Assistant Manager - Global Information Security

Tata Communications

Chennai District

On-site

INR 2,500,000 - 4,200,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Tata Communications is hiring for an Application Security professional to embed security across the SDLC, lead vulnerability management, and advance DevSecOps initiatives. You will perform SAST/DAST/ VAPT, secure code reviews, and threat modeling for web, mobile, API, microservices, and cloud-native apps.

Requirements include 5+ years in application security, strong OWASP knowledge, and hands-on security testing across enterprise environments.

Qualifications

  • Bachelor's/Master's degree in Computer Science, Cyber Security, IT, or related engineering discipline.
  • 5–10 years of cybersecurity experience, including minimum 5 years in Application Security.
  • Hands-on experience in SAST, SCA, DAST, VAPT, Secure Code Review, Threat Modeling, API Security, Secure SDLC, and CI/CD security integration.
  • Strong knowledge of OWASP Top 10, OWASP ASVS, SANS Top 25, DevSecOps, Cloud Security, and vulnerability management.
  • Experience in large enterprise, Agile, DevOps, and cloud-native environments, including management of security testing and remediation.
  • Working knowledge of Java, .NET, Python, JavaScript, Node.js, Go, YAML, Shell scripting, and Linux/Unix.

Responsibilities

  • Perform manual and automated SAST, SCA, DAST, VAPT/Penetration Testing, and Secure Code Reviews across web, mobile, API, microservices, cloud-native, and enterprise applications.
  • Identify, validate, prioritize, track, remediate, and retest vulnerabilities; provide secure coding and remediation guidance.
  • Integrate and maintain security tools and security gates within CI/CD pipelines and drive shift-left/DevSecOps practices.
  • Conduct/support Threat Modeling, Security Architecture Reviews, Application Risk Assessments, and secure design reviews.
  • Collaborate with Development, QA, DevOps, Architecture, Cloud, and Security teams to embed security throughout the SDLC.
  • Administer and optimize Application Security tools, onboard applications/repositories, improve scan coverage, and reduce false positives.
  • Develop and maintain Application Security policies, standards, procedures, baselines, and developer secure coding awareness/training.
  • Ensure compliance with organizational requirements and OWASP, NIST, ISO 27001, PCI DSS, and applicable secure development standards.
  • Track and report security posture, vulnerability aging/remediation, exceptions, trends, dashboards, and management metrics.
  • Drive KPIs including Critical/High vulnerability reduction, remediation closure, assessment coverage, CI/CD security-gate adoption, SLA compliance, and secure coding compliance.

Skills

SAST
SCA
DAST
VAPT
Secure Code Review
Threat Modeling
API Security
Secure SDLC
CI/CD security

Education

Bachelor's/Master's in Computer Science / Cyber Security / IT

Tools

Black Duck
Checkmarx
Snyk
Fortify
Burp Suite Professional
Veracode
SonarQube
OWASP ZAP
GitHub Advanced Security

Job description

About The Company

Tata Communications Redefines Connectivity with Innovation and IntelligenceDriving the next level of intelligence powered by Cloud, Mobility, Internet of Things, Collaboration, Security, Media services and Network services, we at Tata Communications are envisaging a New World of Communications

Broad Outline of the Role

Responsible for embedding application security across the SDLC, identifying and mitigating vulnerabilities, conducting security assessments, and driving DevSecOps initiatives. The role requires hands‑on expertise in SAST, SCA, DAST, VAPT/Penetration Testing, Secure Code Review, Threat Modeling, and Application Security governance across web, mobile, API, microservices, and cloud‑native applications.

Minimum Qualifications & Experience
  • Bachelor’s/Master’s degree in Computer Science, Cyber Security, Information Security, IT, or related engineering discipline.
  • 5–10 years of cybersecurity experience, including minimum 5 years in Application Security.
  • Hands‑on experience in SAST, SCA, DAST, VAPT, Secure Code Review, Threat Modeling, API Security, Secure SDLC, and CI/CD security integration.
  • Strong knowledge of OWASP Top 10, OWASP ASVS, SANS Top 25, DevSecOps, Cloud Security, and vulnerability management.
  • Experience in large enterprise, Agile, DevOps, and cloud‑native environments, including management of security testing and vulnerability remediation.
  • Working knowledge of Java, .NET, Python, JavaScript, Node.js, Go, YAML, Shell scripting, and Linux/Unix.
Other Knowledge & Skills
  • Hands‑on experience with Black Duck, Checkmarx, Snyk, Fortify, and Burp Suite Professional; exposure to Veracode, SonarQube, OWASP ZAP, GitHub Advanced Security, Prisma Cloud, Qualys, Tenable, and Acunetix is advantageous.
  • Knowledge of OWASP, NIST, ISO 27001, PCI DSS, secure development frameworks, security architecture, and emerging threats/vulnerabilities.
  • Strong analytical, problem‑solving, communication, documentation, stakeholder management, and cross‑functional collaboration skills.
  • Ability to assess security findings, identify false positives, prioritize risk, and provide practical remediation guidance.
  • Preferred certifications: CSSLP, GWAPT, GWEB, CASE, OSCP, eWPT, CEH, CISSP, CCSP, Security+, or equivalent.
  • Self‑driven, security‑first mindset with continuous learning and ability to drive security adoption.
Key Responsibilities
  • Perform manual and automated SAST, SCA, DAST, VAPT/Penetration Testing, and Secure Code Reviews across web, mobile, API, microservices, cloud-native, and enterprise applications.
  • Identify, validate, prioritize, track, remediate, and retest vulnerabilities; provide secure coding and remediation guidance.
  • Integrate and maintain security tools and security gates within CI/CD pipelines and drive shift-left/DevSecOps practices.
  • Conduct/support Threat Modeling, Security Architecture Reviews, Application Risk Assessments, and secure design reviews.
  • Collaborate with Development, QA, DevOps, Architecture, Cloud, and Security teams to embed security throughout the SDLC.
  • Administer and optimize Application Security tools, onboard applications/repositories, improve scan coverage, and reduce false positives.
  • Develop and maintain Application Security policies, standards, procedures, baselines, and developer secure coding awareness/training.
  • Ensure compliance with organizational requirements and OWASP, NIST, ISO 27001, PCI DSS, and applicable secure development standards.
  • Track and report security posture, vulnerability aging/remediation, exceptions, trends, dashboards, and management metrics.
  • Drive KPIs including Critical/High vulnerability reduction, remediation closure, assessment coverage, CI/CD security‑gate adoption, SLA compliance, and secure coding compliance.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
Application Security Engineer
Application Security Engineer

Omnissa • Bengaluru

On-site
INR 2,800,000 - 4,600,000
Application security
Application security

Codincity Digital Technologies • Chennai District

On-site
INR 3,500,000 - 5,500,000
Staff Engineer - Application Security
Staff Engineer - Application Security

UST • Bengaluru

On-site
INR 2,400,000 - 4,200,000
Cyber Security Consultant
Cyber Security Consultant

Infosys • Bengaluru

On-site
INR 1,800,000 - 2,400,000
Application Security Testing Consultant with SAST and DAST
Application Security Testing Consultant with SAST and DAST

Cloudxtreme • Hyderabad, Pune District, Bengaluru

On-site
INR 1,200,000 - 1,800,000
Application Security Engineer
Application Security Engineer

Ola • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Dynamic application security Engineer
Dynamic application security Engineer

Cloudxtreme • Hyderabad, Chennai District, Bengaluru

On-site
INR 1,200,000 - 2,400,000
Hybrid work model
Senior Application Security Manager
Senior Application Security Manager

Adani Enterprises Limited • Ahmedabad District

On-site
INR 1,800,000 - 3,000,000
Manager - AppSec/DevSecOps Security Engineer
Manager - AppSec/DevSecOps Security Engineer

Ex • Dadri

On-site
INR 2,500,000 - 5,000,000