Associate Architect - Product Security

Trivandrum, Kerala, India

āš ļø We'll shut down after Aug 1st - try foošŸ¦ for all jobs in tech āš ļø

Envestnet

Explore our connected ecosystem of solutions, intelligence, and technologies that connect people’s daily lives with their long-term goals. See how we’re equipping advisors with the tools and resources needed to deliver the most impactful...

View all jobs at Envestnet

Apply now Apply later

  • Responsibilities

    • Define and enforce secure coding standards and best practices.
    • Perform threat modeling, security architecture reviews, and code analysis.Ā 
    • Design and implement secure CI/CD pipelines with integrated security controls.Ā 
    • Automate security testing (SAST, DAST, IAST, SCA, container scanning) in SDLC process.Ā 
    • Evaluate and integrate security tools and platformsĀ Ā 
    • Lead DevSecOps program in collaboration with DevOps, Operations and Engineering teamsĀ 
    • Build automation focused on efficiency (E.g. increase triaging efficiency, manage false positives etc.)Ā 
    • Leverage ASPM and build workflows and reportsĀ Ā 
    • Evaluate and integrate security tools and platformsĀ 
    • Implement Infrastructure as Code (IaC) security and cloud-native security controls.Ā 
    • Monitor and respond to security incidents in development and production environments.Ā 
    • Collaborate with development teams to remediate vulnerabilities and design secure applications.Ā 
    • Develop and deliver secure coding training and awareness programs.Ā 
    • Stay current with emerging threats, vulnerabilities, and security technologies.Ā 
    • Ensure compliance with industry standards (e.g., OWASP, NIST etc). Ā Ā 
RequirementsĀ 
    • Overall 10+ years of experience in application security, software development, or related roles.Ā 
    • 6+ years of work experience in Application security, preferably in a fintech or financial services domainĀ Ā 
    • Strong understanding of web, mobile, API and cloud application architectures.Ā 
    • Experience of code reviewing or code contributing in Java, Java Script, .Net. C#, Python, or IaC scripting.Ā 
    • Hands-on experiences running SCA, SAST, DAST, IAST, SBOM, ASPM, Apigee, WAF etc., with approaches or optimizations for the tools to efficiently enforce the enterprise S-SDLC policies.Ā 
    • Deep understanding of DevSecOps practices and experience in CI/CD automation forĀ  one of the popular platforms, such as Gitlab, GitHub or Azure DevOps.Ā 
    • Knowledge of cloud platforms (AWS, Azure) and container orchestration (Kubernetes, Docker).Ā 
    • Perspective of supporting developer tools as a security professional (E.g. integrating security tools with IDE, PR checks etc.)Ā 
    • The experiences in building security controls for a system that follows NIST CSF and SSDF frameworks andĀ  performing the risk-based security reviews that meet the OWASP, SOC2, GDPR requirements.Ā Ā 
    • Ability to identify and summarize practical operational procedures, write standards or SOPs, and provide security scan reports.Ā 
    • A good understanding of full stack software development and best practices for developing software (version control, branching, automation, IaC, documentation, testing, etc.)Ā Ā 
    • Ability to collaborate cross-functionally and communicate effectively with highly technical teams and provide written assessment reports as needed.Ā 
    • Certifications such as CSSLP, OSWE, or CEH.Ā 
    Ā 
Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index šŸ’°

Job stats:  1  0  0
Category: Architecture Jobs

Tags: APIs Application security Automation AWS Azure C CEH CI/CD Cloud Code analysis Compliance CSSLP DAST DevOps DevSecOps Docker FinTech Full stack GDPR GitHub GitLab IAST Java Kubernetes NIST OSWE OWASP Product security Python SAST SBOM Scripting SDLC SOC 2 Vulnerabilities

Region: Asia/Pacific
Country: India

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.