Lead Engineer - Product Security
Trivandrum, Kerala, India
Envestnet
Explore our connected ecosystem of solutions, intelligence, and technologies that connect people’s daily lives with their long-term goals. See how we’re equipping advisors with the tools and resources needed to deliver the most impactful...
Role Summary
- Responsible to ensure the implementation of security standards and compliance practices in various SDLC phases.
- Lead and mentor the team, collaborate with onsite and offshore teams to implement and ensure application security standards and practices.
- Perform various application security audits, tests and assessments to ensure security complaince within SLA.
- Review the application features and enhancement design, perform code review and provide security specific recommendations and best practises in each SDLC phase.
- Perform penetration test on web applications, identify the vulnerabilities, report security issues, suggest remediation measures and guide the development team to resolve the issue.
- Execute automated scan on web applications using various SAST and DAST tools, triage the issues, identify true positives and work with the development team for resolution.
- Collaborate with development team to review, recommend and consult on security concerns and set secure architecture standards.
- Perform security controls assessments, recommend and update application security policies and procedures to keep up with the security trends and changing internal and external requirements.
- Perform domain audits with help of OSNIT tools.
- Collaborate with clients and third parties, provide technical support for penetration tests and audit of the products.
- Review, evaluate and recommend security best practices for AWS cloud specific implementations of SDLC.
- Analyse, review and suggest new application installations, test various features and fuctionalities and collaborate with IT helpdesk team through the process of application whitelisting.
- Design and implement application and web-based security trainings across the organization.
- Develop tools to automate security testing, design and implement strategies to enhance the efficiency of secuity bug discovery and resolution.
- Lead and mentor the team, provide technical and non-technical guidance for their overall development.
- Lead the vulnerabiility management by collaborating with development leads, managers to ensure vulnerabalities are remediated within SLA.
Exposure and Experience
- Minimum 8 years experience in web application security.
- Expert knowledge in Software Development Life Cycle.
- Experience in Security Controls Assessment, Vulnerbility Management, Penetration Testing and Application Whitelisting.
- Domain knowledge on Investment Banking/Wealth Management would be an added advantage.
- Education: BTech/ MCA
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Job stats:
3
1
0
Categories:
Leadership Jobs
Security Engineering Jobs
Tags: Application security Audits AWS Banking Cloud Compliance DAST Pentesting Product security SAST SDLC Vulnerabilities
Region:
Asia/Pacific
Country:
India
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Senior Security Analyst jobsInformation System Security Officer jobsSenior Cloud Security Engineer jobsSenior Cybersecurity Engineer jobsInformation Security Specialist jobsInformation Security Manager jobsSenior Network Security Engineer jobsSecurity Consultant jobsCyber Security Specialist jobsIT Security Engineer jobsSecurity Specialist jobsSenior Information Security Analyst jobsSenior Penetration Tester jobsIT Security Analyst jobsSenior Cyber Security Engineer jobsSystems Engineer jobsChief Information Security Officer jobsSystems Administrator jobsStaff Security Engineer jobsInformation System Security Officer (ISSO) jobsSenior Product Security Engineer jobsPrincipal Security Engineer jobsThreat Intelligence Analyst jobsCloud Security Architect jobsInformation Systems Security Engineer jobs
Encryption jobsGDPR jobsPowerShell jobsDevSecOps jobsEDR jobsSaaS jobsIDS jobsSplunk jobsSDLC jobsIPS jobsRMF jobsTop Secret jobsSQL jobsIntrusion detection jobsBash jobsThreat detection jobsCompTIA jobsActive Directory jobsITIL jobsOWASP jobsDoDD 8570 jobsBanking jobsDocker jobsCRISC jobsFinance jobs
UNIX jobsTCP/IP jobsGIAC jobsClearance Required jobsCISO jobsTerraform jobsIndustrial jobsIT infrastructure jobsHIPAA jobsSANS jobsOSCP jobsJavaScript jobsVPN jobsSOC 2 jobsCCSP jobsMITRE ATT&CK jobsSOAR jobsSOX jobsData Analytics jobsJira jobsPolygraph jobsDNS jobsNIST 800-53 jobsSecurity strategy jobsMachine Learning jobs