Staff Application Security Engineer
Bangalore, India (Bagmane)
Ivanti
Ivanti finds, heals and protects every device, everywhere – automatically – so employees can work better from anywhere.Who We Are:
In today’s work environment, employees use a myriad of devices to access IT applications and data over multiple networks to stay productive, wherever and however they work. Ivanti elevates and secures Everywhere Work so that people and organizations can thrive.
While our headquarters is in the U.S., half of our employees and customers are outside the country. We have 36 offices in 23 nations, with significant offices in London, Frankfurt, Paris, Sydney, Shanghai, Singapore, and other major cities around the world.
Ivanti’s mission is to be a global technology leader enabling organizations to elevate Everywhere Work, automating tasks that discover, manage, secure, and service all their IT assets. Through diverse and inclusive hiring, decision-making, and commitment to our employees and partners, we will continue to build and deliver world-class solutions for our customers.
Our Culture - Everywhere Work Centered Around You
At Ivanti, our success begins with our people. This is why we embrace Everywhere Work across the globe, where Ivantians and our customers are thriving. We believe in a healthy work-life blend and act on it by fostering a culture where all perspectives are heard, respected, and valued. Through Ivanti’s Centered Around You approach, our employees benefit from programs focused on their professional development and career growth.
We align through our core values by locking arms in collaboration, being champions for our customers, focusing on the outcomes that matter most and fighting the good fight against cyber-attacks. Are you ready to join us on the journey to elevate Everywhere Work?
Why We Need you!
As an Application Security Engineer within our Product Security team, you will be responsible for designing, implementing and managing security posture to protect Ivanti’s products against emerging threats.
As a technical leader, you will collaborate with various teams to integrate security best practices into all aspects of our product operations, ensuring compliance with industry standards and regulatory requirements. Your proactive approach to security will help us build a robust defence mechanisms to maintain trust of our customers.
What You Will Be Doing:
- Develop both broad and deep technical understanding of Ivanti products, services and architectures
- Conduct security assessments such as threat modelling, secure architecture, code reviews and penetration tests on web and mobile applications and services
- Interpret security vulnerability reports to stakeholders, providing advice on vulnerability prioritization, remediation and mitigation
- Closely coordinate with all stakeholders to bake in security into all phases of SDLC
- Create and maintain documentation for security processes
- Deliver accurate metrics to stakeholders and business leaders in a clear and concise manner
- Maintain high proficiency in relevant security topics (latest vulnerabilities, TTPs, exploits, etc.)
- Create and deliver security education across the organization
- Develop innovative and scalable tools, solutions and processes to enhance product security operations
- Support accurate security tooling implementation to maximize their effectiveness and interpret their results to relevant stakeholders
To Be Successful in The Role, You Will Have:
- 8+ years of experience in Application Security roles
- Have proven experience in application, API, database and infrastructure security topics
- Have strong technical knowledge on security vulnerabilities, defense techniques and security best practices
- Ability to explain vulnerabilities in a precise, concise and easy to understand manner to stakeholders of varying security and technical backgrounds
- Experience in performing Threat Modelling and providing actionable advise from its results
- High level of experience in scoring security vulnerability severities through CVSS
- Good understanding of SSDLC as well as development and integration tools and technologies uses as part of CI/CD pipelines
- Experience providing secure coding education to developers
- Know how to go beyond generic security vulnerability remediation advice
- Have good understanding of one or more major cloud providers (Azure, AWS, GCP)
- Have experience in authentication and authorization standards and protocols (SAML, Oauth, LDAP, AD, etc.)
- Practical knowledge of applied cryptography and common attacks against modern cryptographic algorithms (encryption at rest, TLS, hashing, etc.)
- Can read and write code with ease
- Ability to work in a self-directed environment that is highly collaborative and cross functional
- Passion and self-drive for researching vulnerabilities and latest exploitation techniques
This job posting will remain active until a qualified candidate is identified.
At Ivanti, we are committed to providing an environment of mutual respect where equal employment opportunities are available to all applicants and teammates without regard to race, color, religion, sex, pregnancy (including childbirth, lactation and related medical conditions), national origin, age, physical and mental disability, marital status, sexual orientation, gender identity, gender expression, genetic information (including characteristics and testing), military and veteran status, and any other characteristic protected by applicable law. Ivanti believes that diversity and inclusion among our teammates is critical to our success as a global company, and we seek to recruit, develop and retain the most talented people from a diverse candidate pool.
#L1-SHUBHANGI
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: APIs Application security AWS Azure CI/CD Cloud Compliance Cryptography CVSS Encryption Exploits GCP Hashing LDAP Product security SAML SDLC Security assessment SSDLC TLS TTPs Vulnerabilities
Perks/benefits: Career development Startup environment
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.