Loading...

Job Description

  • Skill Set : Application Security Concepts
  • Total Experience : 10.00 to 15.00 Years
  • No of Openings : 1
  • Job Post Date : 05/05/2026
  • Job Expiry Date : 31/07/2026
  • Domain : IT
  • Location : NOIDA [India]
  • Job Reference No : 4067510

Job Summary

Responsibilities Include

  • Lead crossâ€`functional, enterpriseâ€`wide initiatives and define strategic direction for modern Software Development Lifecycle (SDLC) security practices.
  • Conduct security design reviews and advanced threat modeling for new and existing missionâ€`critical services across the platform.
  • Define and enforce secure architecture standards, frameworks, and resilient security patterns across application, cloudâ€`native, and infrastructure layers.
  • Evaluate, implement, operate, and govern core application security tools and services (DAST, SAST, SCA, WAF, secrets management, container security, etc.).
  • Identify emerging security threats, assess their relevance, and proactively deploy centralized mitigations.
  • Maintain deep awareness of evolving security threats and operational best practices.
  • Lead security assessments, penetration testing, and bug bounty programs, translating findings into systemic riskâ€`reduction strategies.
  • Ensure application security practices comply with PCI DSS requirements.
  • Act as a technical leader during security incident response activities.

Required Qualifications

  • Strong technical foundation (Computer Science/Engineering degree or equivalent experience) with the ability to translate technical vulnerabilities into business risk.
  • 8+ years of handsâ€`on technical security experience in a leading software company, including threat modeling, security architecture, cryptography, mobile security, and cloud technologies.
  • Expert knowledge of application and infrastructure vulnerabilities and mitigations (OWASP Top 10, CWE, etc.).
  • Deep expertise in the eâ€`commerce transaction lifecycle and PCI DSS compliance in highâ€`volume environments.
  • Proven success implementing Secure Development Lifecycle (SDL) processes, tools, and automation within DevOps/DevSecOps environments.
  • Experience with largeâ€`scale web applications and microservices, including API security, access management, authentication, authorization, encryption, and data protection.
  • Proficiency in multiple programming languages and frameworks (e.g., Python, C#, .NET, JavaScript, Node.js, Java).
  • Excellent problemâ€`solving, communication, and collaboration skills with the ability to influence technical and executive stakeholders.

Bonus Qualifications

  • Experience in highâ€`transaction or eâ€`commerce environments with strong PCI DSS expertise.
  • Handsâ€`on experience with Cloudflare, AWS (VPC, EC2), Docker, and containerized workloads.
  • Experience driving application security training, security champion programs, and awareness initiatives.
  • Active participation in the security community (research, open source, publications) and demonstrated ability to attract top talent.
  • Relevant security certifications such as OSCP, CISSP, or CSSLP.

Recommend to Friend