H&R Block

Senior Security Engineer

H&R Block

Thiruvananthapuram, Kerala, India · Full Time

Be the first to apply

Experience
5+ yrs
Salary
—
Openings
1
Posted
5 days ago
Work mode
In office
Education
Bachelor's degree
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

Role Overview

The Senior Application Security Engineer will ensure the security of organizational products throughout their lifecycle, providing expertise and consultation to various stakeholders on security matters.

Key Responsibilities

  • Conduct threat modeling, application architecture analysis, and vulnerability evaluations to identify and address security risks in product design and development.
  • Deploy security tools and automation to advance the Application Security team’s capabilities and embed security best practices throughout the Software Development Lifecycle (SDLC), which includes code reviews, penetration testing, and static/dynamic analysis, aligning with standards such as AICPA SOC2, HIPAA, PCI DSS, SOX, ISO 27001, and NIST CSF.
  • Collaborate with product and engineering teams to architect, develop, and enforce security controls directly within software products, integrating security solutions and tooling into CI/CD pipelines, including SAST, DAST, software composition analysis, and infrastructure-as-code scanning.
  • Engage in product roadmap planning and work cross-functionally to establish mitigation strategies, mentor Product, Engineering, and IT teams on security best practices, and deliver security training and awareness programs.
  • Maintain documentation of security processes and controls, generate security risk and mitigation reports for executives and regulators, and perform audits and code reviews especially on critical application updates.

Candidate Profile

  • A minimum of five years' professional experience in application security roles.
  • Bachelor’s degree in Computer Science, Cybersecurity, or a closely related discipline.
  • Proven experience leading architectural improvements or complex cross-team initiatives addressing security vulnerabilities.
  • Proficient understanding of threat modeling methodologies, including MITRE ATT&CK, STRIDE, and PASTA.
  • Familiarity with cloud services such as Amazon AWS and Microsoft Azure.
  • Ability to secure web applications, and knowledge of orchestration tools like Ansible and Terraform.
  • Hands-on experience with security frameworks including OWASP Top 10, and familiarity with SAST/DAST tools and CI/CD pipeline integration.
  • Programming fluency in Python, React, and Django Rest Framework.
  • Skilled in manual source code review and embedding security measures into production codebases.
  • Experienced in deploying security tools integrated within the CI/CD environment.
  • Proven track record of advancing secure software development lifecycle programs targeting comprehensive vulnerability elimination.
  • Excellent communication and interpersonal skills facilitating effective teamwork and independent work.
  • Strong organizational capabilities and time management skills.

Desirable Qualifications

  • Professional certifications such as CISSP, CSSLP, CEH, or equivalents.
  • Knowledge or experience relating to IoT, embedded systems, or mobile app security.
  • Awareness of regulatory and compliance standards, including AICPA SOC2, NIST CSF, GDPR, and HIPAA.

Equal Opportunity and Inclusion

H&R Block values equal employment opportunity and strictly prohibits discrimination based on race, color, religion, ancestry, age, gender (including pregnancy and related conditions), sexual orientation, gender identity or expression, military service, origin, disabilities, genetic information, citizenship, or any legally protected status.

Level

Senior

Minimum education

Bachelor's Degree

Tools & software

How they work

Communication Teamwork & Collaboration Time Management Independence Interpersonal Skills
🤖
Online · instant AI help
Broxer