Role Purpose:
To protect applications throughout the software development lifecycle by identifying security vulnerabilities, implementing secure development practices, and ensuring applications meet organizational security standards and compliance requirements.
Responsibilities:
Application Security Assessment
- Conduct application security assessments, vulnerability assessments, and penetration testing.
- Identify and analyze security vulnerabilities across web, mobile, and API applications.
- Assess applications against OWASP and industry security standards.
- Recommend and track remediation of identified vulnerabilities.
Secure Software Development
- Integrate security practices into the Software Development Lifecycle (SDLC).
- Conduct security reviews of application architecture, designs, and source code.
- Provide secure coding guidance to development teams.
- Support implementation of Security by Design principles.
Security Testing \& Automation
- Perform SAST, DAST, SCA, API security testing, and other application security testing.
- Configure and manage application security testing tools.
- Integrate security testing into CI/CD pipelines.
- Validate remediation and perform security regression testing.
Vulnerability Management
- Analyze, prioritize, and track application vulnerabilities based on risk.
- Coordinate with developers and technical teams for remediation.
- Conduct root cause analysis of security issues.
- Monitor emerging application security threats and vulnerabilities.
Security Architecture \& Compliance
- Review application architectures for security risks and control gaps.
- Define and recommend application security controls and standards.
- Support compliance with organizational security policies and applicable regulations.
- Maintain application security guidelines, standards, and documentation.
Collaboration \& Continuous Improvement
- Collaborate with developers, DevOps, infrastructure, QA, and cybersecurity teams.
- Conduct security awareness and secure coding sessions for development teams.
- Provide technical guidance on application security risks and remediation.
- Continuously evaluate and improve application security processes and tools.
Qualifications:
Necessary Knowledge and Experience to be able to do the Job
- 4–6 years of relevant experience in Application Security, Cybersecurity, or Information Security.
- Strong experience in application security testing and vulnerability assessment.
- Hands-on experience with web applications, mobile applications, APIs, and cloud environments.
- Strong understanding of OWASP Top 10 and secure coding practices.
- Experience with SAST, DAST, SCA, penetration testing, and vulnerability management.
- Experience integrating security into SDLC and CI/CD environments.
- Strong knowledge of application security threats, vulnerabilities, and remediation techniques.
Education and Certification Requirements
- Bachelor’s degree in Computer Science, Cybersecurity, Information Security, or a related field.
- Relevant certifications such as OSCP, CEH, GWAPT, CSSLP, or Security+ are an advantage.
Job Specific Technical Skills
- Application Security
- OWASP Top 10
- Web \& Mobile Application Security
- API Security
- SAST / DAST / SCA
- Vulnerability Assessment \& Penetration Testing
- Secure SDLC / DevSecOps
- Secure Coding Practices
- CI/CD Security Integration
- Threat Modeling \& Risk Assessment
- Source Code \& Security Review
- Security Testing Tools
- Python, Java, JavaScript, or similar programming languages
- Git and CI/CD tools
- Cloud Security fundamentals
Application Question(s):
- What is your salary expectation?
- What will be your notice period to join once selected?
- Do you have strong experience in application security testing and vulnerability assessment?
- Do you have experience with SAST, DAST, SCA, penetration testing, and vulnerability management?
- Do you have Experience integrating security into SDLC and CI/CD environments?
- Do you have strong knowledge of application security threats, vulnerabilities, and remediation techniques
Experience:
- Application Security, Cybersecurity, or Information Security: 4 years (Preferred)
Work Location: In person