Lead Security Analyst

Morningstar Credit Ratings, LLC

Mumbai

On-site

INR 1,800,000 - 2,400,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Morningstar India Private Ltd. in Mumbai seeks a Lead Security Analyst to drive application security automation within CI/CD. You will integrate static and dynamic analysis tools into pipelines, verify findings, and help remediation efforts across development teams while collecting security metrics.

The role emphasizes communication with internal business units, delivering guidance, and training on secure coding practices to strengthen Morningstar's overall security posture.

Qualifications

  • A bachelor's degree and 7+ years' experience in a development or software security / penetration testing role.
  • Experience with static and dynamic security assessment tools and code reviews.
  • Strong understanding of Java, JavaScript, .NET, PHP, Ruby and authentication models (SAML/OAuth/OpenID).
  • Excellent communication skills and ability to communicate risks to business units.

Responsibilities

  • Create, manage and maintain Jenkins CI jobs to support application security automation.
  • Administer common static and dynamic security assessment tools.
  • Verify automated findings from static/dynamic assessments.
  • Communicate risks to internal business units and drive timely remediation of vulnerabilities.
  • Collect and analyze application security metrics.
  • Provide remediation guidance and training to technical personnel.
  • Document secure coding guidelines and run training programs for developers.
  • Provide software security support and remediation guidance to development personnel.

Skills

Application security
Static analysis tools
Dynamic analysis tools
Java
JavaScript
.NET
PHP
Ruby
SAML/OAuth/OpenID
Communication skills

Education

Bachelor's degree

Tools

Semgrep
Brightsec
WAF

Job description

The Area

The Information Security department is responsible for setting enterprise security policies and standards that are designed to protect the confidentiality, integrity and availability of Morningstar information. The security team offers guidance and technical expertise in areas like application security, policies and procedures, disaster recovery and compliance/regulation. We analyze emerging security threats and conduct risk and vulnerability assessments to ensure that our information remains secure.

The Role

The Lead Security Analyst will assist in supporting Morningstar's application security automation program. This individual will help integrate static and dynamic security analysis tools into Morningstar's continuous integration processes, assist with security remediation activities, ensure that vulnerabilities are being remediated in a timely manner and support development and technical personnel as required. This position is based in our Mumbai location.

Responsibilities
  • Create, manage and maintain Jenkins continuous integration jobs to support application security automation
  • Administer common static and dynamic security assessment tools
  • Verify automated application security findings that result from automated static and dynamic assessments
  • Work directly with internal business units to communicate risks and to help ensure open vulnerabilities are resolved in a timely manner
  • Collect and analyze application security metrics
  • Provide security remediation advice and training to technical personnel
  • Assist with documenting secure coding guidelines and running training programs to assist internal development personnel
  • Provide software security support and remediation guidance to development personnel
Requirements
  • A bachelor's degree and 7+ years' experience in a development or software security / penetration testing role
  • We're looking for someone who enjoys breaking code, solving puzzles, and diagnosing problems
  • Excellent communication skills and a strong understanding of software development and application security fundamentals
  • Candidates should be interested in keeping up with the latest security trends, as well as enjoy performing code / architecture reviews and penetration test activities
  • Experience with common static and dynamic analysis tools (Semgrep, Brightsec, WAF etc.)
  • A strong understanding of security best practices in Java, JavaScript, .NET, PHP and Ruby programming languages
  • Strong understanding of common authentication models (SAML, OAuth, OpenID, etc.) is preferred
  • A software development and application security background is preferred

Morningstar is an equal opportunity employer.

Morningstar's hybrid work environment gives you the opportunity to collaborate in-person each week as we've found that we're at our best when we're purposely together on a regular basis. In most of our locations, our hybrid work model is four days in-office each week. A range of other benefits are also available to enhance flexibility as needs change. No matter where you are, you'll have tools and resources to engage meaningfully with your global colleagues.

US Applicants: Morningstar is an E-Verify program participant. Learn more: This Organization Participates in E-Verify (English) This Organization Participates in E-Verify (Spanish) Right to Work (English) Right to Work (Spanish)

EEO is the Law Pay Transparency Notice

Morningstar is strongly committed to creating and preserving equal opportunity for all employees and applicants. We make all employment decisions - including recruitment, hiring, compensation, training, promotion, transfer, discipline, termination, and other personnel matters - without regard to race, color, ancestry, religion, sex, national origin, age, disability, protected veteran status, marital status, sexual orientation, genetic information, citizenship, gender identity and expression, parental status, or other legally protected characteristics or conduct.

I10_MstarIndiaPvtLtd Morningstar India Private Ltd. (Delhi) Legal Entity

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Analyst
Security Analyst

Morningstar Credit Ratings, LLC • Mumbai

Hybrid
INR 700,000 - 1,100,000
Hybrid work model
Hiring For Security Analyst - Morningstar
Hiring For Security Analyst - Morningstar

Morningstar • Mumbai, Thane

Hybrid
INR 600,000 - 900,000
Senior Software Engineer (Run)
Senior Software Engineer (Run)

Morningstar Credit Ratings, LLC • Mumbai

On-site
INR 1,200,000 - 2,000,000
Associate Manager
Associate Manager

Morningstar Credit Ratings, LLC • Mumbai

Hybrid
INR 1,800,000 - 3,000,000
Hybrid work model
Four days in-office each week
Global collaboration tools
Associate Director, Platform Services
Associate Director, Platform Services

Morningstar Credit Ratings, LLC • Mumbai

Hybrid
INR 3,500,000 - 5,400,000
Hybrid work model
Equal opportunity employer
Associate Content Researcher
Associate Content Researcher

Morningstar Credit Ratings, LLC • Mumbai

Hybrid
INR 700,000 - 1,100,000
Software Engineer
Software Engineer

Morningstar • Delhi

On-site
INR 1,400,000 - 2,800,000
Senior Software Engineer (Engagement)
Senior Software Engineer (Engagement)

Morningstar Credit Ratings, LLC • Mumbai

Hybrid
INR 2,000,000 - 4,000,000
Finance Analyst
Finance Analyst

Morningstar Credit Ratings, LLC • Mumbai

Hybrid
INR 900,000 - 1,200,000
Software Development Engineer
Software Development Engineer

Morningstar Credit Ratings, LLC • Mumbai

Hybrid
INR 1,200,000 - 1,800,000
Hybrid work model
Collaboration with global teams
Opportunities for growth and learning