability detection, SSL configuration assessment, and server-level remediation tracking is necessary.
- Experience with cloud security tools including Wiz for service account vulnerabilities and exposed secrets, and Google Cloud Security Command Center (SCC) for misconfiguration detection and IAM role assessment is critical.
- Hands-on experience with Burp Suite Pro for manual penetration testing and validation.
- SonarQube (SAST) for source code analysis based on OWASP Top 10, JFrog Xray (SCA) for third-party library and dependency scanning, and ZAP (DAST) for pipeline integration is highly valued.
Vulnerability Management
- Deep understanding of CVEs, OWASP Top 10, SANS 25, and WASC security standards is mandatory.
- Robust knowledge of common web application attack vectors including SQL injection, Cross-Site Scripting (XSS), CSRF, session management issues, clickjacking, and buffer overflows is required.
- Strong PowerShell skills for automating vulnerability data collection, sanitization, and dispatch sheet management are required.
- CI/CD and Power BI Dashboards.
- Working knowledge of Linux, Unix, Windows, and server environments is required for Qualys vulnerability context.
- Strong familiarity with Google Cloud Platform (GCP) security and cloud vulnerability management.
- Ability to assess misconfigurations, weak IAM roles, exposed secrets, insecure service accounts, vulnerable workloads, storage exposure, network exposure, and cloud-native risks identified through Wiz and Google Cloud Security Command Center (SCC).
- Familiarity with CI/CD pipelines and DevSecOps.
- Strong skills in coordinating with InfoSec, PCDM, and cross-functional teams throughout the vulnerability lifecycle are required.
How to Apply: Interested candidates are encouraged to respond/submit their updated resumes, and for additional job opportunities, please visit Jobs In India – VARITE.
Unlock Rewards: Refer Candidates and Earn.
If you're not available or interested in this opportunity, please pass this along to anyone in your network who might be a good fit and interested in our open positions. VARITE offers a Candidate Referral program, where you'll receive a one-time referral bonus based on the following scale if the referred candidate completes a three-month assignment with VARITE.
Experience Level Bonus Referral: 0-2 years INR 5,000 2-6 years INR 7,500 6+ years INR 10,000
About VARITE: VARITE is a global staffing and IT consulting company providing technical consulting and team augmentation services to Fortune 500 Companies in USA, UK, CANADA and INDIA. VARITE is currently a primary and direct vendor to the leading corporations in the verticals of Networking, Cloud Infrastructure, Hardware and Software, Digital Marketing and Media Solutions, Clinical Diagnostics, Utilities, Gaming and Entertainment, and Financial Services.
Equal Opportunity Employer:
VARITE is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, marital status, veteran status, or disability status.
📌 Senior Developer: Vulnerability Management, Tracking and Remediation (India)
🏢 VARITE
📍 India