Get alerts for new jobs matching your selected skills, preferred locations, and experience range.
5 - 6 years
6 - 8 Lacs
Pune
Work from Office
The Senior Manager of Information Security (External Role Description Application / Product Security Architect) will report to the Chief Information Security Officer. As a leader in the Information Security organization, this role will lead the task of refining, managing and executing strategic product/application security roadmap that is based on industry standard software security frameworks. You will plan, implement and track key initiatives focused on product / application security strategy, metrics, compliance, policy, developer awareness, training and stakeholder engagement. You will work closely with multiple teams that make up Information Security, Product Management, Engineering, Legal, Risk and Compliance to improve product / application security controls and drive impactful change to the team and its members. Responsibilities: Bring a deep background and broad experience in Information Security, Application Security, & Application Development or related business areas. Lead a team of high performing individuals who create remediation plans, perform security reviews, and recommend security solutions to meet current and future needs for HMH products and applications. Drive the development and implementation of product and application standard security review processes that result in effective methods for reducing security risks before product releases. Demonstrate an ability to influence all project and portfolio stakeholders; communicate relevant security information to both executive leaders and individual contributors in an effective manner. Accountable for all aspects of staff management, hiring, coaching, training, performance reviews and recommending pay actions and promotions for the Security Engineering team Provide input into the Information Security strategy to ensure that future security investments are aligned appropriately when considering key priorities such as business requirements, industry threat landscape, and risk appetite of HMH. Collaborate closely with the Architecture teams Demonstrated experience handling the demand/supply of project and program resources and tracking allocation. Track policy exceptions and remediation dates through active engagement with development teams and operations teams. Partner with Audit teams to periodically audit controls and secure coding practices being followed by development teams. Staying abreast of latest cyber security threats both internal and external Oversee projects, program delivery, daily monitoring, response; review of cloud infrastructure, physical infrastructure, and the full life cycle of alerts through incident response; and the threat landscape to ensure ongoing and continued maturity of the organization's security controls in addition to service support Drive operational efficiency and excellence leveraging tools, process and automation with appropriate and transparency visibility and metrics that can meet SLAs/SLOs Support and implement controls and visibility to meet third party attestations (SOC2, ISO27001, GDPR, SOX) Balance being collaborative, open, and approachable while still being firm on security policies and in facilitating progress and compromise What you should have: 5 to 6+ years hands-on experience in application security utilizing SAST, DAST, IAST, RASP and WAF. 5+ years of application engineering, architecture or development management experience Proficient analyzing ambiguous problems, compelling communicator with the ability to receive and analyze information, translating security risk to business risk to driving actionable decisions across multiple levels and departments Experience in leading application security remediation work, leading the mitigation initiative to accommodate the developer community priority. Proficient experience with common web application attack vectors and related mitigation strategies that translate to controls within the organization You are highly organized. With many people doing many things in a fast-moving company, strong organizational skillsboth for yourself and for the teamwill be required
Posted 1 month ago
4 - 9 years
14 - 16 Lacs
Gandhinagar
Work from Office
Job Summary A Security Analyst specializing in Vulnerability Assessment and Penetration Testing (VAPT) is responsible for evaluating and testing an organizations digital asset for vulnerabilities. This Role is responsible to manage organizations internal and external vulnerability management program from scan to resolution of identified vulnerabilities Roles and Responsibilities: Perform Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Interactive Application Security Testing (IAST) to identify vulnerabilities in software applications & IT Assets. Leverage threat modelling for applications to identify potential threats and suggest suitable mitigation strategies. Manage organization’s internal vulnerability management program execution, coordination, reporting and mitigation of vulnerabilities with various stakeholders. Work with external Vendor to plan, execute External VAPT on IT Assets, software applications, software code, mobile apps. Provide technical leadership in setting up SoW, complete External VAPT scan from start to closer of identified vulnerabilities. Work closely with cross function teams including IT and product development teams to close security findings, vulnerabilities. Develop and implement strategies to improve overall security posture. Knowledge And Skills Bachelor’s degree in computer science, Information Security, or a related field. Proven experience in vulnerability assessment and penetration testing. Good understanding of various Security standards like OWASP Top 10, OWASP Mobile Top 10, OWASP API Top 10, OWASP IoT Top 10, SANS Top 25, NIST. Good understanding of vulnerability severity calculation methods like CVSS Any of security certification related to VAPT, for example: Certified Security Analyst (ECSA); Licensed Penetration Tester (LPT); Offensive Security Certified Professional (OSCP); Offensive Security Certified Web Expert (OSWE); GIAC Penetration Tester (GPEN) Sound working experience with security scan products like Nessus, burp suits, Open VAS. Strong understanding of security principles, techniques, and technologies. Knowledge of application design and coding practices. Knowledge on any vulnerability management products like Qualys, Tenable, Rapid7 High level of initiative and self-direction Excellent communicator in English, both written and spoken while being able to convey information effectively at multiple levels of sensitivity and for various audiences
Posted 2 months ago
6 - 10 years
10 - 18 Lacs
Hyderabad
Work from Office
Role & responsibilities 1. Security Testing Conduct Static Application Security Testing (SAST) and Software Composition Analysis (SCA) Perform Dynamic Application Security Testing (DAST) and Interactive Application Security Testing (IAST) for deeper analysis of vulnerabilities during runtime Execute Mobile Application Security Testing and API Security Testing to safeguard against OWASP Security risks Ensure applications are resilient to real-world attack vectors 2. Vulnerability Management and Threat Mitigation Identify, prioritize, and remediate vulnerabilities through Vulnerability Assessments and Penetration Testing (VAPT) Identify and mitigate vulnerabilities aligned with the latest OWASP Top 10 risks, including Injection, Broken Access Control, and Insecure Design Assess and remediate vulnerabilities in accordance with OWASP Application Security Verification Standard (ASVS) Use Threat Modeling to predict, identify, and mitigate potential security threats early in the development lifecycle Provide detailed report analysis and assess the actual business and technical impact of security vulnerabilities Generate and analyze SAST reports, delivering actionable insights to technical and business stakeholders Implement and maintain robust vulnerability management processes 3. Cloud Security Secure cloud environments hosted on AWS and Azure, adhering to CIS Benchmarks and NIST Cybersecurity Framework standards Ensure data privacy and protection compliance with GDPR and HIPAA in cloud implementations Implement security controls and frameworks for cloud applications and infrastructure 4. Compliance and Regulations Ensure application and infrastructure compliance with standards such as PCI DSS, HIPAA, and GDPR Conduct regular assessments to align with SANS Top 25 Software Errors, NIST SP 800-53, and CIS Controls Support the creation of secure applications that meet industry compliance and regulatory requirements 5. DevSecOps Integration Embed security practices within the Secure Software Development Lifecycle (SDLC) by automating security checks and remediation Collaborate with DevOps teams to integrate security tools and testing into the CI/CD pipelines using Jenkins and Azure DevOps Automate security testing and monitoring to support agile development cycles 6. Security Architecture and Best Practices Design secure application architectures to address OWASP Top 10 risks and API-specific threats Advocate and enforce secure coding practices throughout the development teams Integrate OWASP ASVS principles and Threat Modeling to enhance application security Design and implement security architecture for web, mobile, and API applications 7. Leadership and Training Lead security assessments and mentor junior team members on secure application practices Conduct workshops and training sessions on OWASP Top 10, PCI DSS, Secure SDLC, and other key frameworks Act as a subject matter expert (SME ) in application security, fostering a culture of security awareness across the organization Required Skills and Qualifications 1. Technical Proficiency Legacy technologies: Java, .NET Modern technologies: React, Node.js, Python, PHP, Ruby/Rails, Angular, etc CMS experience with Magento-Adobe and Avocode 2. Cloud Skills Expertise with AWS and Azure cloud platforms 3. Security and Compliance Knowledge Strong understanding of OWASP Top 10, OWASP ASVS, PCI DSS, HIPAA, GDPR, CIS Benchmarks, and NIST Cybersecurity Frameworks Familiarity with SANS Top 25 Software Errors and their remediation strategies Knowledge of static compliance standards and security frameworks 4. Security Testing Expertise Proficiency in SAST, SCA, DAST, IAST, and penetration testing techniques Experience in Threat Modeling to proactively identify and mitigate risks Strong knowledge of VAPT, mobile, and API security testing 5. DevSecOps and SDLC Integration Expertise in implementing Secure Software Development Lifecycle (SDLC) practices Proficiency in integrating security tools with CI/CD pipelines using Jenkins and Azure DevOps 6. Soft Skills Excellent communication skills to bridge the gap between technical and business teams Strong leadership and collaboration skills Ability to articulate technical issues to both technical and non-technical audiences Preferred Certifications Certified Information Systems Security Professional (CISSP) Certified Ethical Hacker (CEH) GIAC Web Application Penetration Tester (GWAPT) AWS Certified Security -- Specialty Microsoft Certified: Azure Security Engineer Associate
Posted 3 months ago
Upload Resume
Drag or click to upload
Your data is secure with us, protected by advanced encryption.
Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.
We have sent an OTP to your contact. Please enter it below to verify.
Accenture
36723 Jobs | Dublin
Wipro
11788 Jobs | Bengaluru
EY
8277 Jobs | London
IBM
6362 Jobs | Armonk
Amazon
6322 Jobs | Seattle,WA
Oracle
5543 Jobs | Redwood City
Capgemini
5131 Jobs | Paris,France
Uplers
4724 Jobs | Ahmedabad
Infosys
4329 Jobs | Bangalore,Karnataka
Accenture in India
4290 Jobs | Dublin 2