16 Sep
|
systems plus
|
Pune
Location: Pune Employment Type: full-time
Job Details
- 8–12 years of overall experience in Cybersecurity and Application Security, with at least 4+ years of hands-on experience in application security, security assessments, and security architecture.
- Strong experience performing application security assessments and identifying security risks across web applications, APIs, mobile applications, and enterprise platforms.
- Deep expertise in threat modeling, with the ability to assess systems from an attacker's perspective and identify potential attack paths and security weaknesses.
- Strong experience conducting application and security architecture reviews and providing security recommendations during solution design and implementation.
- Robust knowledge of OWASP Top 10, OWASP ASVS, OWASP API Security Top 10, and secure software development principles.
- Experience with attack surface analysis, abuse cases, data-flow analysis, security design reviews, and threat modeling methodologies.
- Strong understanding of common application security vulnerabilities, including broken authentication, broken access control, injection, insecure APIs, session management issues, cryptographic weaknesses, and application misconfigurations.
- Good understanding of penetration testing and red-team methodologies, with a strong attacker mindset; however,
this is not a dedicated penetration testing role.
- Hands-on experience with SAST, DAST, SCA, API security tools, vulnerability scanning, secrets scanning, and other application security testing technologies.
- Strong knowledge of secure application architecture, including authentication, authorization, API security, encryption, secrets management, session management, and secure integration patterns.
- Experience implementing or supporting Secure SDLC and DevSecOps, including the integration of security controls into CI/CD pipelines.
- Strong understanding of modern application environments, including cloud platforms such as AWS and/or Azure, microservices, containers, Kubernetes, and APIs.
- Ability to work closely with development, infrastructure, enterprise architecture, and cybersecurity teams to prioritize and drive remediation of security risks.
- Ability to translate technical security findings into clear risk assessments, security requirements, architectural recommendations, and remediation roadmaps.
- Strong communication, documentation, and stakeholder management skills, with the ability to independently work as part of a long-term dedicated security team supporting US-based stakeholders.
📌 Sr. Application Security Architect (Pune)
🏢 systems plus
📍 Pune