Talent.com
TC-CS-CTM-AppSec-Senior

TC-CS-CTM-AppSec-Senior

ConfidentialBengaluru / Bangalore, India
9 days ago
Job description

At EY, we're all in to shape your future with confidence.

We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go.

Join EY and help to build a better working world.

CTM Senior – DevSecOps

As part of our Cyber Security team, you will help secure cloud / on-prem applications and platform while ensuring seamless development, build and deployment capabilities. You will be responsible for the security assessment of infrastructure and applications, setting up processes and guidelines. You will work closely with DevOps, architects, developers and QA teams to build highly reliable and secure products. You shall also perform in-depth analysis of security test results and create report that describes findings, exploitation procedures, risks and recommendations.

The opportunity

We're looking for Senior Security Consultant with expertise in DevSecOps. This is a fantastic opportunity to be part of a leading firm whilst being instrumental in the growth of new service offerings. You will work with other infrastructure, DevOps and application engineers to understand client business needs, provide expertise around application and cloud service development, as well as define and own clear guardrails, alerts, and Security as Code (SaC) deployments.

Your Key Responsibilities

  • Expertise In executing large scale application security programs
  • Expertise in Shift left security concept and security in DevOps
  • Understanding of agile software development principles and security practices
  • Convey complex technical security concepts to technical and non-technical audiences including executives.
  • Strong knowledge of software supply chain vulnerabilities and the ability to effectively communicate methodologies and techniques with development teams
  • Provide technical leadership and advise to junior team members on application security engagements.
  • Develop automated solutions that mitigate risks throughout the organization.
  • Support policies and vulnerability analysis using application security testing infrastructure including (SAST, DAST, SCA, IAST, and API Security)
  • Ensure these tools deliver maximum value for both security and developer stakeholders.
  • Support integration and automation efforts to ensure that security testing is an integral and painless part of code development.
  • Partner with and train developers in how to deliver secure code.
  • Track, prioritize and drive remediation of code vulnerabilities.
  • Develop and foster effective working relationships within both Security and IT teams to ensure that projects are delivered securely and on-time.

Skills And Attributes For Success

  • Experience with performing manual and automated SAST assessments.
  • Experience with scripting / programming skills (e.g., Python, PowerShell, Java, Perl etc.) updated and familiarized with the latest exploits and security trends.
  • Familiarity with dynamic web application vulnerability scanning tools and services (Acunetix, HP WebInspect, HCL AppScan, BurpSuite)
  • Familiarity with static code analysis tools and services (CheckMarx, Snyk, Fortify Static Code Analysis tool, Veracode, Coverity, IBM AppScan Source)
  • Experience in developing a DevSecOps CI / CD pipeline completely using open source tools.
  • Experience with SCM tools like Github, Gitlab, Bitbucket and their ability to integrated with CI / CD pipelines by using webhooks, actions, etc.
  • Experience with implementing different phases of CI / CD like secret scanning, SAST, SCA, DAST, Infrastructure as code, compliance as code, vulnerability management.
  • Optimizing the pipeline to produce the best results and ability to plan a maturity model for the DevSecOps program.
  • Understanding of web-based application vulnerabilities (OWASP Top 10).
  • Experience with scripting / programming skills (e.g., Python or PowerShell or Java or Perl etc.).
  • To qualify for the role, you must have

  • BE / B.Tech / MCA.
  • Minimum of 3 years of full-time work experience in SAST, SCA, DAST and DevSecOps.
  • Knowledge of Windows, Linux, UNIX, any other major operating systems.
  • Strong Excel and PowerPoint skills.
  • Ideally, you will also have

  • Familiarity with programming languages such as Java, JavaScript, Python and Angular
  • Strong knowledge of relevant Security Standards (OWASP) and how to apply them to the software development lifecycle in a large agile environment.
  • Experience performing security analysis on web applications and APIs.
  • Experience working in an Agile environment.
  • What Working At EY Offers

    At EY, we're dedicated to helping our clients, from start–ups to Fortune 500 companies — and the work we do with them is as varied as they are.

    You get to work with inspiring and meaningful projects. Our focus is education and coaching alongside practical experience to ensure your personal development. We value our employees and you will be able to control your own development with an individual progression plan. You will quickly grow into a responsible role with challenging and stimulating assignments. Moreover, you will be part of an interdisciplinary environment that emphasizes high quality and knowledge exchange. Plus, we offer :

  • Support, coaching and feedback from some of the most engaging colleagues around
  • Opportunities to develop new skills and progress your career
  • The freedom and flexibility to handle your role in a way that's right for you
  • EY | Building a better working world

    EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.

    Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.

    EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.

    Skills Required

    Acunetix, DAST, Java, Github, Veracode, Powershell, SCA, Checkmarx, Burpsuite, DevSecOps, Perl, Bitbucket, SAST, API Security, Gitlab, Owasp Top 10, Coverity, Python

    Create a job alert for this search

    TC-CS-CTM-AppSec-Senior • Bengaluru / Bangalore, India

    Related jobs
    • Promoted
    • New!
    Co-Founder (Android AOSP)

    Co-Founder (Android AOSP)

    HappiDost.aiBengaluru, Karnataka, India
    This is a full-time on-site role for a Co-Founder (Android AOSP) at HappiDost.The Co-Founder will play a vital role in shaping the company's product and technological foundation, focusing primarily...Show moreLast updated: 11 hours ago
    • Promoted
    Observability Engineer (Cloud Engineer) (Otel, AWS, Grafana)

    Observability Engineer (Cloud Engineer) (Otel, AWS, Grafana)

    FICOhosur, tamil nadu, in
    FICO is seeking a Full-Stack observability Lead Engineer to design, maintain, and optimize our observability platform.The ideal candidate will be an expert in Open telemetry(Otel) instrumentation a...Show moreLast updated: 4 days ago
    • Promoted
    • New!
    Field CTO - Solutions Engineering - SecOps - SOAR, SIEM, DLP

    Field CTO - Solutions Engineering - SecOps - SOAR, SIEM, DLP

    CareerXperts Consultinghosur, tamil nadu, in
    Ready to Shape the Future of AI Security?.We're not looking for someone who just talks tech—we need a.Imagine this : You're in the room when a Fortune 500 CISO asks, "How do we stop AI from becoming...Show moreLast updated: 13 hours ago
    • Promoted
    ML Ops

    ML Ops

    EXLhosur, tamil nadu, in
    Deploy, monitor, and scale ML models on.GCP (Vertex AI, GKE, Cloud Functions).GitHub Actions / Jenkins / cloud-native tools. Containerize and orchestrate workloads with.MLflow, Feast, Prometheus / Gra...Show moreLast updated: 30+ days ago
    • Promoted
    Microsoft Power App Lead

    Microsoft Power App Lead

    Persistent Systemshosur, tamil nadu, in
    We are Looking for Lead having good experience in implementing and leading of Microsoft power platform as part of a service-oriented architecture for managing dynamic business process.Must be profi...Show moreLast updated: 28 days ago
    • Promoted
    • New!
    Senior Integration Specialist Tibco

    Senior Integration Specialist Tibco

    YALLO Grouphosur, tamil nadu, in
    We are looking for a Senior Integration Specialist to design, develop, and maintain backend integration solutions across ecommerce, ERP, POS, inventory, and loyalty systems.This role primarily invo...Show moreLast updated: 13 hours ago
    • Promoted
    DevSecOps / AppSecOps Staff Engineer

    DevSecOps / AppSecOps Staff Engineer

    First American (India)hosur, tamil nadu, in
    Our people-first culture empowers bold thinkers and passionate technologists to solve real-world challenges through scalable architecture and innovative design. If you're driven by impact, thrive in...Show moreLast updated: 30+ days ago
    • Promoted
    Appworks

    Appworks

    OpenTextBengaluru, Karnataka, India
    Opentext - The Information Company.As the Information Company, our mission at OpenText is to create software solutions and deliver services that redefine the future of digital.Be part of a winning ...Show moreLast updated: 7 days ago
    • Promoted
    GCP Observability Engineer

    GCP Observability Engineer

    Dexian IndiaBengaluru, Karnataka, India
    We are seeking an experienced and motivated engineer to join the Observability fleet which focuses on delivering tools in private and public cloud environments. The role focuses on developing and mo...Show moreLast updated: 30+ days ago
    • Promoted
    AppScan Product _Lead SDET_Remote Location

    AppScan Product _Lead SDET_Remote Location

    HCLSoftwarehosur, tamil nadu, in
    Remote
    HCL Software” : - Is a Product Development Division of HCL Tech : That operates its primary Software business.At HCL Software we Develop, Market, Sell and Support over 20 Product families in the area...Show moreLast updated: 30+ days ago
    • Promoted
    Advanced Engineer Software [T500-20657]

    Advanced Engineer Software [T500-20657]

    Albertsons Companies Indiabangalore, karnataka, in
    About Albertsons Companies Inc : .As a leading food and drug retailer in the United States, Albertsons Companies, Inc.Our well-known banners across the United States, including Albertsons, Safeway, V...Show moreLast updated: 30+ days ago
    • Promoted
    Senior Serdes Architect

    Senior Serdes Architect

    Mulya TechnologiesGreater Bengaluru Area, India
    Senior SerDes Architect and Lead.About Omni Design Technologies.Omni Design Technologies is a leading provider of high-performance, ultra-low power IP cores, from 28nm down through advanced FinFET ...Show moreLast updated: 30+ days ago
    • Promoted
    Senior Engineer ML [T500-20680]

    Senior Engineer ML [T500-20680]

    Albertsons Companies Indiabangalore, karnataka, in
    About Albertsons Companies Inc.As a leading food and drug retailer in the United States, Albertsons Companies, Inc.Our well-known banners across the United States, including Albertsons, Safeway, Vo...Show moreLast updated: 30+ days ago
    • Promoted
    Advanced Engineer AIOps [T500-21171]

    Advanced Engineer AIOps [T500-21171]

    ANSRBengaluru, Karnataka, India
    About Albertsons Companies Inc.As a leading food and drug retailer in the United States, Albertsons Companies, Inc.Our well-known banners across the United States, including Albertsons, Safeway, Vo...Show moreLast updated: 5 days ago
    • Promoted
    AppScan Product _Sr. Performance Engineer _Remote Location

    AppScan Product _Sr. Performance Engineer _Remote Location

    HCLSoftwarehosur, tamil nadu, in
    Remote
    HCL Software” : - Is a Product Development Division of HCL Tech : That operates its primary Software business.At HCL Software we Develop, Market, Sell and Support over 20 Product families in the area...Show moreLast updated: 30+ days ago
    • Promoted
    CTO Co-Founder | Remote | Equity linked | Part-Time

    CTO Co-Founder | Remote | Equity linked | Part-Time

    Blitz Consulting & Coachinghosur, tamil nadu, in
    Remote
    One of Blitz Divisions is an applied-AI Venture Studio converting domain inefficiencies into.Our portfolio spans 3 pillars -. Skilling, Consulting & Patent-driven products.The 3 Pillars are unified ...Show moreLast updated: 28 days ago
    • Promoted
    Senior ADC Architect

    Senior ADC Architect

    Mulya TechnologiesGreater Bengaluru Area, India
    About Omni Design Technologies.Omni Design Technologies is a leading provider of high-performance, ultra-low power IP cores, from 28nm down through advanced FinFET nodes, which enable differentiate...Show moreLast updated: 30+ days ago
    • Promoted
    Mobile App Release Manager [T500-19891]

    Mobile App Release Manager [T500-19891]

    Best Buy Indiahosur, tamil nadu, in
    Own the release calendar and manage the end-to-end release process for mobile apps on iOS and Android.Coordinate and execute OTA releases using tools such as Code Push or custom delivery systems, e...Show moreLast updated: 28 days ago