08 Oct
|
incubxperts technoconsulting
|
India
08 Oct
incubxperts technoconsulting
India
Job Description
Role Overview
The Head of Application Security & Dev SecOps is responsible for integrating security into the organization's software development and technology delivery processes. This role partners directly with Engineering to build security into the development lifecycle rather than relying primarily on post-development security reviews.
Key Responsibilities
- Own application and API security practices.
- Establish and mature the Secure SDLC.
- Conduct and facilitate threat modeling.
- Implement and manage SAST, DAST, SCA and secrets scanning capabilities.
- Integrate security controls into CI/CD pipelines.
- Manage application vulnerabilities and remediation.
- Address open-source, dependency and software supply-chain risk.
- Establish secure coding standards and developer security practices.
- Define security requirements for production access and deployments.
- Partner directly with U.S. and offshore Engineering teams.
- Improve developer security awareness and adoption.
- Automate application security testing and remediation workflows.
- Establish meaningful application security metrics and reporting.
Requirements
Candidate Requirements
- 7+ years of application security, Dev SecOps, software engineering or cybersecurity experience.
- Strong understanding of modern application, API and cloud architectures.
- Hands-on experience with CI/CD and application security tooling.
- Experience working directly with software engineering teams.
- Strong understanding of software supply-chain and dependency risk.
- Ability to translate security requirements into practical engineering solutions.
- Financial services,
fintech or regulated-industry experience preferred.
- Remote- US Shift
Requirements
Key Responsibilities: Collaborate with stakeholders to translate business requirements into clean, productive, and well-documented code using programming languages such as Java, C#. Net, or Java Script. Develop and integrate third-party services and APIs, while creating APIs for internal/external use. Gain comprehensive product knowledge by learning and understanding the existing platform. Understand client implementation requirements and develop automation, scripting, or code as needed. Test, debug, and optimize code to ensure performance, reliability, and functionality. Troubleshoot issues, ensuring seamless onboarding of new clients to our platform. Communicate technical concepts to non-technical stakeholders in a clear and concise manner. Requirements Strong technical skills and understanding. Proven experience in one of the programming languages (Java, C#. Net, Java Script, or others). Strong knowledge of XML and SQL, with the ability to handle database queries and data exchange formats. Strong problem-solving and analytical skills, with attention to detail. Ability to gain deep product knowledge and apply it to client implementations. Ability to work independently or collaboratively in a team environment. Experience with software testing, debugging, and performance optimisation. Excellent communication and client-facing skills, with a customer-focused mindset. Preferred: Familiarity with the payments or banking domain is good to have. Experience in client implementation, configuration, and setup Willingness to work in the second shift: 2:00 PM – 11:00 PM IST.
📌 Head of Application Security & DevSecOps (India)
🏢 incubxperts technoconsulting
📍 India