The Solution Security Architect will focus on application security with a primary focus on architecting enterprise level cloud and web application. This position would be part of the Application security COE team that ensures the confidentiality, availability, and integrity of data by applying cloud security services, security design principles to design, developing, testing Devops and deploying huge Enterprise level Web & cloud applications. The software application security architect will lead efforts to establish long-term information security architectural direction, establish standards, create secure coding guidelines, teach developers and establish secure application development checks and balances within the SDLC.
Competencies:
list of 37 items
Using security and cloud expertise to design software strategy at FAI
Developing applications that are aligned to the domain and the business
Bringing a perspective of the best practices being followed in the industry
Demonstrates the qualities of "Practitioner"
Developing a Master Data Management Strategy
Defining the data security standards
Guiding the teams on Data Architecture
Supporting and driving organization's technology initiatives both at an individual level and as a team
Applying industry standard practices and mentor different teams as necessary
Resolving problems and identifying opportunities for improvement across the architecture job family
Supporting creation of thought leadership (POVs, research papers) across the architecture job family
Guiding teams on the Infrastructure architecture concepts
Resolving problems and identifying opportunities for improvement across knowledge areas
Guiding teams in the Devops architecture framework
Defining standards and applying industry best practices
Resolving problems and identifying opportunities for improvement across knowledge areas
Assessing and diagnosing issues relating to the Enterprise architecture frameworks
Determining preliminary solutions to identified issues and gaps
Creating the product charter for the project to clearly list out project objectives, duration, milestones, etc.
Identifying risks across the project life-cycle and conceive mitigation strategies
Creating program plans spanning across multiple projects modules to drive overall program effectiveness in terms of quality, cost and time
Measuring program performance against target and publish dashboards to leadership
Measuring program performance against target and publish dashboards to leadership
list end
Technical Skills:
Working/coding knowledge of MS Development platform, Javascript Frameworks and various Web technologies and cloud application
Set up security policies that help personnel use best practices for digital protection on cloud and web applications.
Work with the board of directors and important stake-holders on the roadmap of security of the applications, recommend best tools and practices in the industry
Secure Software Concepts - security implications in software design, development, testing, deployment etc.
Responsible for developing security code snippets/model/examples for development and testing team
Establish Secure Software Requirements - capturing security requirements in the requirements gathering phase
Secure Software Design - translating security requirements into application design elements
Secure Software Implementation/Coding - unit testing for security functionality and resiliency to attack, and developing secure code and exploit mitigation
Secure Software Testing - integrated QA testing for security functionality and resiliency to attack, including penetration testing and risk assessment
Software Acceptance - Perform code reviews to ensure standards are adhered to and vulnerabilities are addressed.
Establish Standards for Software Deployment, Operations, Maintenance and Disposal - security issues around steady state operations and management of software.
Perform risk assessment across the entire network including hardware and software systems
Ability to clearly present secure software concepts to development groups showing the risks and remediation strategies.
Ability to explain and demonstrate exploitation of developed software vulnerabilities.
Experience with Software Vulnerability Assessment Tools
Educational Qualification and Experience:
Minimum of 15 years of formal education - Graduate / Post Graduate in Computer Science / Information Technology
Professional work experience of 14 years and above in Cloud security services, Microsoft or cross platform web application technologies with a focussed 6+ years of experience in security domain.
Keyskills: QA Testing Application Security Penetration Testing Web Technologies OWASP Software Testing Information Security Secure Coding SDLC Javascript Frameworks
First American (India) is a Global In-house Center (GIC) of the First American Financial Corporation (NYSE: FAF) family of companies. First American Financial Corporation provides comprehensive title insurance, closing/settlement, property data and technology solutions. First American (India...