Associate Security Consultant

Tech Mahindra

Mumbai

On-site

INR 2,500,000 - 4,000,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Tech Mahindra is seeking an Application Security Lead with 6–9 years of experience in securing web and mobile applications. The role emphasizes building and maintaining a robust GRC framework, conducting secure development practices, and coordinating with stakeholders to pass audits.

You will oversee vulnerability assessments, code reviews, and regulatory compliance efforts across BFSI and other sectors, including OWASP Top 10 and secure SDLC integration.

Qualifications

  • Bachelor's degree or higher is the minimum entry requirement.
  • Educational qualifications BE/BTech/MCA with 6–9 years of experience preferred.
  • Certifications such as CISSP, CISA, CISM, or ISO 27001 Lead Auditor preferred.

Responsibilities

  • Regulatory compliance in BFSI and related sectors is preferable.
  • Develop and manage the GRC framework to ensure regulatory compliance.
  • Ensure adherence to standards like ISO 27001, PCI DSS, SOC 2, and NIST.
  • Establish and enforce security policies for data protection and secure development.
  • Collaborate with development teams to integrate security into the SDLC.
  • Conduct application security assessments, code reviews, and vulnerability scans.
  • Manage audits for application security controls and vulnerability management.
  • Deliver training on secure coding practices and compliance awareness.
  • Document and report compliance activities, risk findings, and audit results.
  • Lead CSR (Comprehensive Security Review) initiatives.

Skills

application security

Education

BE/BTech/MCA

Tools

HP Fortify
Burp Suite

Job description

A Bachelor’s or Higher Degree is the minimum entry required for the position

Job Description
  • Skill Set : application security & testing

Application Security Lead

Qualifications

Educational Qualification: BE/BTech/MCA

Experience: 6 to 9 years

Certifications such as CISSP, CISA, CISM, or ISO 27001 Lead Auditor preferred.

Key Responsibilities
  • Prior experience in regulatory compliance in BFSI is preferable.
  • Develop and manage the GRC framework to ensure regulatory compliance.
  • Ensure adherence to standards like ISO 27001, PCI DSS, SOC 2, and NIST.
  • Establish and enforce security policies for data protection and secure development.
  • Collaborate with development teams to integrate security into the SDLC.
  • Conduct application security assessments, code reviews, and vulnerability scans.
  • Manage audits for application security controls and vulnerability management.
  • Conduct risk assessments, maintain a risk register, and track remediation efforts.
  • Deliver training on secure coding practices and compliance awareness.
  • Document and report compliance activities, risk findings, and audit results.
  • Strong knowledge of automated scanning using HP Fortify, Burp suite or similar tools.
  • Suggest mitigation for identified vulnerabilities.
  • Deep knowledge of web application and mobile application security testing.
  • Collaborate on product conceptualization for security by design.
  • Knowledge on web application security, ethical hacking, DFRA, CSR.
  • Experience in understanding false positives from source code scans.
  • Lead at least one CSR (Compressive Security Review).
  • Knowledge of SAST, DAST, and open source security (OSS).
  • Strong understanding of OWASP top 10.
  • Experience in WAF logs analysis.
  • Rapid decision making to prevent delayed releases due to security issues.
  • Coordinate with stakeholders to complete audit points observed by internal and external auditors.
  • Ensure all CERTS, RBI, and various security advisories are checked and recommended actions taken on respective platforms.
  • Working knowledge of web and mobile application security.
  • Extensive experience in vulnerability assessment and penetration testing, web application security.
  • Knowledge in conducting security audits.
  • Good knowledge of threat modeling, cryptography, and common application security practices.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Expert (Application / Web Security) (Min 5 Years)
Security Expert (Application / Web Security) (Min 5 Years)

AagatiServe Pvt Ltd • India

On-site
INR 1,000,000 - 1,500,000
Application Security Specialist - Lead
Application Security Specialist - Lead

adani capital pvt ltd • Ahmedabad District

On-site
INR 1,500,000 - 2,200,000
Associate Information Security Consultant
Associate Information Security Consultant

Qseap Infotech • Navi Mumbai

On-site
INR 350,000 - 550,000
Application Security Head
Application Security Head

Adani Group • Mumbai

On-site
INR 3,500,000 - 6,000,000
Application Security Professional
Application Security Professional

Keka Technologies • Bengaluru

On-site
INR 500,000 - 900,000
Application Security Specialist Lead
Application Security Specialist Lead

Adani Enterprises Ltd • Ahmedabad District

On-site
INR 1,400,000 - 2,200,000
IT Security System Administrator I
IT Security System Administrator I

Mouser Electronics • Bengaluru

On-site
INR 80,000 - 100,000
Application Security Engineer
Application Security Engineer

Byline Learning Solutions • Pune District

On-site
INR 1,200,000 - 1,800,000
Application Security
Application Security

Airtel • India

On-site
INR 1,200,000 - 2,400,000
Security-focused culture
Consultant - Application Security Job
Consultant - Application Security Job

YASH Technologies • Bengaluru

On-site
INR 1,800,000 - 3,200,000