15 Sep
|
Sourcebae
|
Bengaluru
15 Sep
Sourcebae
Bengaluru
Consultant – Application Security
Experience: 5–7+ Years
Location: Bangalore
Job Type: Fulltime - Onsite/Hybrid
Budget: Max ₹25 LPA
Key Responsibilities
1. Security Defect Management
- Analyze, validate, communicate, and provide consultation on security defects identified through automated and manual sources, including CodeQL, Rapid7 Web Application Security, penetration testing, and bug bounty programs.
- Partner with software engineers to explain why vulnerabilities exist and recommend appropriate remediation approaches.
2. Engineering Consulting
- Provide security guidance to software engineers, architects, product owners, and technical leaders.
- Offer context-aware recommendations to support secure feature development and remediation of existing security issues.
3. Tool Enablement
- Enable and monitor automated security defect detection tools, including CodeQL and Rapid7, at the repository or application level.
- Ensure tooling is implemented and maintained according to established processes.
4. Security Test Onboarding & Management
- Collect and communicate required scope and access information for penetration testing and security assurance assessments.
- Manage assessment findings through the established Security Defect Management Process.
5. Maturity Measurement
- Consult with software engineers on practices that improve application security maturity.
- Support application security assessments using established scorecards and maturity models.
6. Correction of Error
- Author correction-of-error reports in partnership with software engineers.
- Help engineering and architecture teams avoid similar security mistakes across applications.
Basic Qualifications Candidates must meet at least two of the following three criteria :
- 5+ years of experience as a software engineer in any language or framework, or as a software engineering manager.
- 5+ years of experience as a software development-focused cybersecurity professional.
- 5+ years of experience working on a major cloud platform such as AWS, Azure, GCP, or Salesforce as a software engineer, cloud/DevOps engineer, security engineer, or architect.
Additional Qualifications
- Experience analyzing and remediating security findings from automated and manual sources, including:
- Static Application Security Testing (SAST)
- Agile Application Security Testing (DAST)
- Penetration Testing
- Software Composition Analysis (SCA)
- Experience using industry-standard security resources and frameworks, including one or more of:
- OWASP Top 10
- MITRE Common Weakness Enumeration (CWE) Top 25
- OWASP Application Security Verification Standard (ASVS)
- Other recognized security best-practice guides or frameworks
- Experience building or supporting web applications and APIs, including Single Page Applications (SPA) and RESTful APIs.
- Proficiency in one or more programming languages.
Key Attributes 1. Decision-Making Ability
- Make sound, justifiable, and customer-focused decisions when identifying security issues, escalating findings, and supporting prioritization decisions.
2. Strong Communication
- Explain complex technical concepts clearly to both technical and non-technical audiences.
- Collaborate effectively with globally distributed engineering teams across different locations and cultural backgrounds.
3. Active Participation
- Proactively contribute technical knowledge and experience.
- Take ownership of complex assignments and deliver high-quality results with limited supervision.
📌 Application Security (Bengaluru)
🏢 Sourcebae
📍 Bengaluru