Senior Engineer - Cyber Security

Adani Group

Mumbai

On-site

INR 1,200,000 - 2,000,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Adani Group is seeking an Application Security Executive to support its security program across development to deployment. You will collaborate with developer teams to enforce secure coding, perform vulnerability assessments, and integrate security into the SDLC with SAST/DAST/IAST tools.

You will help identify risks, follow security standards including OWASP Top 10 and PCI-DSS, and assist with incident response and training to foster a security-first culture.

Qualifications

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
  • Advanced degree in Cybersecurity or related discipline is highly desirable.
  • Industry certifications such as OSCP / CEH / CHFI or similar are preferred.
  • Experience with application security tools such as CheckMarx, Fortify, Burpsuite, Acunetix, Appscan, Tenable, and static code analysis tools.
  • Experience with industry application security assessment frameworks (OWASP, NIST, PCI DSS) and DevSecOps platforms (GitLab, Github, etc.).
  • 2+ years of relevant experience in application security and secure SDLC including hybrid platform.

Responsibilities

  • Assist in implementing the application security program across the organization, ensuring secure development practices.
  • Work with development teams to design, code, and test applications with security in mind.
  • Help integrate security into the SDLC, including code reviews, threat modeling, and security testing.
  • Conduct regular vulnerability assessments (SAST/DAST) to identify security flaws.
  • Assist in managing and mitigating vulnerabilities with development teams.
  • Maintain a vulnerability management system from discovery to remediation.
  • Perform or assist with security code reviews to remediate flaws in source code and third-party libraries.
  • Enforce secure coding guidelines and correct security vulnerabilities in code.
  • Support identification of common vulnerabilities such as SQLi, XSS, IDOR.
  • Assist in security testing tools, including SAST, DAST, and IAST, in scanning applications.
  • Help develop and maintain automated security testing within CI/CD pipelines.
  • Monitor security status using tools and provide insights for improvement.
  • Support threat modeling and risk analysis for new applications or features.
  • Assist in risk assessments and mitigation recommendations.
  • Collaborate with IT, product development, DevOps; provide security awareness training.
  • Promote a security-first mindset across development teams.
  • Assist incident response teams to investigate security incidents and implement remediation.
  • Ensure compliance with OWASP Top 10, PCI-DSS, GDPR/HIPAA where applicable.
  • Provide regular reports on vulnerability assessments and remediation progress.

Skills

Secure coding practices
Vulnerability assessments
Threat modeling
Security testing
Collaboration with development teams
Incident response support

Education

Bachelor's degree in Computer Science / Information Technology / Cybersecurity
Advanced degree in Cybersecurity or related field
OSCP / CEH / CHFI certifications

Tools

CheckMarx
Fortify
Burp Suite
Acunetix
AppScan
Tenable

Job description

Purpose/Objective
  • The Application Security Executive is responsible for supporting the application security program, focusing on ensuring that applications are secure from development to deployment.
  • This role involves collaborating with development teams to enforce secure coding practices, conducting vulnerability assessments, and assisting with the implementation of security solutions throughout the software development lifecycle (SDLC).
  • The Application Security Executive will help to identify and mitigate security risks, ensuring that applications meet the organization’s security standards and compliance requirements.
Key Responsibilities of Role
  • Application Security Executive Application Security Support: Assist in the implementation of the application security program across the organization, ensuring secure development practices are followed.
  • Work closely with the development teams to ensure that applications are designed, coded, and tested with security in mind.
  • Help with the integration of security practices into the software development lifecycle (SDLC), including code reviews, threat modeling, and security testing.
  • Vulnerability Management: Conduct regular vulnerability assessments, including static and dynamic application security testing (SAST/DAST), to identify security flaws within applications.
  • Assist in managing and mitigating vulnerabilities found during testing by working with development teams to prioritize and address issues.
  • Help maintain a vulnerability management system to track vulnerabilities from discovery to remediation.
  • Security Code Reviews: Perform or assist with security code reviews to identify and remediate security flaws in source code and third-party libraries.
  • Enforce secure coding guidelines and work awith developers to correct coding errors related to security vulnerabilities.
  • Support the identification of common vulnerabilities such as SQL injection, cross-site scripting (XSS), and insecure direct object references (IDOR).
  • Security Testing and Tools: Assist in the execution and management of security testing tools, such as SAST, DAST, and IAST, to scan applications for vulnerabilities.
  • Help develop and maintain automated security testing within the continuous integration/continuous deployment (CI/CD) pipeline.
  • Work with security tools and platforms to monitor the security status of applications and provide insights into areas of improvement.
  • Threat Modeling and Risk Analysis: Support the process of threat modeling to identify potential threats, vulnerabilities, and risks associated with new applications or features.
  • Assist in performing risk assessments to evaluate the likelihood and impact of identified threats and vulnerabilities, recommending mitigation strategies.
  • Collaboration and Training: Collaborate with cross-functional teams, including IT, product development, and DevOps, to ensure security is integrated into all stages of the SDLC.
  • Provide security awareness training for developers and other stakeholders, educating them on secure coding practices and security threats.
  • Foster a security-first mindset across development teams and assist in promoting a culture of secure software development.
  • Incident Response Support: Assist in investigating application-related security incidents, gathering information and supporting the identification of root causes.
  • Work with incident response teams to implement remedial actions and prevent the recurrence of similar security issues in applications.
  • Compliance and Standards: Ensure that applications adhere to security standards and industry best practices, including OWASP Top 10, PCI-DSS, and other relevant security frameworks.
  • Assist in the compliance of application security with regulatory requirements, such as GDPR, HIPAA, or other applicable laws.
  • Reporting and Metrics: Provide regular reports on the status of application security efforts, including vulnerability assessments, remediation efforts, and overall risk posture.
  • Track metrics related to application security testing, remediation progress, and effectiveness of security controls.
  • Continuous Learning and Improvement: Stay up-to-date with the latest trends, threats, and vulnerabilities in application security and the wider cybersecurity landscape.
  • Continuously evaluate and improve the application security processes and tools, ensuring the team is using the most effective techniques and solutions available.
  • Key Stakeholders - Internal Business Unit Heads and Department Heads Application Security Lead / Head of Cybersecurity Information Security and IT teams Risk Management Teams Engineering & Development Teams Product Management and Operations Teams Key Stakeholders - External Regulatory Authorities Third-Party Service Providers
Technical Competencies
  • Application Security Management-CYS,Cybersecurity Governance & Compliance-CYS,IT Support & Infrastructure Security-CYS,Identity & Access Management-CYS,Network Security & Perimeter Defense-CYS,Research and Innovation-CYS
Qualifications and Experience
  • Educational Qualification: Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
  • Advanced degree (e.
    g.
    , Master's, MBA) in Cybersecurity, Information Assurance, or a relevant discipline is highly desirable.
  • Certification: Certifications: Industry certifications such as OSCP / CEH / CHFI or similar are preferred.
  • Experience with application security tools, such as CheckMarx, Fortify, Burpsuite, Acunetix, Appscan, Tenable, and static code analysis tools.
  • and experience on Industry application secuiry asesssment frameowrk e.
    g.
    , (OWASP, NIST, PCI DSS) and DevSecOps platforms e.
    g.
    , GitLab, Github etc.
  • Work Experience (Range of years): 2+ years of relevent experience in application security and secure software development lifecycle including hybrid platform
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Graduate Engineer Trainee (GET)
Graduate Engineer Trainee (GET)

Adani Group • Ahmedabad District

On-site
INR 1,200,000 - 1,800,000
Application Security Head
Application Security Head

Adani Group • Mumbai

On-site
INR 3,500,000 - 6,000,000
Application Security Engineer
Application Security Engineer

Cynosure Corporate Solutions • Chennai District

On-site
INR 1,500,000 - 2,500,000
Appsec Specialist - Lead
Appsec Specialist - Lead

Adani Group • Ahmedabad District

On-site
INR 2,800,000 - 4,200,000
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
Consultant - Application Security Job
Consultant - Application Security Job

YASH Technologies • Bengaluru

On-site
INR 1,800,000 - 3,200,000
SOC Engineer
SOC Engineer

Mintskill HR Solutions LLP • Mumbai

On-site
INR 600,000 - 1,000,000
System Security
System Security

BigShip Technologies Pvt. Ltd • Dadri

On-site
INR 1,000,000 - 1,500,000
Application Security Engineer
Application Security Engineer

Ola • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Senior Cybersecurity Engineer | 4-6 years Experience
Senior Cybersecurity Engineer | 4-6 years Experience

Utthunga Technologies • Bengaluru

On-site
INR 1,800,000 - 3,000,000