Experience
10 - 15 yrs
Job Location
Gurugram, India
Vacancy
1
Designation
Application Security Engineer
Job Type
Not specified
Job Description
Location: PAN India
Application Security:
Responsibilities Include:
- Lead cross-functional, enterprise-wide projects and define the strategic direction for cutting-edge Software development lifecycle (SDLC) practices
- Conduct security design reviews and sophisticated threat modeling for new and existing mission-critical services across the entire platform
- Establish secure architecture standards, frameworks, and resilient security patterns spanning application, cloud-native, and infrastructure layers
- Evaluate, prototype, implement, operate, and provide governance over core security tools and services (DAST, SAST, SCA, WAF, Secrets Management, Container Security etc.)
- Discover and analyze emerging security threats, determining applicability to customer, and
proactively implement centralized mitigations - Maintain a strong knowledge of current security threats and operational best practices
- Drive our security assessment, penetration testing, and bug bounty programs translating findings into comprehensive, systemic risk reduction strategies.
- Ensure all application security practices adhere to the Payment Card Industry Data Security Standard (PCI DSS) requirements
- Participate in security incident response activities as a technical leader
In order to be successful in this role one must have:
- Demonstrated technical foundation (Computer Science / Engineering degree or
equivalent experience) with an innate ability to translate technical vulnerabilities into
organizational risks - 10-15 years of technical security experience at a top-tier software company, including
hands-on experience with threat modeling, security design, security architecture,
cryptography, mobile security, cloud computing technologies, and security products - Expert understanding of common application and infrastructure security vulnerabilities and mitigations (OWASP Top 10, CWE 25 )
- Deep, demonstrable knowledge of the e-commerce transaction lifecycle and expert command of PCI DSS compliance standards within a high-transaction environment.
- Proven track record of driving the implementation of SDL processes, technology, and automation in sophisticated DevOps/DevSecOps environments.
- Experience with large-scale web applications and microservices, including API design,
access management, authorization, authentication, data protection and encryption - Knowledge of major programming languages and frameworks (e.g. Python, C# .NET,
JavaScript, node.js, Java...) - Exceptional problem solving, critical thinking, collaboration and communication skills with the ability to influence technical and executive leadership
Bonus Qualifications:
- Experience in an e-commerce or high-transaction environment, specifically with knowledge of PCI DSS compliance requirements
- Experience with Cloudflare security, AWS VPCs, EC2 instances and Docker/containers
- Experience driving application security training, security champions and awareness
campaigns - Active contributor to the security community (research, open source, publications ) with the ability to attract and hire great talent
- Relevant security certifications (e.g., OSCP, CISSP, CSSLP)
No Referrers Available
There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.
