24 Sep
|
Mach 1 Global Supply Chain Services
|
Mysuru
24 Sep
Mach 1 Global Supply Chain Services
Mysuru
Application Security Analyst (Java)
Position Summary
We are seeking an experienced Application Security Analyst with a strong focus on Java application security to help guide our developers to maintain secure software across the enterprise. As a member of the security team, this role partners closely with software development, DevOps, and cloud teams to integrate security into the software development lifecycle (SDLC), identify and remediate vulnerabilities, and promote secure coding practices.
Key Responsibilities
- Perform secure code reviews of Java applications and services.
- Provide guidance to identify, assess, and remediate application security vulnerabilities using SAST, DAST, SCA, and penetration testing results.
- Integrate security controls and automated security testing into CI/CD pipelines.
- Provide guidance to development teams on secure coding practices, OWASP Top 10, API security, authentication, authorization, and cryptography.
- Conduct threat modeling and security architecture reviews for recent applications and major system changes.
- Support vulnerability remediation efforts and validate fixes.
- Develop and deliver secure coding training and awareness programs for Java developers.
- Assist with security incident investigations involving application-layer vulnerabilities.
- Collaborate with DevOps and cloud engineering teams to secure containerized and cloud-native applications.
Required Qualifications
- 5+ years of experience in Application Security, or Secure Software Development.
- Strong proficiency in Java, Spring Boot, REST APIs, and modern application architectures.
- Experience with OWASP Top 10, CWE, secure coding standards, and threat modeling.
- Hands-on experience with security tools such as SemGrep, Trivvy, SonarQube, Snyk, or similar solutions.
- Knowledge of secure authentication technologies including OAuth 2.0, OpenID Connect, SAML, and MFA.
- Familiarity with CI/CD pipelines, JIT.io, Azure DevOps, Git, Jenkins, GitHub Actions, or similar platforms.
- Understanding of cloud security principles and container security (Docker/Kubernetes) preferred.
Others Mode & Location: Work from Office / Mysore
Shift: US Shifts
Notice Period: Immediate / 30 Days / Serving Notice Period
Compensation: As per Industry Standard
📌 Application Security Analyst (Java) (Mysuru)
🏢 Mach 1 Global Supply Chain Services
📍 Mysuru