Your browser does not support javascript! Please enable it, otherwise web will not work for you.

App Sec Manager @ IIFL Finance

Home > IT & Information Security - Other

 App Sec Manager

Job Description

Job Responsibilities:

  • Monitor and track application security posture based on agreed Key Goal Indicators (KGIs) and Key Performance Indicators (KPIs).
  • Conduct detailed IT and security risk assessments for business applications, including Web Apps, Mobile Apps, APIs, Thick Clients, and application integrations.
  • Perform application risk assessments according to company guidelines and industry best practices.
  • Conduct threat modeling, application architecture reviews, and source code analysis.
  • Collaborate with application development and business teams to enforce secure coding practices.
  • Utilize secure code review tools such as SonarQube, Checkmarx, Fortify, etc.
  • Act as an interface between development and VAPT teams, assisting in the closure of identified vulnerabilities.
  • Investigate security incidents related to business applications, driving corrective and preventive actions.
  • Track security metrics based on agreed KPIs/KGIs, providing reports on the overall application security posture, risks, and compliance.
  • Monitor and report on the status of major security initiatives, application security performance, and risk treatment plans.
  • Document relevant SOPs to support and implement application security policies and processes.
  • Track exceptions and ensure all identified risks are managed within the organizations risk appetite.
  • Prepare dashboards related to application security and IT risk assessment.
  • Collaborate with stakeholders to obtain timely data, escalating deviations and violations as necessary.
  • Stay updated on the latest security trends and provide training on secure coding best practices.

Qualifications:

  • Bachelors degree from a recognized university with relevant professional certifications.

Work Experience & Knowledge:

  • 5+ years of experience in application security and risk assessment.
  • Strong knowledge of OWASP Top 10, including API, mobile, and application security.
  • In-depth understanding of the development process, including SSDLC and DevOps practices and tools.
  • Minimum 2 years of secure code review experience using tools like SonarQube, Checkmarx, Fortify, etc.
  • Expertise in .NET, Java, GraphQL, MSSQL, PL/SQL, Azure Cloud architecture, and API gateway.
  • Hands-on experience with application risk assessment, threat modeling, and VAPT (Web & Mobile).
  • Ability to effectively measure and present security metrics through dashboards and reports.
  • Knowledge of industry best practices and standards, including ISO 27000, PCI-DSS, ISO 31000, OWASP Top 10, and relevant regulatory guidelines.
  • Professional certifications like ISO 31000, CEH, and OSCP preferred.
  • Strong analytical, communication, and problem-solving skills.

Job Classification

Industry: IT Services & Consulting
Functional Area / Department: IT & Information Security,
Role Category: IT & Information Security - Other
Role: IT & Information Security - Other
Employement Type: Full time

Contact Details:

Company: IIFL Finance
Location(s): Mumbai

+ View Contactajax loader


Keyskills:   OWASP Application Security Manager Cloud Security Vapt

 Fraud Alert to job seekers!

₹ 10-18 Lacs P.A

Similar positions

Specialist - CyberSecurity

  • MNC
  • 5 - 7 years
  • Bengaluru
  • 6 hours ago
₹ 12-15 Lacs P.A.

AI and Digital Apps Specialist

  • Brigade Group
  • 7 - 10 years
  • Bengaluru
  • 23 hours ago
₹ Not Disclosed

Application Deployment Engineer ( SCCM )

  • Mphasis
  • 5 - 8 years
  • Bengaluru
  • 4 days ago
₹ -12 Lacs P.A.

Senior Information Security Risk Consultant

  • Optum
  • 4 - 8 years
  • Noida, Gurugram
  • 6 days ago
₹ Not Disclosed

IIFL Finance

IIFL Holdings Limited (NSE: IIFL, BSE: IIFL) is the apex holding company of the entire IIFL Group, promoted by first generation entrepreneurs. Formerly known as India Infoline Limited, IIFL offers a gamut of services including financing, wealth and asset management, broking, financial product distri...