Web Application Security
1 month ago
Greetings from Netsach - A Cyber Security Company.
We are looking for Web Application Security consultant with minimum of 3+ years of relevant experience in an information security function with good background in information technology, stakeholder management and people management. Their primary purpose is to Design, Engineer & eventually Embed practical & balanced cyber / information security principles/patterns/controls into all products and platforms. Conduct security assessments, gap analysis, provide remediation to the relevant squads.
Job Title: Web Application Security
Exp: 3+yrs
Location: Dubai Onsite
Job Type: Full-Time
Interested candidates please share your updated resume at emily@netsach.co.in
Key Skills Web Application Security, Security Code review, API security, Underlying infrastructure security, Integration Security, Database Security, Secure Configuration Review.
Tools and Technologies Burp Suite, Postman, Tenable Nessus, Checkmarx SAST, GitHub and good knowledge about monolithic and microservice architecture and pipeline driven security.
Technical Requirement
- Web Application Security Owasp top 10 , CVSS etc
- Security Code Review manual code review in Git etc
- API Security Review Open shift, container review etc.
- Database Security Requirements to enhance security on Database
- Web Server Security Requirements to enhance security on the web server
- Configuration Review has performed different configuration reviews and should have found good misconfigurations in the system.
- Integration review How the application connects with different systems, performed security review on those integrations.
- Transport Layer Security How communication channels are secured and understanding of the Transport layer security mechanisms and controls.
Knowledge & Skill Set:
- Expert at the Web application Security testing, in depth testing skillset and ability to bypass weak implementation for attacks, ability to bypass WAF for attack scenarios such as XSS, SQL Injection etc.
- Good understanding of Microservice based architecture (Technical)
- Good hands-on experience solutioning technology architectures that involve perimeter protection, core protection and end-point protection/detection & API /Micro services Security
- Experience working in a DevOps environment with knowledge of Continuous Integration, Containers, DAST/SAST tools and building Evil Stories (Technical).
- The Analyst / Engineer should be able to understand how different systems work and what security controls are implemented in such integrations.
- The Analyst / Engineer should be capable in understanding the hardening standards, creating one if not available, and perform the testing against the hardening standards.
- The Analyst / Engineer should be capable of assessing security flaws in underlying infrastructure and the connected components.
- The Analyst / Engineer should be capable of assessing the security flaws in the Transport Layer.
- The Analyst / Engineer has the skill to follow design principles and applies design patterns to enforce maintainable and reusable patterns, in the form of code or otherwise.
- The Analyst / Engineer can understand and interpret potential issues found in source or compiled code.
- The Analyst / Engineer has automation skills/capability in the form of scripting or similar.
- The Analyst / Engineer can attack application and infrastructure assets, interpret threats, and suggest mitigating measures.
- Desirable Ability to interpret Security Requirements mandated by oversight functions and ensure comprehensive coverage of those requirements, via documentation, within high level design and/or during agile ceremonies, via Evil Stories.
- The Analyst / Engineer can propose options for solutions to the security requirements / patterns that provide a balance of security, user experience & performance.
- The Analyst / Engineer has the skill to discuss and present solutions to other architecture, security, development, and leadership teams.
- The Analyst / Engineer can interpret and understand vulnerability assessment reports and calculate inherent and/or residual risks based on the assessment of such reports.
- Ability to articulate and be a persuasive leader who can serve as an effective member of the senior management team.
- Good negotiation skills will be desirable.
- Must have good judgment skills to decide on an exception approval.
- Ability to enforce improvements when necessary, using Influence rather than Policing measures Superior written and verbal communication skills to effectively communicate security threats and recommendations to technical or non-technical stakeholders.
- Knowledge of application of Agile methodologies/principles such as Scrum or Kanban
Soft Skills:
- Ability to collaborate with multiple stakeholders and manage their expectations from a security perspective
- Holistic thinking; must balance security and functionality using practical demonstrable examples. Must also contribute to and implement good architecture principles to lower technical debt
- Assertive personality; should be able to hold her/his own in a project board or work group setting
- Superlative written and verbal communication skills; should be able to explain technical observations in an easy-to-understand manner.
- Ability to work under pressure and meet tough/challenging deadlines
- Influencer- must be able to convince various stakeholders (internal IT Teams, C-Level execs, Risk & Audit) of why a certain observation is a concern or not
- Strong understanding of Risk Management Framework and security controls implementation from an implementer standpoint
- Has strong decision making, planning and time management skills.
- Can work independently.
- Has a positive and constructive attitude
Education
Bachelors degree in a computer-related field such as computer science, cyber/information security discipline, physics, mathematics or similar
Certifications
- General Information Security: OSCP, CEH, CISM/CISA or similar
- General Cloud Security: CCSK /CCSP or similar
- Specific Cloud Security: Azure Security or similar
- Network Security: CCNA, CCNP, CCIE, Certified Kubernetes Security Specialist
Thank You
Emily Jha
emily@netsach.co.in
Netsach - A Cyber Security Company
www.netsach.co.in
-
RSA - Application Security Engineer
3 months ago
Bengaluru, India RSA Security Full timeRSA - Application Security Engineer (Location: Hybrid/ Remote India) RSA offers mission-driven security solutions that provide organizations with a unified approach to managing digital risk that hinges on integrated visibility, automated insights and coordinated actions. RSA solutions are designed to effectively detect and respond to advanced...
-
Senior Frontend Developer for Web Applications
3 weeks ago
Bengaluru, Karnataka, India Web Full timeCompany OverviewWeb LLP specializes in IT-based services and digital marketing, delivering unique strategies and development solutions to clients worldwide. Our approach focuses on understanding and adapting to each client's specific needs, enabling them to grow their business and improve customer service.Job OverviewWe are seeking an experienced Senior...
-
Web Application Security Expert
1 month ago
Bengaluru, India NETSACH GLOBAL Full timeGreetings from Netsach.We are looking for Web Application Security Expert for Dubai location as listed below. Must have minimum 3 years of experience in an information security function with good background in information technology, stakeholder management and people managementJob Title - Web Application Security ExpertExp- 4-5yrsJob Type- Full-timeNo of...
-
Senior Cloud Security Engineer
4 days ago
Bengaluru, Karnataka, India Tata Consultancy Services Full timeTata Consultancy Services is a leading IT services company with a strong presence in India.Salary: ₹1,200,000 per annum (estimated)Job DescriptionWe are seeking a Senior Cloud Security Engineer to join our team. As a key member of the security team, you will be responsible for ensuring the security of our cloud-based applications.Required Skills and...
-
Digital Security Architect
2 weeks ago
Bengaluru, Karnataka, India RSA Security Full timeJob SummaryWe are seeking a seasoned Digital Security Architect to join our team at RSA Security. As a key member of our security team, you will be responsible for designing and implementing secure software and product lifecycle management solutions.About the RoleThis is an exciting opportunity for a highly skilled professional with experience in penetration...
-
Bengaluru, Karnataka, India NETSACH GLOBAL Full timeWe are seeking a seasoned Information Security Consultant to join our team at Netsach Global. In this role, you will be responsible for designing and implementing practical and balanced cyber security principles into all products and platforms.The ideal candidate will have a minimum of 3+ years of relevant experience in an information security function with...
-
Cyber Security Engineer
1 month ago
Bengaluru, India RANDSTAD INDIA PVT LTD Full timeRoles & Responsibilities include : - Perform Enterprise Web Application Firewall (WAF) policy management, architecture, configuration, management, troubleshooting, optimization, governance, risk assessment and automation. - Perform Proxy policy operations and provide required support. - End to End life cycle of Web Application Firewalls (F5, Akamai,...
-
Security Engineer
1 month ago
Bengaluru, Karnataka, India RANDSTAD INDIA PVT LTD Full timeRole Overview As a seasoned Cybersecurity Engineer, you will be responsible for designing and implementing robust Web Application Firewall (WAF) solutions to protect our enterprise systems from evolving threats. Your expertise in configuring, operating, and managing forward and reverse proxies will be instrumental in ensuring the security and integrity of...
-
Application Security
6 months ago
Bengaluru, Karnataka, India iXceed Solutions Full time**Job title**: Java security Lead **Job Location**: Bangalore **Role Type**: Permanent **Work Mode**: Hybrid (2-3 days onsite in a week) - Java, Spring, Maven, REST, SOAP Web Services - OWASP Top 10, Secure Development - Knowledge of about Snyk tools - CI/CD tools and processes like Jenkins - Basics of cloud platforms and dockerization. - Good in Core...
-
Senior Web Security Specialist
3 weeks ago
Bengaluru, Karnataka, India NETSACH GLOBAL Full timeWe are seeking a skilled Senior Web Security Specialist to join our team at Netsach Global in Saudi Arabia.As a Senior Web Security Specialist, you will be responsible for performing manual application penetration testing of web-based applications, thick-client applications, mobile applications, web services, and APIs.The ideal candidate will have experience...
-
Application Security Consultant
2 weeks ago
Bengaluru, Karnataka, India Justdial Full timeJob OverviewWe are seeking an experienced Application Security Specialist to join our team at Justdial in Bangalore. As a key member of our security team, you will be responsible for providing security expertise for web and mobile projects, ensuring compliance with enterprise and IT security policies, industry regulations, and best practices.Key...
-
Frontend Web Developer Opportunity in Bengaluru
3 weeks ago
Bengaluru, Karnataka, India Web Full timeCompany Overview">Web LLP excels in delivering innovative IT-based services and digital marketing solutions. Our success stems from understanding and adapting to clients' unique needs, empowering them to enhance their business, customer service, and development process.">Job Opportunity">We are seeking a skilled Frontend Web Developer with 4-6 years of...
-
Application Security
2 weeks ago
Hyderabad / Secunderabad, Telangana, Bengaluru / Bangalore, India NXTEntry Full timeExperience with software security engineering practices, tooling, and risk assessments.• Strong technical skills in web related technologies (web applications, web services and Service Oriented Architectures), mobile (Android & IOS) and thick-client applications, APIs, and microservices.• Experience with creating threat models and conducting manual...
-
Node.js Developer
23 hours ago
Bengaluru, India Matrix HR technology Full timeResponsibilities :- Design, develop, and maintain backend APIs and microservices using Node.js and industry best practices.- Implement robust security measures to protect applications from vulnerabilities, including authentication, authorization, input validation, and data encryption (mention specific security practices relevant to your company if known).-...
-
Application Security Mobile Application
1 month ago
Bengaluru, India NETSACH GLOBAL Full timeGreetings from Netsach - A Cyber Security Company.We are looking for Mobile & Web Application security with minimum 4 years of experience in an information security function with good background in information technology, stakeholder management and people management Minimum 3 years of experience, as a Security Engineer especially in Cloud Native...
-
Application Security Architect
1 week ago
Bengaluru, India 7-Eleven Global Solution Center – India Full timeJob Summary:7-Eleven InfoSec is seeking a technically proficient Application Security Architect to lead and enhance the security posture of its applications and products. This role involves designing and implementing security solutions across modern application architectures, including Web application, APIs, microservices, and cloud-native platforms. The...
-
Application Security Testing/SAST
3 weeks ago
Bengaluru, India Tata Consultancy Services Full timeGreetings from Tata Consultancy Services!!!Job Role: Application security testing/SASTDesired Experience: 5 to 10 yearsLocation of Requirement - PAN IndiaJob description:Strong foundation in security domains such as web security, cloud services security, identity/access management, web application firewalls, intrusion detection, and static analysis and...
-
Application Security Engineer
6 months ago
Bengaluru, India SolarWinds Full timeAt SolarWinds, we’re a people-first company. Our purpose is to enrich the lives of the people we serve—including our employees, customers, shareholders, Partners, and communities. Join us in our mission to help customers accelerate business transformation with simple, powerful, and secure solutions. The ideal candidate thrives in an innovative,...
-
Senior Web Application Developer
6 months ago
Bengaluru, India Indusface Full timeCareers » Current Openings » Senior Web Application Developer Role: We are hiring web developers with strong skills in AngularJS, JavaScript, CSS, HTML, and experience in creating responsive user interfaces. If you want to be part of our engineering team in Bangalore that is building cutting-edge, award-winning Web application security products used...
-
Senior Web Application Developer
1 month ago
Bengaluru, Karnataka, India Indusface Full timeRole:We are seeking a skilled Full-Stack Web Engineer to join our engineering team in Bangalore. This is an exciting opportunity to work on cutting-edge, award-winning Web application security products used worldwide.Job Description:Develop modern, responsive front-end for the Indusface web application security products.Collaborate with Product Management,...