drjobs Team Lead - Application Security

Team Lead - Application Security

Employer Active

1 Vacancy
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
Send me jobs like this
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs
Job Location drjobs

Maharashtra - India

Monthly Salary drjobs

Not Disclosed

drjobs

Salary Not Disclosed

Vacancy

1 Vacancy

Job Description

Responsibilities

  • Setup and lead application security team.
  • Triage High/Critical findings & drive mitigation. (SAST SCA DAST VDP).
  • Identify approve high severity True or False positive vulnerabilities.
  • Support Product teams implementing SAST/SCA  in their  CI/CD pipelines.
  • Support Product Teams with Application security expertise for best mitigation of findings.
  • Provide generic application security consultancy.
  • Identify security risks in application architecture and infrastructure drive mitigations.
  • Contribute to the target SSDLC framework.
  • Support application security team strategically and technically developing and improving the main pillars of application security.
  • Support Security & Privacy Engineering Key activities.

Role Description

 

  • The Application Security Tech Lead is responsible for setting up leading and functionally steering a team of application security engineers.
  • Contribute to ensure that each steps of SDLC used by software engineers across METRO is following best practices in term of information security and data privacy.
  • Contribute to develop and maintain the needed technologies and processes to be included in CI/CD to include tollgates to secure that security control validations are automatically performed during development and deployment phases
  • Support software engineer teams across METRO to address identified software vulnerabilities and weaknesses
  • Serve as the technical authority providing expert guidance to the security engineers where needed.

Technical & Soft Skills:

  • InDepth knowledge of application security technologies and tools such as SASTSCADAST.
  • Strong knowledge and skills in scripting and development of automation in CI/CD.
  • Good understanding of .git concepts and market leading vendors like GitHub GitLab.
  • Deep understanding of OWASP ASVS is a must.
  • Proficiency in concepts of vulnerability assessments and scans using automated tools (Qualys Polaris
  • Understanding of common vulnerabilities and exposures (CVEs) Common Vulnerability Scoring System (CVSS) and vulnerability databases.
  • Familiarity with vulnerability management frameworks and methodologies such as the National Vulnerability Database (NVD) and the Common Vulnerability Enumeration (CVE) system.
  • Excellent communication and interpersonal skills to effectively collaborate with clients stakeholders and internal teams.
  • Proficient in producing reports briefings and presentations to communicate findings trends and recommendations to stakeholders.
  • Strong organizational and time management skills with the ability to coordinate and prioritize multiple tasks simultaneously.
  • Ability to work under pressure.

 


Qualifications :

Qualifications & Experience

Bachelors degree in computer science Information Technology Cybersecurity or a related field. A masters degree or relevant certifications (e.g. CISSP CSSLP) may be preferred.

Senior Engineer: 7 years of relevant experience preferably in an enterprise.

Hands on DevSecOps experience.


Remote Work :

No


Employment Type :

Fulltime

Employment Type

Full-time

Company Industry

About Company

Report This Job
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.