Talent.com
This job offer is not available in your country.
YASH Technologies - Cyber Security Professional - DAST / SAST

YASH Technologies - Cyber Security Professional - DAST / SAST

YASH TechnologiesBangalore
30+ days ago
Job description

We are looking forward to hire Cyber Security Professionals in the following areas :

Job Description :

Experience required 5+ Defect Management :

  • Analyzing, validating, communicating, and consulting on security defects identified by both automated and manual sources such as CodeQL, Rapid7 Web Application Security, penetration testing, bug bounty, etc. In other words, our security engineers are partners to software engineers who require accurate information on why a vulnerability exists and what they can do about Consulting :
  • Serving as a best friend to software engineers, architects, product owners, and leaders, provide contextually-aware guidance to help these groups make good decisions when implementing new features and remediating existing issues.

Tool Enablement :

  • Enabling and monitoring automated defect detection tooling (CodeQL, Rapid7, etc.) at the repository or application level according to established Test Onboarding & Management :
  • Collecting and communicating required scope and access information for penetration testing and security assurance assessments, as well as handling the output of these assessments via our Defect Management Measurement :
  • Consulting with software engineers on practices which will improve their applications security maturity according to scorecards and maturity models established by Cat of Error :
  • Authoring, in close partnership with software engineers, correction of error reports which help engineers and architects across Cat Digital avoid similar mistakes in their own Qualifications :
  • Two of three :

  • 5+ years of experience as a software engineer (in any language or framework) or software engineering manager
  • 5+ years of experience as a software development-focused cybersecurity professional
  • 5+ years of experience working on a major cloud platform (AWS, Azure, GCP, or Salesforce) as a software engineer, cloud / DevOps engineer, security engineer, or architect.
  • As Well As :

  • Experience analyzing and remediating security findings from automated and manual sources such as Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), penetration testing, Software Composition Analysis (SCA), etc.
  • Experience leveraging one or more of the following resources to support secure coding and decision-making :
  • OWASP Top 10
  • MITRE Common Weakness Enumeration (CWE) Top 25
  • OWASP Application Security Verification Standard (ASVS)
  • Other industry-standard best practice guides or frameworks
  • Experience building or supporting web applications and APIs including Single Page Applications (SPA) and RESTful APIs.
  • Proficiency in one or more programming languages.
  • (ref : hirist.tech)

    Create a job alert for this search

    Cyber Security • Bangalore