Application Security Architect

3 days ago


Bengaluru, India YASH Technologies Full time

Role: Application Security Architect This role is responsible for architecting, designing security controls for applications. The successful candidate will lead efforts to establish and improve secure Software development lifecycle (SDLC) activities and identify tools to integrate into the development process to assess the security of applications. When appropriate, this role will define test plan, perform manual security testing of application components, like APIs to ensure they meet all applicable application security standards,. When security flaws/vulnerabilities are identified this role will work with development teams, offer technical expertise to fix identified issue. You will also lead efforts to create an appropriate application security standard based on industry benchmarks such as OWASP,SANS etc,Typical DayAct as application security expert, liaison for BU and other relevant team members with cybersecurity teams. Be a leader to drive large scale application security requirements. Review application services from a security standpoint, create security baseline controls, conduct code reviews, software composition analysis (SCA) as required. Create test criteria relevant to security controls defined, prepare test plans and guide junior team members to test the services – APIs, Custom-developed applications.Develop and execute project plans to ensure enterprise cybersecurity initiatives are delivered as per schedule. Work with business/IT leaders to plan the project, communicate the project status. Develop metrics and dashboards to provide visibility to cybersecurity risks for IT and business partner organizations.Required technical skills :MUST have good understanding of application security standards, secure coding practicesHands-on experience in multiple application development technologies such as java,.Net, Ruby, python etc.,Good knowledge of customizing security frameworksUnderstanding of engineering applications, infrastructure and software development processKnowledge of securing web applications and interfaces against common vulnerabilitiesExperience in performing code reviews, security scans, applying patches, remediating vulnerabilities and code reviewsDeep understanding of docker, Kubernetes, Micro service , SaaS, PaaS, On-prem Client-server architecture and web technologiesExperience in supporting Agile teamsHands-on experience in JIRA or similar platformsExperience defining and executing a Secure Software Development LifecycleKnowledge of securing applications using SAML and OAuthKnowledge of commonly used DAST and SAST tools for testing security vulnerabilitiesWorking knowledge Common Vulnerability Scoring System (CVSS)Understanding of Open Web Application Security Project (OWASP) Security FrameworkExperienced with security testing methodologies – Vulnerability assessment and Penetration TestingSoft Skills Required:Good communicator with sound understanding of software release cycle.Able to lead a team of application security experts.Collaborate with other technical experts and business partners to explain the risk/gap and discuss recommendations to secure the application/API.Able to communicate with peers and leaders in a verbal or written manner that is professional and concise.Ability to manage small/medium projects with relation to risk mitigation and rolling out security initiatives across the division.Add/build additional capacity and Appsec capabilities as required.Tool exposure:Experience in DAST and SAST tools such as WebInspect, Acunetix, Burp Suite Pro, AppScan, Netsparker, HP Fortify, Checkmarx, Qualys, Rapid7, etcExperience in Jira, ConfluencePreferred certifications :OWASP CertifiedEducation:Bachelor's degree in computer science or equivalent. 10-14 years’ experience required.



  • Bengaluru, India Intraedge Technologies Ltd. Full time

    Job Description : AppSec Architect (AWS)Experience : 7+ YearsLocation : Bangalore / Gurugram / NoidaPosition Overview : We are seeking an experienced Application Security Architect (AWS) to design and implement secure application architectures for AWS-hosted services and applications.The ideal candidate will have deep expertise in application security,...


  • Bengaluru, India TekDoors Inc. Full time

    Job Title: Application Security Architect (AWS focused) Location: Bangalore, Karnataka, India Type: Full Time Primary Focus-AWS Apps Arch- Dev. background Python/Java/Go Lang, Designing, Cloud Native Exp would be required, AWS Security services (MS,VPC),CICD Awareness. Qualifications: • 8+ years in application security, software engineering, or security...


  • Bengaluru, India owow Full time

    Primary Focus- AWS Apps Arch- Dev. background Python/Java/Go Lang,Designing,Cloud Native Exp would be required,AWS Security services (MS,VPC),CICD Awareness. Design and implement application security architecture for AWS-hosted services and applications. Ensures secure-by-design initiatives across SDLC, including threat modeling, risk assessments, and...


  • Greater Bengaluru Area, IN YASH Technologies Full time

    Role: Application Security Architect This role is responsible for architecting, designing security controls for applications. The successful candidate will lead efforts to establish and improve secure Software development lifecycle (SDLC) activities and identify tools to integrate into the development process to assess the security of applications. When...


  • Greater Bengaluru Area, India YASH Technologies Full time

    Role: Application Security Architect This role is responsible for architecting, designing security controls for applications. The successful candidate will lead efforts to establish and improve secure Software development lifecycle (SDLC) activities and identify tools to integrate into the development process to assess the security of applications. When...


  • Greater Bengaluru Area, India YASH Technologies Full time

    Role: Application Security Architect This role is responsible for architecting, designing security controls for applications. The successful candidate will lead efforts to establish and improve secure Software development lifecycle (SDLC) activities and identify tools to integrate into the development process to assess the security of applications. When...


  • Bengaluru, India RSA Security Full time

    Product Overview Outseer Fraud Manager is an advanced, omnichannel fraud detection hub that provides risk-based, multi-factor authentication for organizations seeking to protect their consumers from fraud across digital channels. Powered by the AI/ML based Risk Engine, Outseer Fraud Manager is designed to measure the risk associated with a user’s login...


  • Bengaluru, India RSA Security Full time

    Product Overview Outseer Fraud Manager is an advanced, omnichannel fraud detection hub that provides risk-based, multi-factor authentication for organizations seeking to protect their consumers from fraud across digital channels. Powered by the AI/ML based Risk Engine, Outseer Fraud Manager is designed to measure the risk associated with a user’s login...


  • Bengaluru, India Resmed Full time

    Let's talk about the team At Resmed, the Enterprise Security team safeguards the systems, data, and technologies that enable our mission to improve lives through connected health. We collaborate across engineering, data science, enterprise architecture and business units to embed security in everything we build. Let's talk about the role We are seeking an...


  • Bengaluru, India ResMed Full time

    The Information Technology (IT) team plays a key role in providing business enablement throughout ResMed. We are focused on application, infrastructure, and user productivity solutions, with innovation, efficiency and security. Our goal is providing customer oriented agile delivery, effective business partnership and state-of-the-art technology solutions....