HamburgerMenu
hirist

Job Description

Job Title : Cloud DevOps engineer

Location : Bangalore (WFO)

Skill Required : Digital : Cloud DevOps~Vulnerability Assessment and Penetration Testing~Cyber Security-ASM - Application Security~Digital : Cyber Security - ASM - Mobile Application Security

Experience Range in Required Skills : 6-8 years(Rel 5+ yrs)

Job Description :

- Conducts security risk assessments of applications with respect to design and implementation of system and application code


- Develop and manage security governance processes and procedures for the threat modeling program and application security design develops programs


- Assist in the development of threat modeling governance documentation Works with information security leadership to develop strategies and plans to enforce threat modeling and address identified control gaps


- Develops reports for management concerning residual risk and non-compliance


- Monitor and track compliance with application owners to ensure implementation of security controls as planned


- Review issued security controls with application owners to ensure identified requirements are implemented Validate implementation of security controls against outputs of scanning tools to enable auditability and verifiability


- Assist application owners in filing appropriate security standard exceptions as identified through threat modeling


- Develop, Maintain, update and enhance secure design patterns and secure coding standards.


- Develop, Maintain, update and enhance threat libraries

Essential Skills :

- Must have 6 to 9 years of information security experience

- Experience with threat modeling frameworks, attack vectors and vulnerability analysis CAPEC, ATTCK, Stride Experience with application security controls (Web, API, Mobile, AI)

- Experience with common information security management and application frameworks NIST 800-53, CSF, OWASP ASVS Experience with Application Security design and DevSecOps

- Good to have-AI,ML DevOps Cloud Security Certification ( not Mandatory but expect to attain in 6 months of project) - CISSP, OSCP , CISM

- Strong communication skills

info-icon

Did you find something suspicious?