
Security Engineer III
2 days ago
Job Description The Application Security Engineer leads efforts to enhance application security and the secure software development lifecycle. This individual is responsible for performing manual application security assessments (application pentests) and communicating security findings to the developers and QA teams. Additionally, the individual will provide application design support and security best practice guidance, in the form of consultations, to various development teams and business stakeholders. This individual will also actively promote security through engaging interactive workshops and exercises, such as internal Capture The Flag (CTF) events. Principal Accountabilities - Serve as the primary application security expert for development teams, offering security consulting and best practice guidance throughout the Software Development Life Cycle (SDLC). - Perform manual security assessments at key points in the SDLC. - Produce documentation (reports) and present findings of manual security assessments to various stakeholders, including senior leadership. - Participate in security architecture reviews and threat modelling. - Contribute to automation initiatives, including the integration of new security tools and processes (e.g., AI). - Demonstrate a commitment to continuous education and staying current within the application security domain, promoting collaboration and knowledge sharing. Skills Requirements - 5+ years experience with industry standard penetration testing, or ability to demonstrate equivalent knowledge. - Expertise performing blackbox/greybox/whitebox security assessments of applications (e.g., web applications, APIs, thick clients, web sockets) which use HTTP and/or proprietary protocols. - Expert level skills with application security testing tools including: Burpsuite, sqlmap, nmap, etc. - Experience performing manual reviews of application source code for security vulnerabilities written in various languages including: Java, Javascript, .Net (C#), etc. - Experience with Cloud architectures, security principles and services. Google Cloud Platform (GCP) is preferred. - Experience with automating security testing and/or other relevant activities to streamline service delivery. Preferred scripting languages: Python, bash, Powershell, etc. - Experience with UNIX or Linux. - A self-starter who is highly motivated. Proactively seek answers, ask for help when needed, and communicate solutions. - Excellent Oral and Written communications skills. Ability to effectively communicate and interface with peers and stakeholders at all levels, including senior leadership. Nice To Have - Experience in securing modern APIs, including knowledge of authentication/authorization standards like OAuth 2.0 and JWT, and understanding API-specific vulnerabilities. - Experience in conducting formal threat modeling using frameworks like STRIDE to identify potential security flaws in the design phase. - Experience with AI/ML security testing methodologies, including understanding of OWASP Top 10 for Large Language Models (LLMs) and common AI security vulnerabilities, and using AI to improve pentesting. - Experience with prior development work. - Experience with application reverse engineering and using tools such as: Java decompilers, .Net decompilers, IDAPro, etc. - Experience with Capture The Flag (CTF) competitions and bug bounty programs. - Relevant industry certifications such as OSCP, eWPTX, CCSP, GCP Professional Cloud Security Engineer, etc. CME Group: Where Futures are Made CME Group is the world's leading derivatives marketplace. But who we are goes deeper than that. Here, you can impact markets worldwide. Transform industries. And build a career by shaping tomorrow. We invest in your success and you own it all while working alongside a team of leading experts who inspire you in ways big and small. Problem solvers, difference makers, trailblazers. Those are our people. And we're looking for more. At CME Group, we embrace our employees unique experiences and skills to ensure that everyone's perspectives are acknowledged and valued. As an equal-opportunity employer, we consider all potential employees without regard to any protected characteristic. Important Notice: Recruitment fraud is on the rise, with scammers using misleading promises of job offers and interviews to solicit money and personal information from job seekers. CME Group adheres to established procedures designed to maintain trust, confidence and security throughout our recruitment process. Learn more here.
-
Security Engineer III
1 week ago
Bengaluru, Karnataka, India JPMorganChase Full time ₹ 20,00,000 - ₹ 25,00,000 per yearJOB DESCRIPTIONYour seniority as a security engineer puts you in the ranks of the top talent in your field. Play a critical role at one of the world's most iconic financial institutions where security is vital.As a Security Engineer III at JPMorgan Chase within the Cybersecurity & Tech Controls team, you serve as a seasoned member of a team that works to...
-
Security Platform Engineer Iii
4 weeks ago
Bengaluru, Karnataka, India Eli Lilly Full timeAt Lilly we unite caring with discovery to make life better for people around the world We are a global healthcare leader headquartered in Indianapolis Indiana Our employees around the world work to discover and bring life-changing medicines to those who need them improve the understanding and management of disease and give back to our communities...
-
Security Platform Engineer III
3 weeks ago
Bengaluru, India Eli Lilly Full timeAt Lilly, we unite caring with discovery to make life better for people around the world. We are a global healthcare leader headquartered in Indianapolis, Indiana. Our employees around the world work to discover and bring life-changing medicines to those who need them, improve the understanding and management of disease, and give back to our communities...
-
Security Platform Engineer III
7 days ago
Bengaluru, Karnataka, India Eli Lilly Full time ₹ 20,00,000 - ₹ 25,00,000 per yearAt Lilly, we unite caring with discovery to make life better for people around the world. We are a global healthcare leader headquartered in Indianapolis, Indiana. Our employees around the world work to discover and bring life-changing medicines to those who need them, improve the understanding and management of disease, and give back to our communities...
-
Security Platform Engineer III
6 days ago
Bengaluru, Karnataka, India Eli Lilly and Company Full time ₹ 1,04,000 - ₹ 1,30,878 per yearAt Lilly, we unite caring with discovery to make life better for people around the world. We are a global healthcare leader headquartered in Indianapolis, Indiana. Our employees around the world work to discover and bring life-changing medicines to those who need them, improve the understanding and management of disease, and give back to our communities...
-
Security Engineer
4 weeks ago
india Altered Security Full timeWe are looking for talentedSecurity Engineersto join our team!Altered Security is an information security startup with focus on edtech, hands-on learning and focused security assessments. It has offices in India and Singapore.We are experts in information security training, cyber ranges, online labs and security assessments. We have trained more than 40000+...
-
Security Engineer
4 days ago
india Altered Security Full timeWe are looking for Security Engineers with following qualities to join our team at Altered Security:- Passionate about information security. - Ability to solve challenges. - Interest in new attack vectors and creating challenges. - Demonstrated experience in Windows and Active Directory security. - If you hold CRTP certification, it is a plus.Who should...
-
Security Engineer
1 week ago
india Altered Security Full timeWe are looking forSecurity Engineerswith following qualities to join our team at Altered Security:Passionate about information security. Ability to solve challenges. Interest in new attack vectors and creating challenges. Demonstrated experience in Windows and Active Directory security. If you hold CRTP certification, it is a plus.Who should apply:Very good...
-
Software Engineer III- HCM Security
1 week ago
Bengaluru, Karnataka, India JPMorganChase Full time ₹ 20,00,000 - ₹ 25,00,000 per yearJOB DESCRIPTIONThere's nothing more exciting than being at the center of a rapidly growing field in technology and applying your skillsets to drive innovation and modernize the world's most complex and mission-critical systems.As a Software Engineer III at JPMorgan Chase within the Employee Platforms team, you will be at the forefront of designing and...
-
Software Engineer III- HCM Security
1 week ago
Bengaluru, India JPMorgan Chase & Co. Full timeThere’s nothing more exciting than being at the center of a rapidly growing field in technology and applying your skillsets to drive innovation and modernize the world's most complex and mission-critical systems. As a Software Engineer III at JPMorgan Chase within the Employee Platforms team, you will be at the forefront of designing and building security...