We are looking for 7 to 10 years of experience in cybersecurity, highly skilled and motivated Product & Solution Security Professional to join our team.
The ideal candidate will be responsible for defining secure design principles and supporting multi-functional teams to ensure secure architecture, implementation, and testing of products and solutions.
Proven experience working with software development teams and integrating security practices into the SDLC.
Experience interacting with key collaborators and supporting security activities within software products and having An engineering degree B.E / B.Tech / MCA / M.Tech / M.Sc with good academic record.
Key Responsibilities with SDLC :
- Collaborate with software development teams to integrate security practices throughout the Software Development Process (SDLC).
- Ensure security requirements are included in the design, development, testing, and deployment stages of software projects.
- Perform security code reviews and analyze vulnerabilities during dierent SDLC Activities :
- Develop and implement security protocols, guidelines, and standard processes for software development.
- Conduct threat modelling and risk assessments to identify potential security issues early in the development process.
- Provide guidance on secure coding practices and remediation of Work closely with key stakeholders, including product managers, project managers, and business analysts, to support and promote security activities within products.
- Communicate security risks, issues, and mitigation strategies eectively to both technical and non-technical collaborators.
- Foster a security-aware culture within the development teams and across the organization.
- Implement and manage security tools such as static and dynamic analysis tools and vulnerability scanners.
- Stay updated with the latest security tools, trends, and standard processes to hance products security posture.
- Conduct security training and awareness programs for development teams.
- Promote continuous improvement and knowledge sharing related to application security.
- In-depth knowledge of application security, secure coding practices, and common vulnerabilities (e.g., OWASP Top Ten).
- Experience with security tools and technologies such as static analysis tools (SAST), dynamic analysis tools (DAST), and vulnerability scanners.
- Proficiency in programming languages such as Java, C#, Python.
- Understanding of DevSecOps practices and integration of security into CI / CD pipelines.
- Promote continuous improvement and related to application security.
- Strong communication and interpersonal skills.
- Ability to explain complex security concepts to non-technical collaborators.
- Strong analytical and problem-solving skills.
- Collaborative approach and ability to work e?ectively with multi-functional teams.
Certification Preferred : CEH, Certified Secure Software Lifecycle Professional (CSSLP) or equivalent.
(ref : hirist.tech)