Source description
About the role
Role Overview: The Lead Security Analyst at Morningstar will be responsible for assisting in supporting the application security automation program. This role involves integrating static and dynamic security analysis tools into the continuous integration processes, aiding in security remediation activities, ensuring timely resolution of vulnerabilities, and providing support to development and technical personnel when necessary. This position is based in the Mumbai location. Key Responsibilities: - Create, manage, and maintain Jenkins continuous integration jobs to facilitate application security automation - Administer common static and dynamic security assessment tools - Verify automated application security findings resulting from static and dynamic assessments - Collaborate with internal business units to communicate risks and ensure prompt resolution of open vulnerabilities - Collect and analyze application security metrics - Offer security remediation advice and training to technical personnel - Assist in documenting secure coding guidelines and conducting training programs for internal development personnel - Provide software security support and remediation guidance to development personnel Qualifications Required: - Bachelor's degree and a minimum of 7 years' experience in development or software security/penetration testing role - Enjoy breaking code, solving puzzles, and diagnosing problems - Strong communication skills and a solid understanding of software development and application security fundamentals - Interest in staying updated with the latest security trends, conducting code/architecture reviews, and penetration test activities - Experience with common static and dynamic analysis tools such as Semgrep, Brightsec, WAF, etc. - Proficiency in security best practices in Java, JavaScript, .NET, PHP, and Ruby programming languages - Familiarity with common authentication models like SAML, OAuth, OpenID, etc. is preferred - Background in software development and application security is preferred Morningstar is an equal opportunity employer and offers a hybrid work environment that encourages in-person collaboration on a weekly basis. The company values being together regularly and provides various benefits to enhance flexibility as per changing needs. Tools and resources are available for meaningful engagement with global colleagues regardless of location. Role Overview: The Lead Security Analyst at Morningstar will be responsible for assisting in supporting the application security automation program. This role involves integrating static and dynamic security analysis tools into the continuous integration processes, aiding in security remediation activities, ensuring timely resolution of vulnerabilities, and providing support to development and technical personnel when necessary. This position is based in the Mumbai location. Key Responsibilities: - Create, manage, and maintain Jenkins continuous integration jobs to facilitate application security automation - Administer common static and dynamic security assessment tools - Verify automated application security findings resulting from static and dynamic assessments - Collaborate with internal business units to communicate risks and ensure prompt resolution of open vulnerabilities - Collect and analyze application security metrics - Offer security remediation advice and training to technical personnel - Assist in documenting secure coding guidelines and conducting training programs for internal development personnel - Provide software security support and remediation guidance to development personnel Qualifications Required: - Bachelor's degree and a minimum of 7 years' experience in development or software security/penetration testing role - Enjoy breaking code, solving puzzles, and diagnosing problems - Strong communication skills and a solid understanding of software development and application security fundamentals - Interest in staying updated with the latest security trends, conducting code/architecture reviews, and penetration test activities - Experience with common static and dynamic analysis tools such as Semgrep, Brightsec, WAF, etc. - Proficiency in security best practices in Java, JavaScript, .NET, PHP, and Ruby programming languages - Familiarity with common authentication models like SAML, OAuth, OpenID, etc. is preferred - Background in software development and application security is preferred Morningstar is an equal opportunity employer and offers a hybrid work environment that encourages in-person collaboration on a weekly basis. The company values being together regularly and provides various benefits to enhance flexibility as per changing needs. Tools and resources are available for meaningful engagement with global colleagues regardless of location.
More at Morningstar