Application Security - Vulnerability Operations Center
Location: Bengaluru, India
Years of Experience: 5+ Years
Job Summary
We are seeking a skilled Application Security Analyst with a strong background in application security principles and practices. The ideal candidate will possess in-depth knowledge of vulnerability types, risk assessment, and DevSecOps processes. This role requires a proactive individual who can enhance our vulnerability triage operations and collaborate effectively with cross-functional teams to ensure secure application development.
Responsibilities
- Possess a strong understanding of vulnerability types (OWASP Top 10, CWE, CVE, misconfiguration, insecure API) and clearly explain common attack techniques.
- Demonstrate capability in vulnerability prioritization based on exploitability, asset criticality, and business context.
- Uplift DevSecOps vulnerability triage operations to enhance effectiveness and efficiency.
- Perform manual and semi-automated triage of vulnerability findings, providing expert judgment on severity, exploitability, and business impact.
- Conduct false positive analysis, de-duplication, and tool output normalization.
- Provide technical input during project releases to prepare triage readiness.
- Identify and correlate recurring vulnerability data across projects or business units to observe trends and streamline triage processes.
- Collaborate with application teams, DevOps, BISOs, and developers to explain vulnerabilities and risks clearly.
- Participate in security tool PoC/PoV and selection processes.
- Drive implementation and integration of selected tools into the triage workflow to enhance automation, data accuracy, and analyst efficiency.
- Design and implement automation workflows for enrichment, de-duplication, and ticketing.
- Contribute to strategic planning and continuous improvement of VOC capabilities.
- Prepare documentation and reporting on knowledge base documentation and playbook creation, maintaining accurate records of analysis, risk decisions, and triage actions.
- Provide guidance to developers and application teams on secure coding best practices.
Mandatory Skills
- Strong knowledge of security standards, CVSS scoring, EPSS, CWE, CVE, KEV database, and MITRE ATTCK.
- Experience with CVSS tuning, exploit intelligence, and SLA tagging.
- Familiarity with exploitation techniques, including SQL injection, XSS, CSRF, SSRF, and RCE.
- Proficiency in one or more scripting languages (JavaScript, Python, PowerShell, Bash) and automation platforms.
- Advanced knowledge of vulnerability assessment tools and threat modeling.
- Strong analytical and communication skills, with excellent stakeholder communication and incident coordination abilities.
- Ability to explain technical vulnerabilities clearly to developers and other stakeholders.
- Critical thinking skills to trigger deep-rooted problem solving and multi-disciplinary analytical skills.
- Effective technical writing and documentation skills for SOPs and evaluation reports.
Preferred Skills
- Experience in a legacy environment with technical debt and internal challenges.
- Positive mindset for growth and driving change.
Qualifications
- Bachelors degree in Computer Science, Information Security, or a related field.
- 5+ years of experience in application security or a related field.
Disclaimer: This job description has been sourced from a public domain and may have been modified by Naukri.com to improve clarity for our users. We encourage job seekers to verify all details directly with the employer via their official channels before applying.