This job is with Marsh McLennan, an inclusive employer and a member of myGwork – the largest global platform for the LGBTQ+ business community. Please do not contact the recruiter directly.
We are seeking a talented individual to join our Dev Ops team at Marsh McLennan. This role will be based in Pune. This is a hybrid role that has a requirement of working at least three days a week in the office.
We Will Count On You To
- Conduct comprehensive security-focused pull request reviews across multiple applications and technology stacks
- Design, develop, and maintain reusable security libraries, frameworks, and boilerplate code for development teams
- Establish and enforce secure coding standards through technical guidance and code review processes
- Create and maintain security-focused development tools, linters, and automated checks
Architecture & Design
Review and provide technical input on application architectures from a security perspectiveParticipate in design reviews and technical discussions to ensure security best practices are embedded from the ground upPerform threat modeling and security architecture assessments for new and existing applicationsCollaborate with engineering teams to design secure, scalable solutions that meet business requirementsSecurity Champion Leadership
Serve as the senior technical member within the Security Champion community across MMCMentor and guide other security champions, providing technical expertise and best practice guidanceLead technical discussions regarding proposed changes to Application Security Standards and guidelinesAct as resident security expert and technical consultant across multiple application portfoliosDevelopment & Implementation
Actively contribute to secure application development through hands-on coding and technical implementationIntegrate security controls and features into applications (RBAC, authentication, authorization, encryption, etc.)Develop and maintain security testing frameworks and automated security validation toolsContribute to the design and implementation of security infrastructure and deployment pipelinesStandards & Process
Establish and maintain technical security standards, guidelines, and best practices for development teamsProvide technical guidance on vulnerability assessment, triaging, and remediation approachesReview and validate security incident remediation, including secrets management and disposalEnsure alignment with industry standards (OWASP Top 10, SANS Top 25, CWE) and internal security policiesCollaboration & Communication
Work closely with development teams, product owners, and architects to integrate security seamlessly into the development processServe as technical liaison between development teams and global information securityProvide technical training and knowledge sharing sessions on secure development practicesCommunicate complex security concepts clearly to both technical and non-technical stakeholdersWhat You Need To Have
Bachelor's degree in Computer Science, Engineering, or equivalent technical experienceOverall experience of 14+years, 7+ years of software development experience with strong engineering fundamentalsExpert-level proficiency in multiple programming languages (JavaScript / TypeScript, Python, Java, C#, etc.)Deep understanding of modern application architectures, microservices, and cloud platforms (Azure, AWS)Extensive experience with CI / CD pipelines, DevOps practices, and infrastructure as codeAdvanced knowledge of secure coding practices, common vulnerabilities, and security testing methodologiesSecurity Specialization
Advanced expertise in application security principles, practices, and industry standardsExperience with security testing tools (SAST, DAST, IAST, dependency scanning)Deep understanding of authentication, authorization, cryptography, and secure communication protocolsKnowledge of threat modeling methodologies and security architecture patternsExperience with security frameworks and compliance requirements (SOC 2, ISO 27001, NYDFS, etc.)Leadership & Communication
Proven track record of leading technical initiatives and mentoring development teamsExcellent communication skills with ability to influence and educate technical and non-technical audiencesExperience working in distributed, cross-functional teams across multiple time zonesStrong problem-solving skills with ability to balance security requirements with business needsWhat Makes You Stand Out
Technical Excellence
Demonstrated ability to architect and implement enterprise-scale security solutionsExperience building and maintaining security-focused development tools and frameworksDeep expertise in multiple technology stacks and ability to quickly adapt to new technologiesTrack record of successfully implementing security controls in complex, distributed systemsLeadership & Impact
Experience leading security transformation initiatives within large organizationsProven ability to influence engineering culture and drive adoption of security best practicesExperience with site reliability engineering (SRE) practices and security operationsInnovation & Continuous Learning
Active participation in security communities, conferences, and open-source projectsProactive approach to staying current with emerging security threats and technologiesExperience with AI / ML security considerations and secure integration of LLM technologiesDemonstrated ability to translate business requirements into technical security solutionsWhat makes you stand out
Experience with microservices architecture and serverless computingCertifications in AWS, Azure, GCP, or DevOps tools (e.g., Certified Kubernetes Administrator, AWS Certified DevOps Engineer)Knowledge of network security, firewalls, and VPNsAbility to automate and optimize operational processesStrong interpersonal skills and ability to work across teams and geographiesPassion for learning new technologies and continuous improvementWhy Join Our Team
We help you be your best through professional development opportunities, interesting work and supportive leaders.We foster a vibrant and inclusive culture where you can work with talented colleagues to create new solutions and have impact for colleagues, clients and communities.Our scale enables us to provide a range of career opportunities, as well as benefits and rewards to enhance your well-being.Marsh McLennan (NYSE : MMC) is a global leader in risk, strategy and people, advising clients in 130 countries across four businesses : Marsh, Guy Carpenter, Mercer and Oliver Wyman. With annual revenue of $24 billion and more than 90,000 colleagues, Marsh McLennan helps build the confidence to thrive through the power of perspective. For more information, visit marshmclennan.com, or follow on LinkedIn and X.
Marsh McLennan is committed to embracing a diverse, inclusive and flexible work environment. We aim to attract and retain the best people and embrace diversity of age, background, caste, disability, ethnic origin, family duties, gender orientation or expression, gender reassignment, marital status, nationality, parental status, personal or social status, political affiliation, race, religion and beliefs, sex / gender, sexual orientation or expression, skin color, or any other characteristic protected by applicable law.
Marsh McLennan is committed to hybrid work, which includes the flexibility of working remotely and the collaboration, connections and professional development benefits of working together in the office. All Marsh McLennan colleagues are expected to be in their local office or working onsite with clients at least three days per week. Office-based teams will identify at least one 'anchor day' per week on which their full team will be together in person.
Skills Required
Java, Iso 27001, threat modeling , Encryption, Typescript, Python, SAST, rbac, DAST, Javascript