Application Security Analyst - Vulnerability Management

47 years

0 Lacs

Posted:5 days ago| Platform: Linkedin logo

Apply

Work Mode

On-site

Job Type

Full Time

Job Description

Key Responsibilities

  • Support vulnerability assessments using SAST, DAST, and SCA tools.
  • Collaborate with DevOps, Vulnerability Management teams, IBM and third-party PenTest service providers to ensure security is integrated into CI/CD pipelines.
  • Manage the vulnerability management lifecycle, including triage, tracking, and remediation.
  • Provide remediation guidance and recommendations to developers on vulnerabilities.
  • Maintain and evolve secure SDLC practices and documentation.
  • Deliver security awareness and secure coding training sessions.
  • Demonstrate a willingness to learn, research, and innovate to improve the overall AppSec posture.
  • Administer threat modeling activities.

Technical Skills And Experience Required

  • Experience with the following tools:
  • DAST: Qualys, Rapid7
  • SAST: CodeQL, Checkmarx, Fortify, SonarQube
  • SCA: Dependabot, JFrog Xray
  • API Security: Understanding of API security principles and tools like Postman, OWASP API Security Top 10,
or API gateways with security features.
  • 47 years of hands-on experience in application security or secure software development.
  • Strong understanding of OWASP Top 10, CWE/SANS Top 25, and secure SDLC.
  • Understanding of vulnerability management lifecycle and remediation workflows.
  • Understanding of threat modeling concepts.
  • Familiarity with penetration testing tools (e.g., Burp Suite, Metasploit, Nmap).
  • Proficiency in at least one programming language (e.g., Java, Python, JavaScript, C#).
  • Familiarity with CI/CD tools (e.g., Jenkins, GitLab CI, Azure DevOps).
  • Exposure to cloud security (AWS, Azure, or GCP) is a plus.

Soft Skills Required

  • Strong analytical and problem-solving skills.
  • Excellent verbal and written communication.
  • Ability to work independently and collaboratively in cross-functional teams.
  • Strong documentation and reporting capabilities.
  • Proactive, detail-oriented, and eager to learn.

Good To Have Skills

  • Working knowledge of DevSecOps practices and tools.
  • Experience with container security (Docker, Kubernetes).
  • Certifications such as CEH or equivalent.
  • Familiarity with threat modeling tools (e.g., Microsoft Threat Modeling Tool, IriusRisk).
  • Experience in Agile/Scrum environments.
(ref:hirist.tech)

Mock Interview

Practice Video Interview with JobPe AI

Start DevOps Interview
cta

Start Your Job Search Today

Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.

Job Application AI Bot

Job Application AI Bot

Apply to 20+ Portals in one click

Download Now

Download the Mobile App

Instantly access job listings, apply easily, and track applications.

coding practice

Enhance Your Java Skills

Practice Java coding challenges to boost your skills

Start Practicing Java Now
Sampoorna Consultants logo
Sampoorna Consultants

Museums, Historical Sites, and Zoos

Mumbai

RecommendedJobs for You