24 Sep
|
Tata Consultancy Services
|
Mumbai
24 Sep
Tata Consultancy Services
Mumbai
Role: Application Security Analyst (OSCP Certification Mandatory)
Experience: 5-15 Years
Location: Mumbai
We are looking for an experienced Application Security Analyst with strong expertise in Application Security, Secure SDLC, DevSecOps, Vulnerability Assessment, Threat Modeling, and API Security. The ideal candidate should have hands-on experience in securing web applications, APIs, cloud-native applications, and CI/CD pipelines while working closely with Development and DevOps teams.
Mandatory Skills
- Application Security
- Secure SDLC
- DevSecOps
- Vulnerability Assessment & Penetration Testing (VAPT)
- SAST, DAST, SCA, IAST
- Threat Modeling
- API Security Testing
- OWASP Top 10
- OWASP API Security Top 10
- Burp Suite
- Checkmarx / Veracode / Fortify / SonarQube / Snyk
- Cloud Security (AWS/Azure/GCP)
- CI/CD Security
Key Responsibilities
- Integrate security controls throughout the Software Development Life Cycle (SDLC).
- Implement and manage Application Security tools within CI/CD pipelines.
- Perform code reviews and application vulnerability assessments.
- Conduct threat modeling and secure design reviews for applications and APIs.
- Identify and remediate security vulnerabilities aligned with OWASP Top 10, API Security Top 10, and SANS Top 25.
- Assess REST, GraphQL, and Microservices-based applications for security risks.
- Perform and support application penetration testing activities.
- Collaborate with developers to remediate vulnerabilities and improve security posture.
- Conduct security reviews for cloud-native applications and containerized environments.
- Develop secure coding standards, security guidelines, and developer awareness programs.
- Track vulnerability remediation and ensure closure within defined SLAs.
- Support compliance requirements such as ISO 27001, PCI DSS, GDPR, and SOC2.
Required Technical Skills
- Application Security Testing
- Secure Code Review
- Threat Modeling (STRIDE, Attack Trees)
- API Security Testing
- SAST / DAST / SCA / IAST
- Burp Suite, OWASP ZAP
- Checkmarx, Veracode, Fortify, SonarQube, Snyk
- OAuth 2.0, SAML, JWT
- Microservices Security
- Container & Kubernetes Security
- Cloud Security (AWS/Azure/GCP)
- Vulnerability Management
Desired Candidate Profile
- 5+ years of experience in Application Security or DevSecOps.
- Strong understanding of OWASP Top 10 and API Security Top 10.
- Experience securing APIs, Web Applications, and Cloud Platforms.
- Knowledge of common vulnerabilities such as SQL Injection, XSS, SSRF, IDOR, XXE, CSRF, and RCE.
- Ability to review source code in Java, Python, JavaScript, C#, or Go.
- Strong analytical, problem-solving, and communication skills.
Certifications
Mandatory:
- OSCP (Offensive Security Certified Qualified)Role & responsibilities
If anyone interested please share me your profile to this mail id:
[email protected]
📌 Application Security Analyst (Mumbai)
🏢 Tata Consultancy Services
📍 Mumbai