Cyber Security Specialist

Utthunga

Bengaluru

On-site

INR 1,800,000 - 2,800,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Utthunga is seeking an Application Security Engineer to design, implement, and monitor Secure Development Lifecycle (SDL) practices across software projects in Bengaluru. You will work with cross-functional teams to embed security early, perform threat modeling, and lead security testing.

The ideal candidate has 3–5 years in application security, hands-on experience with web, mobile, and desktop security testing, and familiarity with tools like Burp Suite, OWASP ZAP, and Kali Linux.

Qualifications

  • Bachelor's degree in CS/IT/ Electronics/ Cybersecurity or related field.
  • 3–5 years in Application Security/Product Security (preferred).
  • Experience enforcing IEC 62443-4-1 SDL across projects.
  • Hands-on threat modeling and secure architecture reviews.
  • Proven security testing across Web, Mobile, and Thick Client/Desktop apps.

Responsibilities

  • Lead and monitor SDL implementation across projects.
  • Conduct STRIDE-based threat modeling with architects and teams.
  • Perform manual and automated security testing, remediation, and verification.
  • Review security designs and promote secure coding practices.
  • Collaborate with developers and stakeholders to improve security posture.

Skills

IEC 62443-4-1
Secure SDLC
Threat Modeling
Penetration Testing
OWASP Top 10
Vulnerability Assessment
Secure Coding Principles
REST API security
Agile/Scrum
Security Documentation

Education

Bachelor's degree in Computer Science, IT, Electronics, Cybersecurity or related engineering

Tools

Burp Suite
OWASP ZAP
SonarQube
Black Duck
Wireshark
Kali Linux

Job description

  • Strong experience implementing and monitoring IEC 62443-4-1 Secure Development Lifecycle requirements.
  • Strong understanding of Secure Development Lifecycle processes, software security assurance, and cybersecurity compliance.
  • Hands-on experience conducting STRIDE Threat Modelling and secure architecture reviews.
  • Strong experience performing penetration testing for Web Applications, Mobile Applications, and Thick Client/Desktop Applications.
  • Strong understanding of OWASP Top 10, secure coding principles, application security testing methodologies, and common software vulnerabilities.
  • Strong knowledge of vulnerability assessment, vulnerability management, and industry-standard risk scoring methodologies such as CVSS.
  • Hands-on experience with application security tools such as Burp Suite, OWASP ZAP, SonarQube, Black Duck, Wireshark, and common Kali Linux security tools.
  • Good understanding of software development and secure development practices using one or more technologies such as .NET/C#, Java, Python, or C++.
  • Strong understanding of web technologies, REST APIs, authentication and authorization mechanisms, encryption, secure communications, and networking concepts including HTTP, HTTPS, TCP/IP, and TLS.
  • Good understanding of security controls such as encryption, secure authentication, secure session management, defense-in-depth, least privilege, and Zero Trust principles.
  • Experience working in Agile/Scrum development environments with cross-functional software engineering teams.
  • Experience developing and reviewing security documentation, standards, procedures, and compliance evidence.
  • Excellent analytical, problem-solving, communication, and stakeholder management skills.
  • Ability to mentor junior engineers and promote secure development best practices across project teams.
  • Bachelor’s degree in computer science, Information Technology, Electronics, Cybersecurity, or a related Engineering discipline.
  • 3–5 years of experience in Application Security/Product Security (preferred over network security).
  • Professional cybersecurity certifications such as CEH, CompTIA Security+, CompTIA PenTest+, or equivalent are preferred.
  • Drive and monitor Secure Development Lifecycle (SDL) implementation across software development projects in compliance with prescribed cybersecurity standards.
  • Ensure project compliance with IEC 62443-4-1 Secure Development Lifecycle requirements by creating/maintaining compliance artifacts and client-defined cybersecurity processes.
  • Contribute to all stages of the Secure Development Lifecycle, including Security Requirements Analysis, Secure Design, Secure Implementation, Security Testing, and Secure Deployment.
  • Support STRIDE-based Threat Modelling activities for software products and collaborate with architects and development teams to identify and mitigate security risks.
  • Ensure project teams adhere to secure coding standards by supporting manual code reviews and automated security scanning activities.
  • Coordinate and analyze Static Application Security Testing (SAST) and Software Composition Analysis (SCA) results using approved security tools, and work with development teams to remediate identified findings.
  • Develop security test plans covering penetration testing, security requirements verification, threat validation testing, vulnerability assessment, and regression testing.
  • Design and maintain comprehensive security test cases and test suites aligned with project requirements and cybersecurity standards.
  • Perform manual penetration testing of web applications, mobile applications, and thick client applications, validate identified vulnerabilities, and verify remediation effectiveness.
  • Review, analyze, document, and track security defects through successful closure while ensuring timely reporting and retesting.
  • Perform vulnerability analysis for internally identified issues, automated scan findings, third-party disclosures, and customer-reported vulnerabilities using industry-standard risk assessment methodologies.
  • Participate in Agile sprint planning to identify, estimate, and track security-related activities and user stories.
  • Collaborate closely with software developers, testers, and project teams to embed security throughout the software development lifecycle.
  • Participate in customer discussions and technical reviews to communicate project security posture, compliance status, security risks, and remediation activities.
  • Represent projects during internal quality audits and external cybersecurity assessments by providing compliance evidence and addressing audit observations.
  • Conduct security awareness sessions and technical guidance for development teams on secure development practices and emerging security threats.
  • Continuously stay updated with evolving cybersecurity threats, vulnerabilities, tools, technologies, and industry best practices.

Mandatory Skills

IEC 62443-4-1, Threat Modeling, Threat Analysis, OWASP Zap, Burp Suite, Sonarqube, Blackduck, WireShark, Kali Linux

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Engineer | 4-6 years Experience
Senior Cybersecurity Engineer | 4-6 years Experience

Utthunga Technologies • Bengaluru

On-site
INR 1,800,000 - 3,000,000
Appsec Specialist - Lead
Appsec Specialist - Lead

Adani Group • Ahmedabad District

On-site
INR 2,800,000 - 4,200,000
Senior Security Engineer - Product Security
Senior Security Engineer - Product Security

Ecolab • Bengaluru

On-site
INR 2,500,000 - 4,000,000
Cyber Security Specialist
Cyber Security Specialist

SuperOps • Chennai District

On-site
INR 800,000 - 1,200,000
Cyber Security Engineer
Cyber Security Engineer

Vaisesika Consulting • Bengaluru

Hybrid
INR 1,500,000 - 2,100,000
Application Security Engineer
Application Security Engineer

Cynosure Corporate Solutions • Chennai District

On-site
INR 1,500,000 - 2,500,000
Product Security Engineer
Product Security Engineer

spectris • Chennai District

On-site
INR 1,500,000 - 2,100,000
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
Security Tester
Security Tester

Disprz • Chennai District

On-site
INR 1,800,000 - 3,600,000
Cybersecurity Engineer
Cybersecurity Engineer

Siemens Healthineers • Karnataka

On-site
INR 1,200,000 - 2,100,000