Application Security Engineer

Velocitai Digital
Posted on
Velocitai Digital logo

Experience
10 - 15 yrs
Job Location
Gurugram, India
Vacancy
1
Designation
Application Security Engineer
Job Type
Not specified

Job Description

Location: PAN India

Application Security:

Responsibilities Include:

  • Lead cross-functional, enterprise-wide projects and define the strategic direction for cutting-edge Software development lifecycle (SDLC) practices
  • Conduct security design reviews and sophisticated threat modeling for new and existing mission-critical services across the entire platform
  • Establish secure architecture standards, frameworks, and resilient security patterns spanning application, cloud-native, and infrastructure layers
  • Evaluate, prototype, implement, operate, and provide governance over core security tools and services (DAST, SAST, SCA, WAF, Secrets Management, Container Security etc.)
  • Discover and analyze emerging security threats, determining applicability to customer, and
    proactively implement centralized mitigations
  • Maintain a strong knowledge of current security threats and operational best practices
  • Drive our security assessment, penetration testing, and bug bounty programs translating findings into comprehensive, systemic risk reduction strategies.
  • Ensure all application security practices adhere to the Payment Card Industry Data Security Standard (PCI DSS) requirements
  • Participate in security incident response activities as a technical leader

In order to be successful in this role one must have:

  • Demonstrated technical foundation (Computer Science / Engineering degree or
    equivalent experience) with an innate ability to translate technical vulnerabilities into
    organizational risks
  • 10-15 years of technical security experience at a top-tier software company, including
    hands-on experience with threat modeling, security design, security architecture,
    cryptography, mobile security, cloud computing technologies, and security products
  • Expert understanding of common application and infrastructure security vulnerabilities and mitigations (OWASP Top 10, CWE 25 )
  • Deep, demonstrable knowledge of the e-commerce transaction lifecycle and expert command of PCI DSS compliance standards within a high-transaction environment.
  • Proven track record of driving the implementation of SDL processes, technology, and automation in sophisticated DevOps/DevSecOps environments.
  • Experience with large-scale web applications and microservices, including API design,
    access management, authorization, authentication, data protection and encryption
  • Knowledge of major programming languages and frameworks (e.g. Python, C# .NET,
    JavaScript, node.js, Java...)
  • Exceptional problem solving, critical thinking, collaboration and communication skills with the ability to influence technical and executive leadership

Bonus Qualifications:

  • Experience in an e-commerce or high-transaction environment, specifically with knowledge of PCI DSS compliance requirements
  • Experience with Cloudflare security, AWS VPCs, EC2 instances and Docker/containers
  • Experience driving application security training, security champions and awareness
    campaigns
  • Active contributor to the security community (research, open source, publications ) with the ability to attract and hire great talent
  • Relevant security certifications (e.g., OSCP, CISSP, CSSLP)

No Referrers Available

There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.