Solutions Architect I Application Security

Year    Hyderabad, Telangana - Secunderabad, Telangana, India

Job Description


SUMMARY The Application Security Architect will work closely with both engineering (development) teams and the Information Security group to make sure that RealPage applications are developed with security in mind. Deep awareness of the OWASP Top 10 project and practices for preventing vulnerabilities when developing applications in any tech stack is a key success factor. This person will help to ensure Static Application Security Testing (SAST), DAST and SCA occurs during the development lifecycle and that reported vulnerabilities are properly remediated. This person will also help train developers on how to remediate the vulnerabilities and what those vulnerabilities are when needed, Implement OWASP Application Security Verification Standards (ASVS). Additionally, this person role-models for a small team (1-5 others) of persons with similar responsibilities. Excellent communication skills and a good familiarity with DevOps pipelines are key success factors for this role. PRIMARY RESPONSIBILITIES Shift-Left security in Software Development Life Cycle (SDLC) for various applications. Provide guidelines, tooling, best practices and implement for: Provide guidance and coaching to teams regarding security remediation efforts Provide guidance to teams on how to properly integrate SAST, DAST, SCA scans into their pipelines Work with teams to ensure dependency scans are also part of their development process and pipelines. Help the team wherever needed to implement them. Provide ongoing improvements and awareness training on new application threats and remediation techniques Provide guidanceon OpenID Connect (OIDC)and OAuth2 and other identity-related best practices and practical approaches for client implementation Help engineering teams plan long term remediation solutions when deep changes are required for remediation activities Collaborate with the Information Security (InfoSec) team on prioritizing both applications and vulnerabilities based on risk Provide guidance to teams on proper storage and retrieval of application secrets. Ability to work in the US Central Time Zone and coordinate with the geographically dispersed teams. REQUIRED KNOWLEDGE/SKILLS /ABILITIES Bachelor\'s degree required equivalent experience equal to 4 years software development may be considered in lieu of degree Minimum 6 years\' experience developing commercial SaaS solutions Deep familiarity with the OWASP Top 10 and other security concerns for web applications Familiarity with OWASP Application Security Verification Standards (ASVS) Familiarity with SAST, DAST, SCA Scans Familiarity and deep understanding of OWASP ASVS. Advanced understanding of OpenID Connect (OIDC) and OAuth2 and recommended practices for web and mobile applications Understand how to interpret and assess CVEs (Common Vulnerability and Exposures) as found by scanning tools Understanding of SAST, DAST tools and dependency scanning tools Experience working/integrating with secret management systems such as HashiCorp Vault or AWS Secrets Manager Advanced knowledge of front-end and back-end web application development in at least one technology stack (.NET, Java, PHP, Ruby/Rails, Angular, Node.js, etc.) Track record of staying current with trends, techniques, tools, and processes that drive improvement of security posture of applications Strong documentation skills Excellent verbal and written communication skills, with proven technical writing abilities Team-oriented thinking with demonstrated ability to produce high-quality work as part of a fast-paced, dynamic team #LI-SK2

foundit

Beware of fraud agents! do not pay money to get a job

MNCJobsIndia.com will not be responsible for any payment made to a third-party. All Terms of Use are applicable.


Related Jobs

Job Detail

  • Job Id
    JD3165508
  • Industry
    Not mentioned
  • Total Positions
    1
  • Job Type:
    Full Time
  • Salary:
    Not mentioned
  • Employment Status
    Permanent
  • Job Location
    Hyderabad, Telangana - Secunderabad, Telangana, India
  • Education
    Not mentioned
  • Experience
    Year