Senior Security Engineer
Thiruvananthapuram, Kerala, India · Full Time
Be the first to apply
- Experience
- 5+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 5 days ago
- Work mode
- In office
- Education
- Bachelor's degree
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Role Overview
The Senior Application Security Engineer will ensure the security of organizational products throughout their lifecycle, providing expertise and consultation to various stakeholders on security matters.
Key Responsibilities
- Conduct threat modeling, application architecture analysis, and vulnerability evaluations to identify and address security risks in product design and development.
- Deploy security tools and automation to advance the Application Security team’s capabilities and embed security best practices throughout the Software Development Lifecycle (SDLC), which includes code reviews, penetration testing, and static/dynamic analysis, aligning with standards such as AICPA SOC2, HIPAA, PCI DSS, SOX, ISO 27001, and NIST CSF.
- Collaborate with product and engineering teams to architect, develop, and enforce security controls directly within software products, integrating security solutions and tooling into CI/CD pipelines, including SAST, DAST, software composition analysis, and infrastructure-as-code scanning.
- Engage in product roadmap planning and work cross-functionally to establish mitigation strategies, mentor Product, Engineering, and IT teams on security best practices, and deliver security training and awareness programs.
- Maintain documentation of security processes and controls, generate security risk and mitigation reports for executives and regulators, and perform audits and code reviews especially on critical application updates.
Candidate Profile
- A minimum of five years' professional experience in application security roles.
- Bachelor’s degree in Computer Science, Cybersecurity, or a closely related discipline.
- Proven experience leading architectural improvements or complex cross-team initiatives addressing security vulnerabilities.
- Proficient understanding of threat modeling methodologies, including MITRE ATT&CK, STRIDE, and PASTA.
- Familiarity with cloud services such as Amazon AWS and Microsoft Azure.
- Ability to secure web applications, and knowledge of orchestration tools like Ansible and Terraform.
- Hands-on experience with security frameworks including OWASP Top 10, and familiarity with SAST/DAST tools and CI/CD pipeline integration.
- Programming fluency in Python, React, and Django Rest Framework.
- Skilled in manual source code review and embedding security measures into production codebases.
- Experienced in deploying security tools integrated within the CI/CD environment.
- Proven track record of advancing secure software development lifecycle programs targeting comprehensive vulnerability elimination.
- Excellent communication and interpersonal skills facilitating effective teamwork and independent work.
- Strong organizational capabilities and time management skills.
Desirable Qualifications
- Professional certifications such as CISSP, CSSLP, CEH, or equivalents.
- Knowledge or experience relating to IoT, embedded systems, or mobile app security.
- Awareness of regulatory and compliance standards, including AICPA SOC2, NIST CSF, GDPR, and HIPAA.
Equal Opportunity and Inclusion
H&R Block values equal employment opportunity and strictly prohibits discrimination based on race, color, religion, ancestry, age, gender (including pregnancy and related conditions), sexual orientation, gender identity or expression, military service, origin, disabilities, genetic information, citizenship, or any legally protected status.
Level
Senior
Minimum education
Bachelor's Degree