Talent.com
Application Security Engineer II - SAST / DAST

Application Security Engineer II - SAST / DAST

PhenomHyderabad
9 days ago
Job description

About the job : What Youll Do :

  • Research, identify and analyze and triage vulnerabilities that could affect Phenom ITX Platform and its supporting infrastructure, and determine its severity, exploitability and corrective action recommendations, summarizing and reporting results.
  • Collaborate with engineering / development teams to evolve software assurance processes to address security risks, and help teams learn and adopt shift-security-to-left practices.
  • Work on implementing the required fixes to remediate the vulnerabilities in collaboration with the engineering team
  • Deploy, improve and utilize SAST / DAST / SCA and other cybersecurity solutions to identify and communicate security vulnerabilities to Phenom production teams
  • Maintain and report progress on the state of application vulnerabilities and escalate as necessary to ensure vulnerability issues are closed and handled in a manner consistent with Phenom standards
  • Work closely with the business, support and production teams to provide input and guidance on development of planned remediation plans and strategies to solve identified vulnerabilities
  • Use technical writing and effective communications to prepare and deliver vulnerability assessment result reports to all levels of audiences (peers and or leadership).
  • Drive compliance support and improvements over time through the management, analysis and tracking of vulnerabilities discovered through audits, products or collaborations.
  • Perform research and analytics and stay apprised on new security vulnerability, threats, risks, attack tools and techniques to contribute and improve Phenoms Threat model and collaborate with senior engineering and product management staff to incorporate effective security standards and controls into product design.
  • Help in the deployment of Phenom Secure Architecture & Software Development program to support the best cybersecurity development practice, and ensure Phenom ITX Platform is highly secure, resilient and aligned with business and product development strategy.
  • Continuously review and identify security improvement opportunities in existing processes, services, and workflows to ensure Phenom ITX platform is robust against current and future cybersecurity threats.
  • Support cybersecurity process activities including security requirements definition, threat modelling, code reviews and cyber risk assessment.
  • Support on development and maintenance of a security by default standard to be used in the development, infrastructure, or any other technology project.
  • Deliver training on Security Development Lifecycle to engineering / development teams
  • Contribute to the review of internal processes and activities and assist in identifying potential opportunities for improvement and automation.
  • Drive continuous improvement activities to define, measure, visualize and improve key cyber security metrics related to Application Security.
  • Provide analytic support to answer questions about vulnerabilities, and general threat intelligence trends

Work Experience :

  • Experience with Amazon Web Services cloud environments and its security controls and their corresponding challenges.
  • Experience with microservices architectures & distributed Platforms especially in the SaaS businesses
  • Experience using Agile software development
  • Coding Experience in Scripting & programming languages (such as Terraform, Java, Python, Ruby, etc.)
  • Knowledge of information security principles (Confidentiality, Integrity, Availability Authentication & Public Key Infrastructure (PKI), Data Security or Cryptography), and understanding of common exploitation techniques and mitigation.
  • Experience implementing, managing, and supporting a vulnerability management program (process and technology).
  • Experience and well-known understanding of Dynamic and Static Application Security Testing (DAST & SAST) and infrastructure automation / development utilizing APIs.
  • Understanding of the main cybersecurity tools (SIEM, IPS, XDR, etc.) and how they help to protect an application.
  • Experience working with Threat modeling (e.g., STRIDE, PASTA, FAIR, Security Cards) and vulnerability frameworks standards (e.g., OWASP, CVSS, CWE) with a good understanding of the Cyber Kill Chain and pervasive threat attack methods and remediation.
  • Thought leadership, critical thinking, strong organizational skills, report writing skills to senior level, ability to prioritize and multitask
  • (ref : hirist.tech)

    Create a job alert for this search

    Security Engineer Ii • Hyderabad

    Related jobs
    Senior Application Security Engineer

    Senior Application Security Engineer

    Practical DevSecOpsHyderabad, India, India
    Remote
    Quick Apply
    Permanent(Full Time / Full-Time).We are seeking an Application Security Engineer to join our team and help maintain, enhance, and develop security training exercises for our renowned DevSecOps, API S...Show moreLast updated: 30+ days ago
    • Promoted
    Sr Engineer, Software - Security Operations [T500-20383]

    Sr Engineer, Software - Security Operations [T500-20383]

    TMUS Global SolutionsHyderabad, Telangana, India
    About T-Mobile : T-Mobile US, Inc.NASDAQ : TMUS), headquartered in Bellevue, Washington, is America’s supercharged Un-carrier, connecting millions through its strong nationwide network and flagship b...Show moreLast updated: 13 days ago
    • Promoted
    SquareShift - Security Engineer - DevSecOps

    SquareShift - Security Engineer - DevSecOps

    SQUARESHIFT TECHNOLOGIES PRIVATE LIMITEDHyderabad
    We are seeking a talented Security Engineer to join our team.The ideal candidate should have a strong background in production security, DevSecOps, and extensive experience with SDLC practices and ...Show moreLast updated: 30+ days ago
    • Promoted
    Lead Security Engineer

    Lead Security Engineer

    ArcanaHyderabad, IN
    As our Lead Security Engineer, you'll own and elevate Arcana's overall security posture - cloud, on-prem, and everything in between. You'll design and enforce policies, automate controls, and harden...Show moreLast updated: 30+ days ago
    • Promoted
    Application Security Engineer

    Application Security Engineer

    ConfidentialHyderabad / Secunderabad, Telangana
    Research, identify and analyze and triage vulnerabilities that could affect Phenom ITX Platform and its supporting infrastructure, and determine its severity, exploitability and corrective action r...Show moreLast updated: 30+ days ago
    • Promoted
    Signiminds - Staff Security Engineer - SOAR / SIEM

    Signiminds - Staff Security Engineer - SOAR / SIEM

    SIGNIMINDS TECHNOLOGIES PRIVATE LIMITEDHyderabad
    Description : We are seeking a skilled and versatile Staff Security Engineer to lead the advancement of our detection and automation initiatives.Re...Show moreLast updated: 6 days ago
    • Promoted
    Security Engineer [T500-20670]

    Security Engineer [T500-20670]

    Delta Air LinesHyderabad, Telangana, India
    Delta Air Lines (NYSE : DAL) is the U.Powered by our employees around the world, Delta has for a decade led the airline industry in operational excellence while maintaining our reputation for award-...Show moreLast updated: 19 days ago
    • Promoted
    YASH Technologies - Application Security Engineer - SIEM

    YASH Technologies - Application Security Engineer - SIEM

    YASH TechnologiesHyderabad
    Description : We are looking forward to hire Application Security Professionals in the following areas : <...Show moreLast updated: 10 days ago
    • Promoted
    Application Security Engineer

    Application Security Engineer

    FoodsmartHyderabad, IN
    Foodsmart is the leading telenutrition and foodcare solution, backed by a robust network of Registered Dietitians.Our platform is designed to foster healthier food choices, drive lasting behavior c...Show moreLast updated: 7 days ago
    • Promoted
    Senior Application Security Engineer

    Senior Application Security Engineer

    QualiZealHyderabad, Telangana, India
    Conduct Static Application Security Testing (SAST) and Software Composition Analysis (SCA).Perform Dynamic Application Security Testing (DAST) and Interactive Application Security Testing (IAST) fo...Show moreLast updated: 30+ days ago
    • Promoted
    Sr Engineer, Software - Security Operations [T500-20381]

    Sr Engineer, Software - Security Operations [T500-20381]

    TMUS Global SolutionsHyderabad, Telangana, India
    NASDAQ : TMUS), headquartered in Bellevue, Washington, is America’s supercharged Un-carrier, connecting millions through its strong nationwide network and flagship brands, T-Mobile and Metro by T-Mo...Show moreLast updated: 13 days ago
    • Promoted
    Senior Security Engineer - SIEM, DevSecOps, IPS / IDS

    Senior Security Engineer - SIEM, DevSecOps, IPS / IDS

    EmburseHyderabad, Telangana, India
    Emburse software engineers contribute to the development of an engaging and interconnected set of system solutions.As an engineer, you will enhance the experiences of your customers, solve interest...Show moreLast updated: 19 days ago
    • Promoted
    Lead Security Engineer

    Lead Security Engineer

    interface.aihyderabad, telangana, in
    Our cutting-edge Generative AI-powered platform serves over 100 banks and credit unions, delivering hyper-personalized customer interactions across voice, chat, and employee-assisting solutions.To ...Show moreLast updated: 30+ days ago
    • Promoted
    Application Security Engineer II - SAST / DAST

    Application Security Engineer II - SAST / DAST

    Phenompeople Private LimitedHyderabad
    Job Requirements : What Youll Do : - Resear...Show moreLast updated: 20 days ago
    • Promoted
    Application Security Engineer III

    Application Security Engineer III

    ConfidentialHyderabad / Secunderabad, Telangana
    We're looking for a full-time phenomenal Application Security Engineer III to architect and lead the implementation of the security-related aspects of our ITX platform. This will include evaluating ...Show moreLast updated: 30+ days ago
    • Promoted
    Appen - Staff Engineer - Application Security

    Appen - Staff Engineer - Application Security

    AppenHyderabad
    About Appen : Appen is a leader in AI enablement for critical tasks such as model improvement, supervision, and evaluation.To do this we l...Show moreLast updated: 29 days ago
    • Promoted
    Senior Application Security Engineer (AI)

    Senior Application Security Engineer (AI)

    BackbaseHyderabad, Telangana, India
    Backbase has ushered in a new era of digital banking with the global launch of its AI-powered Banking Platform, recently lighting up Times Square. This milestone marks a bold step in reshaping the d...Show moreLast updated: 19 days ago
    • Promoted
    DevSecOps / AppSecOps Staff Engineer

    DevSecOps / AppSecOps Staff Engineer

    First American (India)hyderabad, telangana, in
    Our people-first culture empowers bold thinkers and passionate technologists to solve real-world challenges through scalable architecture and innovative design. If you're driven by impact, thrive in...Show moreLast updated: 30+ days ago