Your browser does not support javascript! Please enable it, otherwise web will not work for you.

Immediate Opportunity: Lead App Security @ Tollplus India

Home > Admin / Maintenance / Security / Datawarehousing

 Immediate Opportunity: Lead App Security

Job Description

Hello everyone,


We are looking for a dynamic Application Security Lead - who are inherently driven and fascinated by the art and science of security vision and strategy. We will equip you with the very best tools and tech so that you can deliver top notch results. As a Security Lead, you will be enthused by working on a wide-range of enterprise and customer-facing projects, as well as the chance to work with top notch professionals to learn with and from.

If you thrive in a dynamic, reciprocal workplace, Tollplus provides an environment to explore new opportunities every single day. And if you relish the freedom to bring creative, thoughtful solutions to the table, there's no limit to what you can accomplish here.

Please find the details below. If this interests you, please share your updated resume to sm****i@to*****s.com

Job Profile: Lead App Security Engineer

Experience: 7 - 15 Yrs

Location: Madhapur, Hyderabad


Job Responsibilities:

  • Align with and support the execution of the Information Security programs vision and strategy
  • Formalize and evangelize secure software development lifecycle practices (SSDLC)
  • Define security requirements within the SSDLC to communicate security requirements based on data classification.
  • Serve as a technical point of contact for product teams as it relates to automation, CI/CD, and Application Security Operations
  • Design and implement security features across a variety of application and OS platforms
  • Perform regular web and mobile application assessments to identify vulnerabilities and collaborate with stakeholders to remediate.
  • Perform regular reviews to ensure SSDLC is being followed
  • Define technical and functional requirements covering areas of software design, including microservice APIs, Cloud Services (Azure, AWS, etc.), and XaaS integration
  • Perform software reviews, analyze security flaws and risks, and influence product designs.
  • Perform formal threat model analysis on multiple client and server-side software programs.
  • Work with validation teams to determine best methods to test product security. Familiar with penetration testing and in some cases, can design and perform your own penetration tests.
  • Investigate reported security incidents on our software and act as the communication point for executive updates in those situations.
  • The role requires a practical view of the trade-offs of security and needs to be able to find acceptable compromises in terms of cost, schedule, and features.
  • Serve as an information security subject matter expert and trusted advisor by providing advisory and consulting services as required
  • Understand current and emerging security threats and partner with architecture to mitigate threats
  • Stay abreast of new security technologies and integrate into security design when appropriate

Skill set:

  • Bachelors degree in Computer Science or related field, or demonstrated equivalent experience required
  • 3-5 years of experience in software development and/or design.
  • 2-3 years of experience in application security and/or leading secure coding development
  • Coding experience with .NET, Java, JavaScript, and/or Python experience required. Windows development experience required. This role requires the ability to identify code security flaws across multiple platforms.
  • Experience designing and implementing Container Security, API Security, and Azure Cloud Security.
  • Strong knowledge of Containerization technologies such as; Kubernetes, OpenShift, Docker
  • Experience in encryption and authentication methodologies.
  • Experience reviewing vulnerability assessments and code security reviews.
  • Experience with security technologies and assessment tools.
  • Deep understanding of OWASP Top 20, CWE 25, Data Protection
  • Basic familiarity with waterfall and agile development processes and have experience integrating secure development practices into both models.
  • Deep knowledge and experience in using SAST, DAST and fuzz testing tools
  • Basic understanding of application, network, operating system, and core infrastructure security concepts and concerns
  • Understanding of emerging technologies in IT such as a Cloud Platform and Mobile BYOD as well as the associated security risks
  • Certification or willingness to attain certification within 18 months, CISSP or CSSLP certifications preferred.
  • Strong analytical and problem-solving skills.
  • Ability to meet established deadlines; must be a self-starter and be able to work independently as well as being a team player
  • Excellent communication and presentation skills, with the ability to present ideas in a collaborative team setting and in a user-friendly language
  • Ability to multitask
  • Must be able to react quickly and efficiently to production issues
  • Strong facilitation skills and a clear ability to build strong relationships with business stakeholders at all levels, including senior managers and suppliers
  • Energy and a clear passion for the role
  • Demonstrated personal values aligned with our servant leadership tenants

Regards,

Sharanya Meneni

Technical Recruiter
Email ID: sm****i@to*****s.com

Tollplus India Pvt Ltd

Job Classification

Industry: IT-Software, Software Services
Functional Area: IT Software - Application Programming, Maintenance,
Role Category: Admin/Maintenance/Security/Datawarehousing
Role: Admin/Maintenance/Security/Datawarehousing
Employement Type: Full time

Education

Under Graduation: Any Graduate in Any Specialization
Post Graduation: Post Graduation Not Required, Any Postgraduate in Any Specialization
Doctorate: Any Doctorate in Any Specialization, Doctorate Not Required

Contact Details:

Company: Tollplus India
Address: PLOT NO.45, NEAR JUBILEE RIDGE HOTEL, KAVURI HILLS, MADHAPUR, Hyderabad, Telangana, 500081, Hyderabad, Telangana, India
Location(s): Hyderabad

+ View Contactajax loader


Keyskills:   Software Development Life Cycle Java Application Security Web Technologies Penetration Testing OWASP Information Security Javascript Secure Coding .Net

 Job seems aged, it may have been expired!
 Fraud Alert to job seekers!

₹ Not Disclosed

Tollplus India

Company ProfileTollplusTollPlus is a software company founded by a highly-experienced group of software professionals developing sophisticated End-to-End Toll Road Management solutions to address the challenges in the Electronic Toll Collection (ETC) sector in North America, and other markets in t...