Source description
About the role
SSDLC Sr. Engineer
Vertical
Cyber Security
Employee Type
Employee
Experience range (Years )
3 years - 5 years
Reporting Structure
Reports to the Platform Software Security Services – Lead/ Manager
Education
Bachelor’s Degree in Engineering/Master Degree in Engineering in CSE/CS/IT/IT Security or Cyber Security Specialization/B.Sc/M.Sc/MCA (IT/Computer) preferred
Experience/ Qualifications
Experience in the following process areas:
• Secure SDLC Methodologies for Waterfall/ Agile software development
• Should be well-versed with Security best practices like OWASP and NIST guidelines
• Ability to perform security review of microservices architecture, API Security
• Hands on experience on Source Code reviews - SAST solution
• Hands on experience on Dynamic Application Security Testing - DAST
• Hands on experience in Software Composition Analysis - SCA
• Hands on experience in performing Tech Stack Review
• Comfortable working in an environment that practices Agile development, engaging Product Owner and other stakeholders
• Good knowledge of Cloud platform/VMware
• Ability to identify vulnerabilities & threat actors in the application cycle and communicate effectively to the stake holders.
• Threat Modelling – PASTA, STRIDE etc (Good to Have)
Possesses ability to quickly understand the technical and functional aspects of the project to be able to communicate effectively with different stakeholders.
Excellent written and verbal communication skills in English, high integrity, strong work ethic and ability to empathize with the customer.
Ability to work effectively in a fast-paced, project-oriented environment
Ability to prioritize and execute tasks
Ability to handle sensitive and confidential information
Strong analytical and problem-solving skills
Responsibilities
-
- Perform security best practices review followed by Development team
-
- Perform SCA and report vulnerabilities and recommendations
-
- Perform Tech Stack review and report findings along with recommendations.
-
Perform code review (supporting SAST Tool) and remove false positives if any, and report valid security issues to development team
-
Perform DAST on the various applications and remove false positives if any, and report valid security issues to development team
-
Contribution to RFP process and assist in Implementing SSDLC Tools.
-
- Escalate issues and risks and proactively takes ownership for resolution
-
- Track milestones and deliverables and provide regular status reporting to respective stakeholders
-
Certifications
-
CSSLP/CISSP/SSCP or equivalent certification are desirable (Good to Have).
-
Application/API Security Threat Modelling/API Security product Implementations, Specialization or OWASP certifications or Agile Certifications are a plus
-
Employment Type
-
All positions are on fixed term contract on a full-time basis exclusively for ReBIT, initially for a period of five years, extendable by mutual consent
-
Location
-
Navi Mumbai (Mandatory)
-
Joining
-
Immediate Joiners preferred.
More at Reserve Bank Information Technology Pvt Ltd