Source description
About the role
Job Description
Skill Set
-
application security & testing
-
Total Experience :
-
7.00 to 10.00 Years
-
No of Openings :
-
1
-
Job Post Date :
-
03/06/2026
-
Job Expiry Date :
-
31/08/2026
-
Domain :
-
IT
-
Location :
-
NAVI MUMBAI [India]
-
Job Reference No :
-
4080891
-
Recommend to friend
-
Job Summary
-
Application Security Lead
-
Educational Qualification: BE/BTech/MCA Experience: 6 to 9 years
-
Certifications such as CISSP, CISA, CISM, or ISO 27001 Lead Auditor preferred.
-
Key Responsibilities:
-
• Prior experience in a regulatory compliance in BFSI is preferable.
-
• Develop and manage the GRC framework to ensure regulatory compliance.
-
• Ensure adherence to standards like ISO 27001, PCI DSS, SOC 2, and NIST.
-
• Establish and enforce security policies for data protection and secure development.
-
• Collaborate with development teams to integrate security into the SDLC.
-
• Conduct application security assessments, code reviews, and vulnerability scans.
-
• Manage audits for application security controls and vulnerability management.
-
• Conduct risk assessments, maintain a risk register, and track remediation efforts.
-
• Deliver training on secure coding practices and compliance awareness.
-
• Document and report compliance activities, risk findings, and audit results.
-
• Strong knowledge on automated scanning using HP Fortify, Burp suite or similar tools.
-
• Suggest mitigation for identified vulnerabilities.
-
• Deep knowledge of web Application and mobile applications security testing.
-
• Collaboration on product conceptualization for security by design.
-
• Knowledge on web Appsec, ethical hacking, DFRA, CSR.
-
• Experience in understanding false positive from the Source code scans.
-
• Lead at least one CSR (Compressive security review)
-
• Knowledge static application security testing (SAST), dynamic application security testing (DAST), and open source security (OSS)
-
• Strong understanding of OWASP top 10.
-
• Experience in WAF logs analysis.
-
• Rapid decision making to prevent delayed releases due to security issues.
-
• To coordinate with various stakeholders for completion of Audit points observed by internal and external auditor.
-
• Make sure all CERTS in, RBI and various security advisories are checked and recommended action taken on the respective platforms in the application.
-
• Working knowledge of web and mobile application security.
-
• Extensive experience in Vulnerability Assessment and Penetration testing, Web Application security
-
• Knowledge on conducting Security Audits. • Good knowledge on Threat modeling, cryptography, and common application
-
Recommend to Friend
-
Please enter your Name
-
Please enter your email
-
Please enter your Friends Name
-
Please enter your friend's emailId Please enter valid email id , e.g. abc@gmail.com
More at Tech Mahindra