AppScan Product _Lead Security Expert _Remote Location

0 years

0 Lacs

Posted:4 days ago| Platform: Linkedin logo

Apply

Work Mode

Remote

Job Type

Full Time

Job Description

Greetings from “HCL Software” Is a Product Development Division of HCL Tech!!


"HCL Software”: - Is a Product Development Division of HCL Tech: That operates its primary Software Business. At HCL Software we Develop, Market, Sell and Support over 20 Product families in the areas of Customer Experience, Digital Solutions, Secure DevOps, Security & Automation.

About AppScan Product: -"HCL AppScan"

Work Preference: Hybrid Or Remote.


Job Summary

We are looking for a Lead Security Expert with 10+ Yrs experience in our AppScan Product team who possess the following skills:

Key responsibilities include: -

- Discovering new vulnerabilities in application source code.

- Developing automatic vulnerability detection procedures.

- Demonstrating familiarity with at least one programming language (e.g., Java, C/C++, .NET) and multiple operating systems/RDBMS.

- Providing security guidance for our products across new programming languages and frameworks.

- Innovating and improving the security logic of AppScan products.

- Collaborating with AppScan Research Lab teams.

- Analysing AppSec results and identifying false positives.

- Prioritizing high-priority issues based on severity and likelihood of exploit.

- Understanding remediation techniques for various languages and frameworks.

- Executing Source Code Analysis, Reverse Engineering, and Threat Modelling.


Desired skills and experience:

- Experience with Static Analysis (SAST) tools and triaging application security results.

- Proficiency in security remediation techniques and secure coding best practices.

- Expertise with security standards like OWASP Top 10 and CWE/SANS Top 25.

- Ability to articulate security threats to developers or auditors.

- Ability to identify and provide examples of false positives and negatives in source code.

- Experience with multiple operating systems and software attack/exploitation techniques.

- Familiarity with defensive programming concepts.


Advantageous skills:

- Experience with scripting or query languages (e.g., JavaScript, Python).

- Experience creating Data and Process Flow diagrams.

- Knowledge of Taint Analysis.

- Experience with Architectural Risk Analysis, Threat Modelling, and Traceability Matrix.

- Experience with reverse engineering and source-level analysis.

- An academic degree in Computer Science.

- Relevant certifications (e.g., OSWP, OSCP).


Other beneficial skills:

- Security analysis of popular APIs/frameworks.

- OO design skills, API/Framework analysis, Data Structure Algorithms/Graph Theory/Cryptography.

- Experience with Opensource/Software Composition tools, Threat Modelling, or network security.

- Membership in security-focused groups.

- Professional or academic experience with Machine Learning or AI.

- Knowledge of Networking, Telecommunications technologies, and protocols.

- Strong reporting, presentation, and communication skills.

- Experience working with distributed cross-functional teams and identifying/escalating risks.

- A bachelor’s degree in computer science or equivalent.

Mock Interview

Practice Video Interview with JobPe AI

Start DevOps Interview
cta

Start Your Job Search Today

Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.

Job Application AI Bot

Job Application AI Bot

Apply to 20+ Portals in one click

Download Now

Download the Mobile App

Instantly access job listings, apply easily, and track applications.

coding practice

Enhance Your Java Skills

Practice Java coding challenges to boost your skills

Start Practicing Java Now

RecommendedJobs for You