Source description
About the role
Role Overview: As a Security Team Leader, your role is to lead a high-performing, multidisciplinary security team and drive the future of secure software delivery within the organization. Your focus will be on achieving measurable security outcomes through automation and innovation. Key Responsibilities: - Review and interpret various application classifications and architectures, including web apps, APIs, infrastructure, server-side, and mainframe systems. - Demonstrate expertise in data encryption, including data in transit and data at rest encryption, TLS, middleware message queues, secure file transfers, and database encryption. - Understand access control concepts, automated provisioning, reconciliation, and privileged access management tools like SailPoint and CyberArk. - Familiarity with authentication best practices including SSO, SAML, 2FA/MFA, Arcot, RSA, etc. - Clear understanding of application security testing processes such as DAST, SAST, SCA, penetration testing, and VAPT. - Knowledge of payment-specific applications, encryption of payment flows, mutual authentication, and end-to-end encryption. - Work closely with application/asset owners and technical teams to implement security controls and conduct compliance reviews. - Produce concise findings reports and discuss results with relevant stakeholders. - Demonstrate team management ability, prepare management-level reports, and interact with higher management. - Mentor and onboard new team members through knowledge transfer sessions. - Provide consultation and recommendations on application security controls. - Strong knowledge of application security frameworks, standards, and regulatory requirements. - Understanding of OWASP top 10, SAST/DAST/SCA, API security, secure coding practices, threat modeling, vulnerability management, and cryptography techniques. - Good communication skills and IT audit background. - Knowledge of IT security and access control mechanisms. Qualifications Required: - Any technical certification (CEH/ISO27001/CISM/CISA/CISSP) will be a value addition. - Bachelor's degree or equivalent. Additional Company Details: Location: Bengaluru/Mumbai. Role Overview: As a Security Team Leader, your role is to lead a high-performing, multidisciplinary security team and drive the future of secure software delivery within the organization. Your focus will be on achieving measurable security outcomes through automation and innovation. Key Responsibilities: - Review and interpret various application classifications and architectures, including web apps, APIs, infrastructure, server-side, and mainframe systems. - Demonstrate expertise in data encryption, including data in transit and data at rest encryption, TLS, middleware message queues, secure file transfers, and database encryption. - Understand access control concepts, automated provisioning, reconciliation, and privileged access management tools like SailPoint and CyberArk. - Familiarity with authentication best practices including SSO, SAML, 2FA/MFA, Arcot, RSA, etc. - Clear understanding of application security testing processes such as DAST, SAST, SCA, penetration testing, and VAPT. - Knowledge of payment-specific applications, encryption of payment flows, mutual authentication, and end-to-end encryption. - Work closely with application/asset owners and technical teams to implement security controls and conduct compliance reviews. - Produce concise findings reports and discuss results with relevant stakeholders. - Demonstrate team management ability, prepare management-level reports, and interact with higher management. - Mentor and onboard new team members through knowledge transfer sessions. - Provide consultation and recommendations on application security controls. - Strong knowledge of application security frameworks, standards, and regulatory requirements. - Understanding of OWASP top 10, SAST/DAST/SCA, API security, secure coding practices, threat modeling, vulnerability management, and cryptography techniques. - Good communication skills and IT audit background. - Knowledge of IT security and access control mechanisms. Qualifications Required: - Any technical certification (CEH/ISO27001/CISM/CISA/CISSP) will be a value addition. - Bachelor's degree or equivalent. Additional Company Details: Location: Bengaluru/Mumbai.
More at BNP Paribas