
Applications Security Engineer
4 weeks ago
Role Summary
The application security program is designed to ensure that any software developed or acquired meets stringent standards while enabling rapid innovation to meet customers ever? changing needs. The Application Security Engineer is responsible for providing application security services including secure coding techniques, security testing support and guidance for software development :
- Integrating security tools, standards, and processes into the product life cycle (PLC)
- Perform regular vulnerability assessment and penetration testing for Infrastructure, web applications, web services, mobile apps
- Supporting the incident response and architecture review processes whenever application security expertise is needed
- Identify, analyse and assess technical and organisational cybersecurity vulnerabilities
- Identify attack vectors, uncover and demonstrate exploitation of technical cybersecurity vulnerabilities
- Test systems and operations compliance with regulatory standards
- Select and develop appropriate penetration testing techniques
- Organise test plans and procedures for penetration testing
- Establish procedures for penetration testing result analysis and reporting
- Document and report penetration testing results to stakeholders
- Deploy penetration testing tools and test programs
- Managing annual penetration testing services, including both expert consulting and managed service
- Providing manual penetration testing and standards gap analysis services to internal business and technology partners
- Managing application framework and perimeter security improvement projects.
- Supporting vendor due diligence assessments to ensure 3rd party software meets Lebara security standards
- Producing metrics reporting the state of application security programs and performance of development teams against & EXPERIENCE :
- Familiarity and ability to explain common security flaws and ways to address them (e.g., OWASP Top 10, Sans 25)
- Basic development or scripting experience and skills. JavaScript, React, Node, .Net and/or Java are preferred
- A basic understanding of network and web related protocols (such as TCP/IP, UDP, HTTP, HTTPS, protocols)
- Familiarity with some common security libraries and tools (e.g., static analysis tools, proxying / penetration testing tools)
- Knowledge of the SSDLC process and its components.
- Knowledge in SOA (service-oriented architecture), Rest API technology and the API Gateway concept
- Knowledge of one of the three leading cloud services : Azure, GCP or AWS
- Experience in pen testing IaaS, SaaS, PaaS services, Container servers
- Experience in pen testing cloud services such as AWS, Azure
- Should have experience in vulnerability risk scoring system EPSS, CVSS etc.
- Experience in using opensource vulnerability intelligence to predict
- Must be proficient with security configuration standards such as CIS benchmark, NIST etc.
- Experience in maintaining external attack surface security posture
- Should have experience with attack path management
- Should have experience in Red Teaming exercises
- Should have experience in defense evasion, lateral movements, and privilege escalations techniques
- Very good knowledge in MITRE ATT&CK Framework & TTPS
- Very good knowledge in Windows operating system
- Very good knowledge in Linux servers
- Experience in pentest tools such as Kali Linux, Nmap NSE, Bloodhound, Metasploit, Password Crackers, Mimi Katz etc.
- Experience in vulnerability's scanner such as Rapid7 InsightVM, , Burp Suite, OpenVAS, NMAP NSE etc.
- Very good knowledge in scripting languages such as bash, python, PowerShell etc.
- Experience in application technology security testing (white box, black box and code review)
- Understanding of Apache web server and Unix server operating systems
- Knowledge of standard SDLC practices
- Ideally a relevant certification such as CISSP, CEH, OSCP, or CSSLP
)
-
Application Security Engineer
4 weeks ago
Chennai, India Aliqan Technologies Full timeGreetings from ALIQAN Technologies Job Title: Application Security Engineer Experience: 5+ YearsDepartment: Technology – Information Security Location: Chennai (Hybrid – 3 days from office) Reporting To: Application Security Architect Working Hours: Full Time (9 hours/day) About Lebara Lebara is a global telecommunications company, operating across...
-
Application Security
2 weeks ago
Chennai, India Vitasta Consulting Pvt Ltd Full timeOrganisation Unit Purpose (why does the unit exist? What are the results the unit is expected to deliver?) The unit's primary purpose is to Design, Engineer & eventually Embed practical & balanced cyber / information security principles/patterns/controls into all products and platforms. Conduct security assessments, gap analysis, provide remediation to...
-
Application Security
2 weeks ago
Chennai, India Vitasta Consulting Pvt Ltd Full timeOrganisation Unit Purpose (why does the unit exist? What are the results the unit is expected to deliver?) The unit's primary purpose is to Design, Engineer & eventually Embed practical & balanced cyber / information security principles/patterns/controls into all products and platforms. Conduct security assessments, gap analysis, provide remediation...
-
Web Application Security
2 weeks ago
Chennai, India NETSACH GLOBAL Full timeGreetings from Netsach - A Cyber Security Company. We are looking for Web Application Security consultant with minimum of 3+ years of relevant experience in an information security function with good background in information technology, stakeholder management and people management. Their primary purpose is to Design, Engineer & eventually Embed practical &...
-
Web Application Security
2 weeks ago
Chennai, India NETSACH GLOBAL Full timeGreetings from Netsach - A Cyber Security Company. We are looking for Web Application Security consultant with minimum of 3+ years of relevant experience in an information security function with good background in information technology, stakeholder management and people management. Their primary purpose is to Design, Engineer & eventually Embed practical &...
-
Senior Security Engineer
2 weeks ago
Chennai, India Tazapay Pte Ltd Full timeJob Title - Senior Security Engineer (Application & Cloud Security) Location: Chennai About Tazapay Tazapay is a cross border payment service provider. They offer local collections via local payment methods, virtual accounts and cards in over 70 markets. The merchant does not need to create local entities anywhere and Tazapay offers the additional...
-
Senior Security Engineer
2 weeks ago
Chennai, India Tazapay Pte Ltd Full timeJob Title - Senior Security Engineer (Application & Cloud Security) Location: Chennai About Tazapay Tazapay is a cross border payment service provider. They offer local collections via local payment methods, virtual accounts and cards in over 70 markets. The merchant does not need to create local entities anywhere and Tazapay offers the additional...
-
Senior Security Engineer
4 weeks ago
Chennai, India Tazapay Full timeJob Description Job Title - Senior Security Engineer (Application & Cloud Security) Location: Chennai About Tazapay Tazapay is a cross border payment service provider. They offer local collections via local payment methods, virtual accounts and cards in over 70 markets. The merchant does not need to create local entities anywhere and Tazapay offers the...
-
Application Security Architect
1 week ago
Chennai, India IDP Education Ltd Full time**POSITION PURPOSE** This role is part of the IDP Global Cyber-Security team. We have an exciting opportunity for a Security Architect to provide the vision & drive in our DevSecOps way of working. As IDP’s Security Architect you will work very closely with development teams, Cloud & DevOps engineers to guide them in strong security and privacy...
-
Senior Application Security Enginee...
2 weeks ago
Chennai, India Anicalls (Pty) Ltd Full timeCandidate should be able to: Create and manage bug bounty programs. Evangelize software security best practices. Perform threat modeling, architecture design reviews, and detection capabilities Develop and implement security tooling. Partner with software engineering and product teams to ensure security throughout the SDLC. Candidate should have: Strong...