drjobs Senior / Lead Application Security Engineer - (IGT1 Lanka: Workwave)

Senior / Lead Application Security Engineer - (IGT1 Lanka: Workwave)

Employer Active

1 Vacancy
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
Send me jobs like this
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs
Job Location drjobs

Colombo - Sri Lanka

Monthly Salary drjobs

Not Disclosed

drjobs

Salary Not Disclosed

Vacancy

1 Vacancy

Job Description

The ideal candidate should have expertise in compliance and security standards such as PCI DSS SOC ISO and Privacy Shield / Data Privacy Framework. Key responsibilities include ensuring the security of desktop web and mobile applications through vulnerability assessments penetration testing security scans and architecture design reviews. 

Responsibilities  

  • Ensure application security measures comply with industry standards (e.g. PCI DSS SOC 2 ISO 27001). Maintain security policies and support compliance audits.  
  • Conduct regular vulnerability assessments and manage remediation. Implement and maintain vulnerability management tools. 
  • Perform penetration testing on desktop web and mobile applications. Document the findings and collaborate with development teams to implement fixes. 
  • Conduct regular security scans and audits using SAST DAST SCA and IAST tools. 
  • Review application architecture for security best practices Provide secure coding guidance and participate in release readiness reviews.  
  • Ensure data security through encryption and access controls. Implement data protection strategies and follow Privacy by design principles. 
  • Perform network vulnerability assessments and firewall audits and address potential security weaknesses. 
  • Collaborate with cross-functional teams to integrate security into the SDLC.  
  • Provide security training and assist in developing incident response plans. 

Qualifications :

  • Bachelors degree in computer science Information Security or related field. Relevant certifications such as CEH CHFI Security CSSLP  would be an added advantage. 
  • 4 years of experience in application security focusing on desktop web and mobile applications. 
  • Proven experience with compliance standards and frameworks (PCI DSS SOC 2 ISO 27001 Privacy Shield). 
  • Hands-on experience with vulnerability assessment tools and techniques (Qualys Blackduck Polaris BurpSuite Nmap Firewalls WAF IDS IPS Kali Linux). 
  • Strong background in penetration testing and security audits.  
  • Familiarity with SAST DAST SCA and IAST tools.  
  • In-depth knowledge of application security principles cryptography authentication and authorization. 
  • Experience with secure coding practices and application architecture design review. 
  • Ability to work independently and as part of a team.  
  • Strong analytical and problem-solving skills with excellent communication and interpersonal abilities. 


Additional Information :

We believe that coming together as a community in person is important for innovation connection and fostering a sense of belonging. Our roles have the right balance of remote and in-office working to enable flexibility for managing your life along with ensuring a real connection with your colleagues and the broader IFS community.


Remote Work :

No


Employment Type :

Full-time

Employment Type

Full-time

Company Industry

About Company

Report This Job
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.