Collaborate with engineering, operations, and security teams to design, implement, automate and maintain an effective application security programImplement, triage security vulnerabilities and automate security controls like SAST, DAST, SCA and IaCAnalyze security vulnerabilities pertaining to DevOps platforms like GitHub Action, Drone, Jenkins, SpinnakerDevelop the security best practices, standards and guidelines for engineering teams across different technologies and provide support in implementing themDevelop security controls and process to be implemented as self-service and work with different stakeholders for implementationDevelop and automate day-to-day operational tasks and deployment methodsSupport red team in performing security assessment of, but not limited to, web & mobile application, containers, k8s, thick client, cloud environmentsQualifications / Requirements
- 6+ years experience in application security and DevSecOps domain in product based organization
- Proven experience in security engineering and DevSecOps functions, building and managing security solutions across the stack
- Understanding of overall software development process and implementation of security controls in CICD pipeline
- Understanding of DevOps controls, process & technologies and security vulnerabilities pertaining to them
- Expertise in automating complex day-to-day operational tasks using Python or any other scripting language
- Knowledge of OWASP Web and Mobile Top 10 vulnerabilities, identifying, exploiting and remediating them
- Excellent written and verbal communication skills.
- Self-motivated, curious, knowledgeable pertaining to news and current events
Skills Required
Cloud Security, Application Security, Owasp, Data Security, Python