Application Controls Security Principal

7 days ago


Mumbai Maharashtra, India LyondellBasell Industries Full time

Location: Mumbai, IN, 400076- Req ID: 86643- Facility: Mumbai-470- Department: Strategic Services- Division: Innovation**Basic Function**:
An Application Controls Principal plays a vital role in managing the complex organization, execution, and optimization of the organization's SAP and non-SAP security controls.

An Application Controls Principal must lead a team that has primary responsibility for end-to-end controls monitoring, validation, quality assurance, and improvement activities. In addition to the Application Controls Principal leading a dedicated IT Operations-based team, this role must act as a primary point of contact for all IT controls activities and be accountable to the Internal Controls, Governance/Risk/Compliance, Audit departments, and Senior Leadership.

This role will develop long-term strategies in partnership with Control Owners for controls execution and prioritize the team’s activities to ensure zero deficiencies in internal and external testing scenarios. This role will have ultimate responsibility for the remediation of areas of risk and is responsible for communicating status of IT controls, audit findings, remediation efforts, and long-term plans to senior leadership on a recurring basis.

This role requires intensive collaboration to ensure successful execution of all continuous and periodic control activities.

**Roles & Responsibilities**:

- Accountable for the IT controls program direction and influence, including overarching IT controls approach (defining controls, rewriting as necessary, launching renewed IT controls execution, etc.).
- Accountable for aligning non-SAP and SAP controls approach, harmonizing control automations, process efficiencies, and overall controls simplicity.
- Oversee the development of systems and integrations to drive greater automation and remove areas of human error.
- Act as Subject Matter Expert on all IT controls with internal and external auditors during IT audits.
- Regularly assess the program for effectiveness - continuously monitor defined metrics and indicators and quickly adapt to changing requirements.
- Prepare regular reports on team outcomes and initiatives for senior leadership or enterprise-wide distribution.
- Review existing processes and product architectures for IT control security design gaps and vulnerabilities and consult with product teams and cyber security to remediate or mitigate cyber risk.
- Provide strategic oversight to remediations proposed, influencing the technical direction of IT controls improvements.
- Provide strategic leadership and creative thinking to help various technical delivery teams through the project lifecycle.

**Min. Qualifications**:

- Bachelor's degree in Information Technology, Computer Science, or a related field (preferred).
- 7+ years of experience in IT security controls analysis, IT audit, or a similar role.
- Expert knowledge of IT security controls and best practices (data validation, authorization, encryption, audit logging, etc.).
- Proven experience in identifying, analyzing, and remediating non-SAP control deficiencies.
- In-depth understanding of security concepts, including authorization, segregation of duties, and user access review management
- Experience with tools such as ServiceNow or security tools and technologies used for control monitoring and analysis
- Understanding of cloud security concepts and technologies and on-prem technologies
- SOX knowledge, in addition to experience of implementing/auditing against US SOx IT framework control.
- 3 years of experience supporting software security governance and compliance activities, i.e. metrics, assessments, audits, exercises, risk frameworks, and maturity models
- Experience leading a team of resources and prioritizing complex activities and outcomes
- Identity and Access Management exposure
- Application Security Principles and Best Practices exposure
- Security Tools and Technologies exposure
- Application cloud and on prem logic and data layer architecture, inc SQL, Oracle and Azure.

**Desired Skills**:

- Experience with security automation tools and scripting languages (e.g., Python, PowerShell).
- Experience with SharePoint and project management tools.
- Familiarity with GAAP and financial reporting.

**Soft Skills**
- Prioritization of complex activities
- Process improvement mindset
- Clear and effective communication, verbal and written
- Effective leadership and coordination
- Detailed and systematic thinking
- Detailed troubleshooting skills
- Issue resolution and risk mitigation
- Commitment to follow standards

**Preferred Qualifications**:
**Competencies**:

- Build Partnerships
- Deliver Results
- Drive Innovation
- Grow Capabilities
- Promote Inclusion
- Motivational/Cultural Fit
- Technical Skills



  • Mumbai, Maharashtra, India Security Lit Full time ₹ 15,00,000 - ₹ 25,00,000 per year

    Job Description: Application Security Engineer (L2)Role OverviewWe are seeking an experienced Application Security Engineer (L2) to take a lead role in our security testing team. This role requires of 3 year experience (first priority will be given to more than 4 year experience resources for selection) and mandates professional security certifications. You...


  • Mumbai, Maharashtra, India Security Lit Full time ₹ 8,00,000 - ₹ 12,00,000 per year

    Job Description: Application Security Engineer (L1)Role OverviewWe are looking for an Application Security Engineer (L1) to join our security team. This is an entry-level position requiring at least 1 year of hands-on experience in application security testing. You will work on identifying and reporting vulnerabilities across web, mobile, API, and thick...


  • Mumbai, Maharashtra, India BNP Paribas Full time

    APPLICATION SECURITY (JOB NUMBER: CIB120124) About BNP Paribas India Solutions: Established in 2005, BNP Paribas India Solutions is a wholly owned subsidiary of BNP Paribas SA, European Union’s leading bank with an international reach. With delivery centers located in Bengaluru, Chennai and Mumbai, we are a 24x7 global delivery center. India Solutions...


  • Mumbai, Maharashtra, India Cornerstone OnDemand Full time

    We re looking for a Principal Security Engineer This role is Office Based Principal Security Engineer - India - Cybersecurity Engineering The Principal Security Engineer is a hands-on role that blends cloud security engineering with security operations and threat intelligence This position plays an integral role in protecting Cornerstone OnDemand from...


  • Mumbai, Maharashtra, India Zorba Consulting Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Description : As a Principal Security Engineer, you will be the ultimate owner of our application and cloud security posture. You will drive the implementation of security-by-design principles across all engineering teams, performing code reviews, architecture assessments, and leading incident response for critical vulnerabilities. This is a...


  • Mumbai, India LogiNext Full time

    LogiNext is looking for a Principal Engineer - Security to join our team! As a Principal Engineer - Security, you'll lead the effort to design, implement, operate, support, and maintain the security infrastructure and supporting tools that are necessary to protect internal and external assets on networks that support our corporate infrastructure and...

  • Application Security

    2 weeks ago


    Mumbai, India Skillventory Full time

    **Application Security**: - From 2 to 7 year(s) of experience - ₹ Not Disclosed by Recruiter - Mumbaior **Roles and Responsibilities** Hiring for a Leading Private Bank**Responsibilties: - ** - Strong understanding of OWASP TOP 10, SANS25, Open Source Security Testing Methodology. - Manual (OSSTMM) methodologies and tools. - Familiar with...


  • Mumbai, Maharashtra, India Johnson Controls Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Build your best future with the Johnson Controls teamAs a global leader in smart, healthy and sustainable buildings, our mission is to reimagine the performance of buildings to serve people, places and the planet. Join a winning team that enables you to build your best future Our teams are uniquely positioned to support a multitude of industries across the...


  • Mumbai, Maharashtra, India Johnson Controls Full time ₹ 12,00,000 - ₹ 24,00,000 per year

    Build your best future with the Johnson Controls teamAs a global leader in smart, healthy and sustainable buildings, our mission is to reimagine the performance of buildings to serve people, places and the planet. Join a winning team that enables you to build your best future Our teams are uniquely positioned to support a multitude of industries across the...


  • Pune, Maharashtra, India Principal Financial Full time

    Responsibilities Software Development Experience Looking for candidates from development teams who have 7-9 years - 1 3-5 yrs in software development experience using languages like Java Python Net C JavaScript or Typescript SAST SCA Experience Must have 4-5 yrs experience with Secure Code Reviews Required Hands-on experience in using enterprise code SAST...