Application Security Engineer II

Phenom People

Hyderabad

On-site

INR 1,500,000 - 2,100,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Phenom People is seeking a security-focused professional to identify and triage vulnerabilities in the Phenom ITX Platform, determine severity, and recommend corrective actions. You will collaborate with engineering to advance secure development practices and implement fixes with cross-functional teams.

In this role you will deploy DAST/SCA/DAST tools, maintain vulnerability management programs, and communicate findings to leadership.

Qualifications

  • Experience with AWS cloud environments and security controls.
  • Experience with microservices architectures in SaaS businesses.
  • Experience using Agile software development.
  • Coding in scripting and programming languages (Terraform, Java, Python, Ruby).
  • Knowledge of information security principles (CIA, PKI, cryptography) and understanding of exploitation techniques.
  • Experience implementing, managing, and supporting a vulnerability management program.
  • Experience with DAST/SAST and infrastructure automation using APIs.
  • Understanding of cybersecurity tools (SIEM, IPS, XDR) and their role in protecting an application.
  • Experience with threat modeling (STRIDE, PASTA, FAIR) and framework standards (OWASP, CVSS, CWE).
  • Strong written and report-writing skills; ability to communicate to leadership.

Responsibilities

  • Research, identify and analyze vulnerabilities affecting Phenom ITX Platform and determine severity and corrective actions.
  • Collaborate with engineering to evolve security assurance and shift-left practices.
  • Implement fixes to remediate vulnerabilities with engineering teams.
  • Deploy and utilize SAST/DAST/SCA to identify vulnerabilities for production teams.
  • Maintain and report progress on vulnerabilities to ensure closure per Phenom standards.
  • Provide guidance on remediation planning with business and production teams.
  • Prepare and deliver vulnerability assessment reports to diverse audiences.
  • Drive improvements via vulnerability management across audits and collaborations.
  • Stay updated on new threats and enhance Phenom’s threat model and security standards.
  • Support deployment of Phenom Secure Architecture & Software Development program.
  • Review processes to identify security improvement opportunities; automate where possible.
  • Deliver training on Security Development Lifecycle to engineering teams.
  • Help improve internal processes and automation opportunities.
  • Drive continuous improvement of cyber security metrics for application security.
  • Provide analytics on vulnerabilities and threat intelligence trends.

Skills

AWS cloud
Microservices architectures
Agile development
Scripting languages
Information security fundamentals
Vulnerability management
DAST/SAST
Cybersecurity tools
Threat modeling
OWASP/CVSS/CWE

Tools

Terraform
Java
Python
Ruby

Job description

Job Description
What Youll Do
  • Research, identify and analyze and triage vulnerabilities that could affect Phenom ITX Platform and its supporting infrastructure, and determine its severity, exploitability and corrective action recommendations, summarizing and reporting results.
  • Collaborate with engineering/development teams to evolve software assurance processes to address security risks, and help teams learn and adopt shift-security-to-left practices.
  • Work on implementing the required fixes to remediate the vulnerabilities in collaboration with the engineering team
  • Deploy, improve and utilize SAST/DAST/SCA and other cybersecurity solutionsto identify and communicate security vulnerabilities to Phenom production teams
  • Maintain and report progress on the state of application vulnerabilities and elevate as necessary to ensure vulnerability issues are closed and handled in a manner consistent with Phenom standards
  • Work closely with the business, support and production teams to provide input and guidance on development of planned remediation plans and strategies to solve identified vulnerabilities
  • Use technical writing and effective communications to prepare and deliver vulnerability assessment result reports to all levels of audiences (peers and or leadership).
  • Drive compliance support and improvements over time through the management, analysis and tracking of vulnerabilities discovered through audits, products or collaborations.
  • Perform research and analytics and stay apprised on new security vulnerability, threats, risks, attack tools and techniques to contribute and improve Phenom’s Threat model and collaborate with senior engineering and product management staff to incorporate effective security standards and controls into product design.
  • Help in the deployment of Phenom Secure Architecture & Software Development program to support the best cybersecurity development practice, and ensure Phenom ITX Platform is highly secure, resilient and aligned with business and product development strategy.
  • Continuously review and identify security improvement opportunities in existing processes, services, and workflows to ensure Phenom ITX platform is robust against current and future cybersecurity threats.
  • Support cybersecurity process activities including security requirements definition, threat modelling, code reviews and cyber risk assessment.
  • Support on development and maintenance of a “security by default” standard to be used in the development, infrastructure, or any other technology project.
  • Deliver training on Security Development Lifecycle to engineering/development teams
  • Contribute to the review of internal processes and activities and assist in identifying potential opportunities for improvement and automation.
  • Drive continuous improvement activities to define, measure, visualize and improve key cyber security metrics related to Application Security.
  • Provide analytic support to answer questions about vulnerabilities, and general threat intelligence trends
Work Experience
  • Experience with Amazon Web Services cloud environments and its security controls and their corresponding challenges.
  • Experience with microservices architectures & distributed Platforms especially in the SaaS businesses
  • Experience using Agile software development
  • Coding Experience in Scripting & programming languages (such as Terraform, Java, Python, Ruby, etc.)
  • Knowledge of information security principles (Confidentiality, Integrity, Availability Authentication & Public Key Infrastructure (PKI), Data Security or Cryptography), and understanding of common exploitation techniques and mitigation.
  • Experience implementing, managing, and supporting a vulnerability management program (process and technology).
  • Experience and well-known understanding of Dynamic and Static Application Security Testing (DAST & SAST) and infrastructure automation/development utilizing APIs.
  • Understanding of the main cybersecurity tools (SIEM, IPS, XDR, etc.) and how they help to protect an application.
  • Experience working with Threat modeling (e.g., STRIDE, PASTA, FAIR, Security Cards) and vulnerability frameworks standards (e.g., OWASP, CVSS, CWE) with a good understanding of the Cyber Kill Chain and pervasive threat attack methods and remediation.
  • Thought leadership, critical thinking, strong organizational skills, report writing skills to senior level, ability to prioritize and multitask
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer II
Application Security Engineer II

Phenom • Hyderabad

On-site
INR 1,800,000 - 3,000,000
Application Security Engineer III
Application Security Engineer III

Phenom • Hyderabad

On-site
INR 1,200,000 - 2,400,000
Health and wellness benefits
Flexible hours
Career development opportunities
+1
Cyber Security Engineer II
Cyber Security Engineer II

Phenom • Hyderabad

On-site
INR 2,500,000 - 4,000,000
Cyber Security Engineer
Cyber Security Engineer

Phenom People • Hyderabad

On-site
INR 2,400,000 - 3,800,000
Application Security Engineer
Application Security Engineer

DigiCert • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Generous time off policies
Top shelf benefits
Education, wellness, and lifestyle support
Application Security Engineer
Application Security Engineer

Basebiz • Chennai District

On-site
INR 1,200,000 - 1,800,000
Application Security Engineer
Application Security Engineer

Basebiz • Bengaluru

On-site
INR 1,800,000 - 2,800,000
Cloud Security Engineer II
Cloud Security Engineer II

Phenom • Hyderabad

On-site
INR 1,000,000 - 1,500,000
Health and wellness benefits
Flexible hours and working schedules
Career pathing and development opportunities
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2coms • Bengaluru

On-site
INR 2,500,000 - 4,000,000
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000