Source description
About the role
Role & Responsibilities : - Lead Application Security and Product Security initiatives across the Software Development Lifecycle (SDLC).- Perform Threat Modeling (STRIDE, PASTA, Microsoft Threat Modeling Tool) to identify and mitigate security risks.- Conduct Security Architecture, Design Reviews, and Secure Code Reviews for enterprise applications and cloud-native products.- Implement and drive Secure SDLC (SSDLC) practices across development teams.- Integrate security into CI/CD pipelines using DevSecOps methodologies.- Perform SAST, DAST, SCA, vulnerability assessments, and penetration testing while ensuring timely remediation.- Design and implement security controls for Azure/AWS cloud environments, containers (Docker/Kubernetes), and APIs.- Collaborate with Engineering, DevOps, QA, Product Management, and Security teams to embed Security by Design principles.- Define security standards aligned with OWASP Top 10, NIST, ISO 27001, CWE, and CIS Benchmarks.- Mentor development teams on secure coding practices and conduct security awareness sessions.- Support security audits, compliance initiatives, and customer security assessments.- Stay updated with emerging threats, vulnerabilities, and industry best practices.Preferred Candidate Profile : - 15+ years of experience in Application Security or Product Security.- Strong expertise in Secure SDLC (SSDLC) and Threat Modeling (STRIDE, PASTA, Attack Trees).- Hands-on experience in Security Architecture, Secure Design Reviews, and Secure Code Reviews.- Strong knowledge of Cloud Security (Azure and/or AWS), including identity, networking, storage, and compute security.- Experience with SAST, DAST, SCA tools such as Fortify, Checkmarx, Veracode, Coverity, SonarQube, Black Duck, Snyk, or AppScan.- Good understanding of DevSecOps, CI/CD pipelines, GitHub Actions, Azure DevOps, Jenkins, GitLab CI, or similar platforms.- Experience securing Web, Mobile, APIs, Thick Client, and Cloud-Native Applications.- Hands-on knowledge of Docker, Kubernetes, and container security.- Strong understanding of OWASP Top 10, CWE, NIST, ISO 27001, and secure coding practices.- Experience in vulnerability management, penetration testing, and remediation.- Excellent communication and stakeholder management skills with the ability to work across global engineering teams.- Certifications such as CISSP, CSSLP, CEH, OSCP, CISM, Azure Security Engineer (AZ-500), or AWS Security Specialty are preferred. (ref:hirist.tech) Role & Responsibilities : - Lead Application Security and Product Security initiatives across the Software Development Lifecycle (SDLC).- Perform Threat Modeling (STRIDE, PASTA, Microsoft Threat Modeling Tool) to identify and mitigate security risks.- Conduct Security Architecture, Design Reviews, and Secure Code Reviews for enterprise applications and cloud-native products.- Implement and drive Secure SDLC (SSDLC) practices across development teams.- Integrate security into CI/CD pipelines using DevSecOps methodologies.- Perform SAST, DAST, SCA, vulnerability assessments, and penetration testing while ensuring timely remediation.- Design and implement security controls for Azure/AWS cloud environments, containers (Docker/Kubernetes), and APIs.- Collaborate with Engineering, DevOps, QA, Product Management, and Security teams to embed Security by Design principles.- Define security standards aligned with OWASP Top 10, NIST, ISO 27001, CWE, and CIS Benchmarks.- Mentor development teams on secure coding practices and conduct security awareness sessions.- Support security audits, compliance initiatives, and customer security assessments.- Stay updated with emerging threats, vulnerabilities, and industry best practices.Preferred Candidate Profile : - 15+ years of experience in Application Security or Product Security.- Strong expertise in Secure SDLC (SSDLC) and Threat Modeling (STRIDE, PASTA, Attack Trees).- Hands-on experience in Security Architecture, Secure Design Reviews, and Secure Code Reviews.- Strong knowledge of Cloud Security (Azure and/or AWS), including identity, networking, storage, and compute security.- Experience with SAST, DAST, SCA tools such as Fortify, Checkmarx, Veracode, Coverity, SonarQube, Black Duck, Snyk, or AppScan.- Good understanding of DevSecOps, CI/CD pipelines, GitHub Actions, Azure DevOps, Jenkins, GitLab CI, or similar platforms.- Experience securing Web, Mobile, APIs, Thick Client, and Cloud-Native Applications.- Hands-on knowledge of Docker, Kubernetes, and container security.- Strong understanding of OWASP Top 10, CWE, NIST, ISO 27001, and secure coding practices.- Experience in vulnerability management, penetration testing, and remediation.- Excellent communication and stakeholder management skills with the ability to work across global engineering teams.- Certifications such as CISSP, CSSLP, CEH, OSCP, CISM, Azure Security Engineer (AZ-500), or AWS Security Specialty are preferred. (ref:hirist.tech)
More at Sunovaa Tech Pvt. Ltd.