-
View all jobs
Skills:
OWASP Top Ten, Penetration Testing, Web Application Firewalls, Secure Software Development Lifecycle (SDLC), Cross-Site Scripting (XSS) Prevention, SQL Injection Mitigation, API Security Code Review Security Configuration, Web Application Security,
Greetings from Netsach - A Cyber Security Company.
We are looking for Web Application Security with 3 yrs of relevant experience and mandatory skills set are Web Application Security, Security Code review, API security, Underlying infrastructure security, Integration Security, Database Security, Secure Configuration Review.
Job Title: Web Application Security
Exp: 3+ - 5yrs
Job Location: Bangalore
Job Type: Full-time
Interested candidates please share your resume at [email protected] and netsachglobal.com
Job Description
Desirable Or Essential
Description of Knowledge / Skill etc.
Good understanding of Microservice based architecture (Technical)
Good hands-on experience solutioning technology architectures that involve perimeter protection, core protection and end-point protection/detection & API /Micro services Security
Experience working in a DevOps environment with knowledge of Continuous Integration, Containers, DAST/SAST tools and building Evil Stories (Technical)
The Analyst / Engineer should be able to understand how different systems work and what security controls are implemented in such integrations.
The Analyst / Engineer should be capable in understanding the hardening standards, creating one if not available, and perform the testing against the hardening standards.
The Analyst / Engineer should be capable of assessing security flaws in underlying infrastructure and the connected components.
The Analyst / Engineer should be capable of assessing the security flaws in the Transport Layer.
The Analyst / Engineer has the skill to follow design principles and applies design patterns to enforce maintainable and reusable patterns, in the form of code or otherwise
The Analyst / Engineer can understand and interpret potential issues found in source or compiled code
The Analyst / Engineer has automation skills/capability in the form of scripting or similar
The Analyst / Engineer can attack application and infrastructure assets, interpret threats, and suggest mitigating measures
Ability to interpret Security Requirements mandated by oversight functions and ensure comprehensive coverage of those requirements, via documentation, within high level design and/or during agile ceremonies, via Evil Stories
Desirable
The Analyst / Engineer can propose options for solutions to the security requirements / patterns that provide a balance of security, user experience & performance
Desirable
The Analyst / Engineer has the skill to discuss and present solutions to other architecture, security, development, and leadership teams.
Desirable
The Analyst / Engineer can interpret and understand vulnerability assessment reports and calculate inherent and/or residual risks based on the assessment of such reports
Desirable
Ability to articulate and be a persuasive leader who can serve as an effective member of the senior management team.
Good negotiation skills will be desirable
Desirable
Must have good judgment skills to decide on an exception approval
Desirable
Ability to enforce improvements when necessary, using Influence rather than Policing measures
Desirable
Superior written and verbal communication skills to effectively communicate security threats and recommendations to technical or non-technical stakeholders
Desirable
Knowledge of application of Agile methodologies/principles such as Scrum or Kanban
Desirable
Emily Jha
[email protected]
Netsach - A Cyber Security Company
www.netsachglobal.com
+91 8050023824
OWASP Top Ten, Penetration Testing, Web Application Firewalls, Secure Software Development Lifecycle (SDLC), Cross-Site Scripting (XSS) Prevention, SQL Injection Mitigation, API Security Code Review Security Configuration, Web Application Security,
Greetings from Netsach - A Cyber Security Company.
We are looking for Web Application Security with 3 yrs of relevant experience and mandatory skills set are Web Application Security, Security Code review, API security, Underlying infrastructure security, Integration Security, Database Security, Secure Configuration Review.
Job Title: Web Application Security
Exp: 3+ - 5yrs
Job Location: Bangalore
Job Type: Full-time
Interested candidates please share your resume at [email protected] and netsachglobal.com
Job Description
- Job Overview
- Job Purpose
- Encourage Shift Left Mindset - Proactively embed security requirements, by influencing implementation of security & privacy patterns from the start of the development cycle
- Implement via Influence - Influence stakeholders such as Product Owners, Solution Architects, Developers, Testers, Engineers & others to include security patterns into features, epics and stories in order to build secure, innovative & superior digital products for customers and employees
- Assessments Perform security assessment and perform gap analysis to provide appropriate remediations to the teams for implementing the fixes.
- Tools and Technologies Burp Suite, Postman, Tenable Nessus, Checkmarx SAST, GitHub and good knowledge about monolithic and microservice architecture and pipeline driven security.
- Technical Requirements
- Web Application Security Owasp top 10 , CVSS etc
- Security Code Review manual code review in Git etc
- API Security Review Open shift, container review etc.
- Database Security Requirements to enhance security on Database
- Web Server Security Requirements to enhance security on the web server
- Configuration Review has performed different configuration reviews and should have found good misconfigurations in the system.
- Integration review How the application connects with different systems, performed security review on those integrations.
- Transport Layer Security How communication channels are secured and understanding of the Transport layer security mechanisms and controls.
- Ability to collaborate with multiple stakeholders and manage their expectations from a security perspective
- Holistic thinking; must balance security and functionality using practical demonstrable examples. Must also contribute to and implement good architecture principles to lower technical debt
- Assertive personality; should be able to hold her/his own in a project board or work group setting
- Superlative written and verbal communication skills; should be able to explain technical observations in an easy-to-understand manner
- Ability to work under pressure and meet tough/challenging deadlines
- Influencer- must be able to convince various stakeholders (internal IT Teams, C-Level execs, Risk & Audit) of why a certain observation is a concern or not
- Strong understanding of Risk Management Framework and security controls implementation from an implementer standpoint
- Has strong decision making, planning and time management skills.
- Can work independently.
- Has a positive and constructive attitude.
- Person Specifications
Desirable Or Essential
Description of Knowledge / Skill etc.
- Education
- General
- Professional
- General Information Security:OSCP, CEH, CISM/CISA or similar
- General Cloud Security: CCSK /CCSP or similar
- Specific Cloud Security: Azure Security or similar
- Network Security: CCNA, CCNP, CCIE, Certified Kubernetes Security Specialist
- Experiences
- Industry
- Regional
- Functional
- Knowledge & Skills
- Technical
- Functional
- Managerial
Good understanding of Microservice based architecture (Technical)
Good hands-on experience solutioning technology architectures that involve perimeter protection, core protection and end-point protection/detection & API /Micro services Security
Experience working in a DevOps environment with knowledge of Continuous Integration, Containers, DAST/SAST tools and building Evil Stories (Technical)
The Analyst / Engineer should be able to understand how different systems work and what security controls are implemented in such integrations.
The Analyst / Engineer should be capable in understanding the hardening standards, creating one if not available, and perform the testing against the hardening standards.
The Analyst / Engineer should be capable of assessing security flaws in underlying infrastructure and the connected components.
The Analyst / Engineer should be capable of assessing the security flaws in the Transport Layer.
The Analyst / Engineer has the skill to follow design principles and applies design patterns to enforce maintainable and reusable patterns, in the form of code or otherwise
The Analyst / Engineer can understand and interpret potential issues found in source or compiled code
The Analyst / Engineer has automation skills/capability in the form of scripting or similar
The Analyst / Engineer can attack application and infrastructure assets, interpret threats, and suggest mitigating measures
Ability to interpret Security Requirements mandated by oversight functions and ensure comprehensive coverage of those requirements, via documentation, within high level design and/or during agile ceremonies, via Evil Stories
Desirable
The Analyst / Engineer can propose options for solutions to the security requirements / patterns that provide a balance of security, user experience & performance
Desirable
The Analyst / Engineer has the skill to discuss and present solutions to other architecture, security, development, and leadership teams.
Desirable
The Analyst / Engineer can interpret and understand vulnerability assessment reports and calculate inherent and/or residual risks based on the assessment of such reports
Desirable
Ability to articulate and be a persuasive leader who can serve as an effective member of the senior management team.
Good negotiation skills will be desirable
Desirable
Must have good judgment skills to decide on an exception approval
Desirable
Ability to enforce improvements when necessary, using Influence rather than Policing measures
Desirable
Superior written and verbal communication skills to effectively communicate security threats and recommendations to technical or non-technical stakeholders
Desirable
Knowledge of application of Agile methodologies/principles such as Scrum or Kanban
Desirable
- Behavioral Competencies
- Thinking Related
- People Related
- Self Related
- Influencer/Security Evangelist for the Team/Squad
- Positive & Constructive Attitude
- Autonomous worker / Decision Maker
- Good listener
- Patient & Calm during stressful situations
- High energy individual / Motivator
- Win-Win Attitude
- Hacker/Defense-In-Depth mindset
- Analytical thinking
- Team Player/Interpersonal Skills
- Eye for detail
- Persistent & Persuasive
- Organized / Structured
- Deadline oriented
- Competent and committed
- Peoples Person; understands stakeholder management
- Empathetic
- Passionate about architecting smart solutions
- Innovator/Out of the box thinker
- Collaborative Leadership style
- Confident Presenter
Emily Jha
[email protected]
Netsach - A Cyber Security Company
www.netsachglobal.com
+91 8050023824
Key Skills
Ranked by relevance
cyber security
cloud security
cloud
sql
vulnerability assessment
continuous integration
penetration testing
design patterns
kubernetes
burp suite
firewalls
postman
devops
server
nessus
owasp
scrum
ccna
ccie
ccnp
ccsp
git
ceh
c
Related Jobs
3 roles aligned with this opportunity
View Job Details
Related
Mobile Application Developer (Android & IOS)
2025-05-14
Full-time
Director
India
IT Services
Information Technology
View Job Details
Related
Mobile Application Developer (Android & IOS)
2025-05-07
Full-time
Director
India
IT Services
Information Technology
View Job Details
Related
Mobile Application Developer (Android & IOS)
2025-04-23
Full-time
Director
India
IT Services
Information Technology
Login to Apply
- Posted
- Feb 20, 2025
- Type
- Full-time
- Level
- Mid-Senior
- Location
- Bengaluru
- Company
- NETSACH GLOBAL
Industries
IT Services
IT Consulting
Categories
Information Technology
Related Jobs
3 roles aligned with this opportunity
View Job Details
Related
Mobile Application Developer (Android & IOS)
2025-05-14
Full-time
Director
India
IT Services
Information Technology
View Job Details
Related
Mobile Application Developer (Android & IOS)
2025-05-07
Full-time
Director
India
IT Services
Information Technology
View Job Details
Related
Mobile Application Developer (Android & IOS)
2025-04-23
Full-time
Director
India
IT Services
Information Technology