Home
Jobs

IN_Senior Associate_Source Code Review_MS Engineering

5 - 7 years

9 - 13 Lacs

Posted:5 hours ago| Platform: Naukri logo

Apply

Work Mode

Work from Office

Job Type

Full Time

Job Description

Not Applicable Specialism Microsoft Management Level Senior Associate & Summary At PwC, our people in cybersecurity focus on protecting organisations from cyber threats through advanced technologies and strategies. They work to identify vulnerabilities, develop secure systems, and provide proactive solutions to safeguard sensitive data. As a cybersecurity generalist at PwC, you will focus on providing comprehensive security solutions and experience across various domains, maintaining the protection of client systems and data. You will apply a broad understanding of cybersecurity principles and practices to address diverse security challenges effectively. & Summary We are looking for experienced members with strong analytical and problemsolving abilities willingness and to learn new technologies and adapt to changing project requirements ability to prioritize tasks and manage time effectively to meet deadlines good verbal and written communication skills ability to work collaboratively in a team setting Responsibilities 1. Review application source code based on the industry standard security frameworks and organizations internal security policy. 2. Running the source code scan and analyzing the results derived from the SAST platform. 3. Coordinate with application development teams to ensure identified gaps are fixed in proper time. 4. Work with the application development team to eliminate false positives, to clarify compensating security controls. 5. Closely work with issue management team to ensure proper remediation plans are in places with well documented records. 6. Collaborate with senior developers and architects to ensure security best practices and secured design patterns are followed. 7. Work closely with other team members, including project leads, regional leads and territory security leadership team. 8. Provide regular updates on progress and issues to project managers and stakeholders Mandatory skill sets 1. Strong knowledge of secure coding practices and common security vulnerabilities (e.g., OWASP Top 10). 2. Strong knowledge of Industry standard SAST tools (e.g. Veracode, Fortify on Demand). 3. Strong knowledge of Industry standard SCA tools (e.g. Blackduck). 4. Strong knowledge in manual and toolbased code review process, focusing on OWASP methodology. 5. Strong Knowledge of security vulnerability identification and remediation methodologies. 6. Familiarity with industry standard security frameworks and policies. 7. Strong knowledge of DevSecOps practices and integration of security within CI/CD pipelines. Preferred skill sets Desirable Skills 1. CEH, CISM, CCSK Years of experience required 57 yrs Education qualification BTech/BE/MTech from reputed institution/university as per the hiring norms Education Degrees/Field of Study required Bachelor of Technology, Master of Engineering Degrees/Field of Study preferred Required Skills Static Application Security Testing (SAST) Accepting Feedback, Accepting Feedback, Active Listening, Agile Methodology, Analytical Thinking, Azure Data Factory, Communication, Creativity, Cybersecurity, Cybersecurity Framework, Cybersecurity Policy, Cybersecurity Requirements, Cybersecurity Strategy, Embracing Change, Emotional Regulation, Empathy, Encryption Technologies, Inclusion, Intellectual Curiosity, Learning Agility, Managed Services, Optimism, Privacy Compliance, Regulatory Response, Security Architecture {+ 8 more} Travel Requirements Government Clearance Required?

Mock Interview

Practice Video Interview with JobPe AI

Start Cism Interview Now
PwC Service Delivery Center
PwC Service Delivery Center

IT Services and IT Consulting

New York NY

10001 Employees

703 Jobs

    Key People

  • Tim Ryan

    U.S. Chairman and Senior Partner
  • Dawn P. O’Reilly

    Chief Operating Officer

RecommendedJobs for You

Hyderabad, Pune, Bengaluru