Job Description:
The primary objectives of the ASAP Architect is to design, deliver and enhance various security services.
The services include technical security assessments of application and infrastructure. This is a hands-on role, requiring technical skills from hardware to the application layer, involving design reviews & risk assessments.
Conduct Application Security testing to assess the vulnerabilities.
Read and analyze global standards and policies (ex: GDPR, CCPA) and adjust internal requirements accordingly
Device methods to automate testing activities and streamline testing process.
Design and conduct penetration testing / vulnerability assessment for cloud Infrastructure.
Ensure infrastructure and application are secure.
Elaborate tests and deliver reports suitable for viewing by clients
Researching, evaluating and developing relevant Testing tools / methods
Key Responsibilities:
Perform application and infrastructure penetration tests
Review product / customer requirements, provide information security solutions and contribute towards S-SDLC.
Perform security reviews of application designs, covering all types of applications (web application, web services, mobile applications, etc.,)
Publish and perform the Security/Penetration tests and certify the release of product / applications
Work with developers, product development, and operations teams to develop Security testing strategy, ensuring proper execution.
Ability to track Security test execution, facilitate and drive the overall testing effort with limited test cycles.
Excellent communication skills for reporting to senior executive management on testing activities and issues.
Job Requirements:
Bachelor degree or higher, technical discipline preferred
Should have Strong knowledge in security / code scan tools like Checkmarx, AppScan, Burpsuite, Owasp ZAP, Fiddler, Nessus, Netsparker, Vega, Zap or related tools.
Expert proficiency in latest Infra technologies like dockerization, kubernetes, secure architectures and best practices with clear understanding of HTTP / Network protocol concepts & Client Server Architecture.
Strong understanding and hands on experience on application and infrastructure vulnerabilities, automated/manual testing, auditing and remediation techniques
Strong Understanding of OWASP, WASC 2.0 Threats classification
8 - 10 years of working experience in application / cloud infrastructure security testing.
Should have exposure to task / team management tools like JIRA or related tools.
Working knowledge of Security principles, techniques and technologies
Good understanding of network protocols, design and operations
Should be a good team player. Lead & Mentor juniors and ensure employee satisfaction.
Strong analytical skills and efficient problem solving
Decision-making, R&D of tools, cross-functional coordination to improve overall deliverables.
AWS Certified Security - Specialty / CEH / (ISC)2 CCSP / (ISC)2 CSSLP
Preferred Skills:
Application development background - example of languages include C, C#, C++, Java, J2EE, JS.
Keyskills: Vega c++ c appscan Fiddler ASAP Architect information security Zap J2EE test execution Netsparker nessus WASC java owasp zap OWASP Burpsuite penetration testing security services aws application security testing Checkmarx