Talent.com
This job offer is not available in your country.
Amadeus Labs - Senior Information Security Specialist - DevSecOps

Amadeus Labs - Senior Information Security Specialist - DevSecOps

Amadeus LabsBangalore
24 days ago
Job description

Job Title : SR SPECIALIST INFORMATION SECURITY

Responsibility & Key Result Areas :

  • Represent CISO organization and in particular the Application Security Office, in Bangalore, relaying important security objectives, requirements, and information to R&D in BLR.
  • Should be from core application software development or DevSecOps background and should have extensive development, designing & DevSecOps skill.
  • Should be leading the one or more development / implementation initiatives for Application Security Office.
  • As DevSecOps & Secure SDL Senior Specialist, Lead build, implementation and deployment of the Secure Development Lifecycle activities in CI / CD pipeline, Assist in security assessments of new architecture and technology.
  • Will have hands on experience in Secure SDLC including DevSecOps, Threat Modelling, Web Application Scan, Static & Binary Scan, Vulnerability assessment and triaging and Security Testing.
  • Should provide expertise and consultancy on SCM like GitHub, BitBucket, Jenkins etc and security tools like Burpsuite, Qualys WebApp Scan, Blackduck, Prisma scanner, Fortify SSC, sonarcube, Checkmarx and other static / dynamic analysis tools.
  • Should have exposure or ability to learn application security concepts not limited to CIA triad, OWASP Top 10 Vulnerabilities, OAuth, SAML, JWT, Cryptography and other advanced security concepts.
  • Perform or assist in performing security assessments for new architectures and technologies, providing expert guidance on potential security risks.
  • Analyse, support and validate Security requirements with the purpose of continuously improving our services.
  • Support and help in conducting regularly MOCK PCI-DSS & GDPR compliance audits and provide consultancy as required in order to maintain certifications, compliance certificates and adherence to standards and compliancy requirements.
  • Ensure Compliance loopback channel to the organization with excellent coordination and communication between stakeholders within the organization.
  • Play the role of Security Product Owner / Scrum Master / Facilitator for App Security Agile Scrum / Kanban Team.
  • Interface with the rest of the organization with the purpose to collect areas of improvement and transform / enrich them in a way meaningful to the expected providers.
  • Understand the environment in sufficient details to solicit, suggest, validate and prioritize innovative ideas and / or requirements that will improve the Security services provided by the organization.
  • Ensure project deliverables are delivered to the quality and schedule committed as per project management plan.
  • Ensure accurate and effective communication and reporting of key security indicators (KSI) to all relevant stakeholders.
  • Help animating R&D community of Security Whitehats and build internal security expertise.
  • Assist in creating a security culture and provide input to HR Training for security trainings.
  • Provide formalised but pragmatic security standards, guidelines and recommendations, in collaboration with other security offices.
  • Raise alerts and find solutions, communicate and report to internal and external stakeholders.

Competencies :

  • The right candidate will have total 9 to 12 years of experience in software development design & development / coding and engineering practices along with extensive experience in DevSecOps and product secure development lifecycle (Secure SDL) and methodologies implementation & governance.
  • Good knowledge of infrastructure as code, end-to-end fully-automated CI / CD pipelines, from code commits to production and security of repositories (like GitHub, BitBucket etc), pipelines, build / release tools (like Jenkins, GitHub actions etc) and methodologies in CI / CD pipelines.
  • Proficiency in scripting, including Python, Groovy, Helm, shell scripts, Perl etc to support the automation and continuous improvement of processes.
  • Hands on experience in DevSecOps, Secure SDLC including Threat Modeling, Vulnerability assessment.
  • Security Testing, Security Scans and Security compliance like PCI-DSS / GDPR / ISO.
  • Exposure on Webservices( SOAP / REST) security assessment will be a definite plus.
  • Experience in full DevSecOps CI / CD pipeline, Agile methodology, container security, APIs, and microservices.
  • Knowledge of OWASP Top10, SANS Top25, CWE and CVE / Mitre, along with hands-on practical experience in development & testing for vulnerabilities and implementing remediation.
  • Should have good exposure in Burpsuite, Qualys WebApp Scan, Blackduck, Prisma scanner, Fortify SSC and other static / dynamic analysis tool.
  • Good understanding on all security areas like CIA Triad, Authentication, Authorization, Session Management, Cryptography, Data Validation, Error Handling, Confidentiality / Integrity / Availability / Authentication / Authorization / Auditing / Logging etc.
  • Should have good experience in other areas of Secure SDLC.
  • Investigate (potential) attacks, assess exploitability and risk exposure, and propose mitigation.
  • Security certifications such as CEH, CDP, CDE, CSSLP, CISSP, CCSP etc are a plus.
  • Soft Skills :

  • Multi-cultural approach, and ability to interface with all levels of the organization.
  • Strong analytical, conceptual and problem solving skills.
  • Accountability and reliability, personal involvement.
  • Pro-activity, initiative, and autonomy.
  • Independent work ethic.
  • Diversity & Inclusion :

    Amadeus aspires to be a leader in Diversity, Equity and Inclusion in the tech industry, enabling every employee to reach their full potential by fostering a culture of belonging and fair treatment, attracting the best talent from all backgrounds, and as a role model for an inclusive employee experience.

    Amadeus is an equal opportunity employer.

    All qualified applicants will receive consideration for employment without regard to gender, race, ethnicity, sexual orientation,?age, beliefs, disability or any other characteristics protected by law.

    (ref : hirist.tech)

    Create a job alert for this search

    Information Security Specialist • Bangalore

    Related jobs
    • Promoted
    Senior DevOps Security Engineer

    Senior DevOps Security Engineer

    JRD SystemsBengaluru, IN
    We are seeking a highly skilled Senior DevOps / Platform Engineer to join our dynamic team.The ideal candidate will have extensive experience in managing and automating infrastructure, improving depl...Show moreLast updated: 3 days ago
    • Promoted
    ColorTokens - L3 Senior Security Analyst

    ColorTokens - L3 Senior Security Analyst

    ColortokensBangalore
    Job Title : Senior Security Analyst L3 Location : Bangalore (on site) Experience Level : 5 to 8 years<...Show moreLast updated: 30+ days ago
    Senior Information Security Engineer

    Senior Information Security Engineer

    ScaleneWorksBengaluru, Karnataka, India
    Quick Apply
    This position requires experience in participating in designing a Secure Development Lifecycle and bringing in security best practices at every step of the systems development cycle, integrating ap...Show moreLast updated: 30+ days ago
    • Promoted
    ServiceNow SecOps

    ServiceNow SecOps

    Mindsprinthosur, tamil nadu, in
    ServiceNow SecOps Implementation Specialist (VR & SIR).ServiceNow platform with at least 3 years focused on SecOps – Vulnerability Response (VR) and Security Incident Response (SIR).ServiceNow Cert...Show moreLast updated: 25 days ago
    • Promoted
    Lead Security Engineer

    Lead Security Engineer

    interface.aihosur, tamil nadu, in
    Our cutting-edge Generative AI-powered platform serves over 100 banks and credit unions, delivering hyper-personalized customer interactions across voice, chat, and employee-assisting solutions.To ...Show moreLast updated: 25 days ago
    • Promoted
    Senior Engineer - Security Research

    Senior Engineer - Security Research

    Indus face Private LimitedBangalore
    Job Description : - Create signatures for Indusface WAS & WAF product to detect & protect Web applications vulnerabilities. Research evolving web attacks, CVEs...Show moreLast updated: 30+ days ago
    • Promoted
    Information Security Lead

    Information Security Lead

    ConfidentialBengaluru / Bangalore, India
    Are you passionate about cybersecurity and data security If your answer is a resounding yes, then we are hunting for you. As an Information Security Lead, your primary role will be to play a crucial...Show moreLast updated: 8 days ago
    • Promoted
    Lead Information Security Engineer -GRC

    Lead Information Security Engineer -GRC

    InMobi AdvertisingBengaluru, Karnataka, India
    InMobi is the leading provider of content, monetization, and marketing technologies that fuel growth for industries around the world. Our end-to-end advertising software platform, connected content,...Show moreLast updated: 30+ days ago
    • Promoted
    Xoxoday - Information Security Engineer - Cyber Security

    Xoxoday - Information Security Engineer - Cyber Security

    Nreach Online Services Pvt. Ltd.Bangalore
    Information Security Engineer As an Information Security Engineer, you will play a crucial role in safeguarding the GIIFT organization's information systems and ...Show moreLast updated: 30+ days ago
    • Promoted
    Information Security Engineer Lead

    Information Security Engineer Lead

    BenchireBengaluru, Karnataka, India
    Develop and implement comprehensive information security strategies, policies, standards, and procedures.Lead the creation and maintenance of robust security controls to protect all information ass...Show moreLast updated: 15 days ago
    • Promoted
    Security Technology Lifecycle Analyst

    Security Technology Lifecycle Analyst

    HR PLACEMENT CONSULTANTS (HRPC)Bangalore Rural, Karnataka, India
    Position - Analyst - Security Technology Lifecycle Analyst.Job Type - Full-time (Third party payroll •).The Security Technology Lifecycle Analyst plays a critical role in supporting the Corporate Se...Show moreLast updated: 19 days ago
    • Promoted
    Senior Information Security Technical Consultant - SIEM

    Senior Information Security Technical Consultant - SIEM

    Gateway SearchBangalore
    Overview : We are hiring for a tech client in Bangalore for Information Security Technical Consultant having 8 to 12 years of experience in Firewa...Show moreLast updated: 30+ days ago
    • Promoted
    Information Security Lead - Vulnerability Management

    Information Security Lead - Vulnerability Management

    Terralogic Software Solutions Private Limited.Bangalore
    Location : Bangalore Employment Type : Full-Time Experience Required : 10+ Years Show moreLast updated: 30+ days ago
    • Promoted
    Information Security Lead

    Information Security Lead

    Narayana HealthBengaluru, Karnataka, India
    The Information Security Lead will be responsible for developing and implementing the organization’s information security framework to safeguard patient data, clinical systems, and enterprise IT in...Show moreLast updated: 22 days ago
    • Promoted
    Lead Security Engineer

    Lead Security Engineer

    Arcanahosur, tamil nadu, in
    As our Lead Security Engineer, you'll own and elevate Arcana's overall security posture - cloud, on-prem, and everything in between. You'll design and enforce policies, automate controls, and harden...Show moreLast updated: 30+ days ago
    Senior Information Security Specialist

    Senior Information Security Specialist

    ScaleneWorksBengaluru, Karnataka, India
    Quick Apply
    The information security officer will mainly deal with Information Security Assets protection in deep technical environment. The person will Identify and assess potential security risks in the Cloud...Show moreLast updated: 30+ days ago
    Senior Information Security Engineer

    Senior Information Security Engineer

    Epergne SolutionsBengaluru, Karnataka, India
    Quick Apply
    Senior Information Security Engineer.Job Roles & Responsibilities.Lead vulnerability assessments and policy compliance scans across on prem, cloud, container (Docker / Kubernetes), database, and ...Show moreLast updated: 30+ days ago
    • Promoted
    Senior Manager, DevSecOps

    Senior Manager, DevSecOps

    ConfidentialBengaluru / Bangalore, India
    Create and implement security practices & tools within CI / CD pipelines where applicable to integrate security into the DevOps lifecycle. Identify, evaluate, and remediate security vulnerabilities in...Show moreLast updated: 8 days ago