Risk Consulting - Protect Tech - Senior (IT Risk - Application Security)

Bengaluru, KA, IN, 560016

EY

Mit unseren vier integrierten Geschäftsbereichen — Wirtschaftsprüfung und prüfungsnahe Dienstleistungen, Steuerberatung, Unternehmensberatung und Strategy and Transactions — sowie unserem Branchenwissen unterstützen wir unsere Mandanten dabei,...

View all jobs at EY

Apply now Apply later

At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all. 

 

 

 

 

Risk Consulting - Protect Tech - Senior (IT Risk – Application Security)

 

Key responsibilities


The purpose of this role will be to supervise delivery, provide technical and project leadership to your team members, as well as build relationships with clients. While delivering quality client services and enabling high-performing teams, you will drive high-value work products within expected timeframes and budget. You will monitor progress, manage risks and ensure key stakeholders are kept informed about progress and expected outcomes. Additionally, you should have following skills added below.

 

  • Perform comprehensive security assessments and collaborate with developers to mitigate vulnerabilities.
  • Evaluate software architectures to detect potential threats, craft threat models to illustrate possible attack paths, and prioritize security measures.
  • Scrutinize developer-written code for security weaknesses, compliance with coding standards, and alignment with best practices, integrating security throughout the development process.
  • Execute a suite of security tests, including static (SAST), dynamic (DAST), and interactive (IAST) analyses, to discover and address application vulnerabilities.
  • In critical security incidents, you'll be instrumental in the investigation, containment, and resolution efforts, working alongside incident response teams.
  • Guide application onboarding and support developers through the review process, ensuring a smooth integration into our security framework.
  • Develop and refine roadmaps and priorities for our Assurance program, focusing on the security of tools and services.
  • Partner with engineering teams and tool owners to proactively embed the Assurance function earlier in the development cycle.
  •  Innovate and enhance the Application Risk Assessment program, ensuring continuous improvement.
  • Evaluate tools and technologies to identify gaps in data protection and compliance, ensuring adherence to regulatory standards.

 

To qualify for the role, you must have

  • A bachelor’s degree in information technology, Cybersecurity, or Business Management with at least 3 years of experience in product/technical program management, data analysis, or product development, or an equivalent combination of education and experience.
  • At least 3 years of work experience in technology administration/management, technical risk management, technical risk consulting, and/or software development/engineering.
  • Proficiency in coordinating complex process reviews, interpreting results, and clearly articulating findings.
  • Good to have at least one relevant industry certification, such as CISA, CISM, CISSP, CRISC, CCSK, ISO 27001, among others.
  • Prior experience working on an application or service development team is advantageous.
  • A self-starter who is motivated to work autonomously with minimal supervision.
  • Strong analytical skills with the capacity to think creatively, communicate recommendations, influence change, and introduce process and structure in a dynamic environment.
  • A comprehensive understanding of various technologies, including cloud computing, networking, cloud application design, development tools/processes, and common cloud-based application architectures.
  • Knowledge of data security concepts, such as Application Security Testing, Vulnerability Assessment, or Information Systems Audit.

 

EY | Building a better working world 


 
EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.  


 
Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.  


 
Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.  

Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  0  0  0

Tags: Application security CCSK CISA CISM CISSP Cloud Compliance CRISC DAST IAST Incident response ISO 27001 Risk assessment Risk management SAST Security assessment Strategy Vulnerabilities

Perks/benefits: Career development

Region: Asia/Pacific
Country: India

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.