
▷ [High Salary] SR SPECIALIST – INFORMATION SECURITY
3 weeks ago
Job Description
Job Title
SR SPECIALIST - INFORMATION SECURITY
Responsibility & Key Result Areas:
- Represent CISO organization and in particular the Application Security Office, in Bangalore, relaying important security objectives, requirements, and information to R&D in BLR
- Should be from core application software development or DevSecOps background and should have extensive development, designing & DevSecOps skill. Should be leading the one or more development / implementation initiatives for Application Security Office.
- As DevSecOps & Secure SDL Senior Specialist, Lead build, implementation and deployment of the Secure Development Lifecycle activities in CI/CD pipeline, Assist in security assessments of new architecture and technology.
- Will have hands on experience in Secure SDLC including DevSecOps, Threat Modelling, Web Application Scan, Static & Binary Scan, Vulnerability assessment and triaging and Security Testing.
- Should provide expertise and consultancy on SCM like GitHub, BitBucket, Jenkins etc and security tools like Burpsuite, Qualys WebApp Scan, Blackduck, Prisma scanner, Fortify SSC, sonarcube, Checkmarx and other static/dynamic analysis tools
- Should have exposure or ability to learn application security concepts not limited to CIA triad, OWASP Top 10 Vulnerabilities, OAuth, SAML, JWT, Cryptography and other advanced security concepts
- Perform or assist in performing security assessments for new architectures and technologies, providing expert guidance on potential security risks.
- Analyse, support and validate Security requirements with the purpose of continuously improving our services.
- Support and help in conducting regularly MOCK PCI-DSS & GDPR compliance audits and provide consultancy as required in order to maintain certifications, compliance certificates and adherence to standards and compliancy requirements.
- Ensure Compliance loopback channel to the organization with excellent coordination and communication between stakeholders within the organization.
- Play the role of Security Product Owner/Scrum Master/Facilitator for App Security Agile Scrum / Kanban Team.
- Interface with the rest of the organization with the purpose to collect areas of improvement and transform/enrich them in a way meaningful to the expected providers.
- Understand the environment in sufficient details to solicit, suggest, validate and prioritize innovative ideas and/or requirements that will improve the Security services provided by the organization.
- Ensure project deliverables are delivered to the quality and schedule committed as per project management plan.
- Ensure accurate and effective communication and reporting of key security indicators (KSI) to all relevant stakeholders.
- Help animating R&D community of Security Whitehats and build internal security expertise. Assist in creating a security culture and provide input to HR Training for security trainings.
- Provide formalised but pragmatic security standards, guidelines and recommendations, in collaboration with other security offices
- Raise alerts and find solutions, communicate and report to internal and external stakeholders
Competencies:
- The right candidate will have total 9 to 12 years of experience in software development design & development/coding and engineering practices along with extensive experience in DevSecOps and product secure development lifecycle (Secure SDL) and methodologies implementation & governance.
- Good knowledge of infrastructure as code, end-to-end fully-automated CI/CD pipelines, from code commits to production and security of repositories (like GitHub, BitBucket etc), pipelines, build/release tools (like Jenkins, GitHub actions etc) and methodologies in CI/CD pipelines.
- Proficiency in scripting, including Python, Groovy, Helm, shell scripts, Perl etc to support the automation and continuous improvement of processes
- Hands on experience in DevSecOps, Secure SDLC including Threat Modeling, Vulnerability assessment. Security Testing, Security Scans and Security compliance like PCI-DSS/GDPR/ISO. Exposure on Webservices( SOAP/ REST) security assessment will be a definite plus
- Experience in full DevSecOps CI/CD pipeline, Agile methodology, container security, APIs, and microservices.
- Knowledge of OWASP Top10, SANS Top25, CWE and CVE / Mitre, along with hands-on practical experience in development & testing for vulnerabilities and implementing remediation.
- Should have good exposure in Burpsuite, Qualys WebApp Scan, Blackduck, Prisma scanner, Fortify SSC and other static/dynamic analysis tool
- Good understanding on all security areas like CIA Triad, Authentication, Authorization, Session Management, Cryptography, Data Validation, Error Handling, Confidentiality /Integrity / Availability / Authentication / Authorization / Auditing / Logging etc...
- Should have good experience in other areas of Secure SDLC
- Investigate (potential) attacks, assess exploitability and risk exposure, and propose mitigation
- Security certifications such as CEH, CDP, CDE, CSSLP, CISSP, CCSP etc are a plus.
Soft Skills:
- Multi-cultural approach, and ability to interface with all levels of the organization
- Strong analytical, conceptual and problem solving skills
- Accountability and reliability, personal involvement
- Pro-activity, initiative, and autonomy
- Independent work ethic
Diversity & Inclusion
Amadeus aspires to be a leader in Diversity, Equity and Inclusion in the tech industry, enabling every employee to reach their full potentialby fostering a culture of belonging and fair treatment, attracting the best talent from all backgrounds, andas a role model for an inclusive employee experience.
Amadeus is an equal opportunity employer. All qualified applicants will receiveconsideration for employment without regard to gender, race, ethnicity, sexual orientation, age, beliefs, disability or any other characteristics protected by law.
-
Information Security Specialist
2 weeks ago
Bengaluru, India Ample Full timeJob Description Designation - Information Security Specialist Location - Address: 4th Floor, NCC Windsor, International Airport Road, opposite Flying Club, Yashoda Nagar, Jakkur, Bengaluru, Karnataka 560065 Job Type: Full Time Job Summary: We are seeking a skilled and proactive Information Security Specialist to join our Internal IT team. This role...
-
Pune, India Deutsche Bank Full timeJob Description Information Security Specialist - Engineer / Tester, AVP Position Overview Job Title: Information Security Specialist - Engineer / Tester, AVP Location: Pune, India Role Description - As an Information Security Specialist focused on the Microsoft Purview solution, you will play a critical role in safeguarding the bank's information...
-
▷ [High Salary] Sr Specialist-Network Design
3 weeks ago
Bengaluru, India HCL Technologies Limited Full timeJob Description Job Description (Posting). About HCLTech HCLTech is a global technology company, spread across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud and AI, powered by a broad portfolio of technology services and products. We work with clients across all major verticals, providing industry...
-
Information Security Engineer
6 days ago
Bengaluru, Karnataka, India Tally Solutions Pvt Ltd Full time ₹ 12,00,000 - ₹ 36,00,000 per yearJob Description Designation:Information Security Engineer Function/Group: CIS/Information Systems Experience:5-7 yrs What will you be doing? As an Information Security Engineer, you will be responsible for protecting the organizations Technology resources and information assets by Ensuring strategic alignment of information security by working with InfoSec...
-
Information security specialist
3 weeks ago
Bengaluru, India Worldwide Flight Services Full timeThe Information Security Specialist will be responsible for monitoring, maintaining, and improving the organization’s security posture. The role involves incident management and response, endpoint security, identity and access management, compliance with ISO 27001:2022, and support in employee awareness programs. The specialist will work closely with...
-
Information Security Specialist
3 weeks ago
Bengaluru, India Worldwide Flight Services (WFS) Full timeThe Information Security Specialist will be responsible for monitoring, maintaining, and improving the organization’s security posture. The role involves incident management and response, endpoint security, identity and access management, compliance with ISO 27001:2022, and support in employee awareness programs. The specialist will work closely with...
-
Gsoc - Travel Security Specialist
4 weeks ago
India MAX Security Full timeCompany Profile: Max is Global Risk Management organization based out in Tel Aviv, Israel and its APAC HQ is based out of Mumbai.Led by veterans from Israeli Military Special Forces, Intelligence, Cyber and Secret Services we operate in 160 countries across the globe.We have capabilities in every continent across the world and carry the experience of 25 +...
-
Information Security Specialist
4 weeks ago
Bengaluru, Karnataka, India Worldwide Flight Services (WFS) Full timeThe Information Security Specialist will be responsible for monitoring, maintaining, and improving the organization's security posture. The role involves incident management and response, endpoint security, identity and access management, compliance with ISO 27001:2022, and support in employee awareness programs. The specialist will work closely with...
-
Information Security Specialist
3 weeks ago
Bengaluru, India Worldwide Flight Services (WFS) Full timeThe Information Security Specialist will be responsible for monitoring, maintaining, and improving the organization’s security posture. The role involves incident management and response, endpoint security, identity and access management, compliance with ISO 27001:2022, and support in employee awareness programs. The specialist will work closely with...
-
Information Security Specialist
3 weeks ago
Bengaluru, India Worldwide Flight Services (WFS) Full timeThe Information Security Specialist will be responsible for monitoring, maintaining, and improving the organization’s security posture. The role involves incident management and response, endpoint security, identity and access management, compliance with ISO 27001:2022, and support in employee awareness programs. The specialist will work closely with...