Application Security Engineer II

1 day ago


Hyderabad City Taluka, Pakistan FANATICS INC Full time

RESPONSIBILITIES:

  • Establish security best processes and practices for our mobile, on-premises and cloud-based platforms.
  • Provide expert knowledge and guidance to the product teams about security vulnerabilities and remediation controls.
  • Support and consult with product and development teams in the area of application security, including threat modeling and Application Security reviews.
  • Implement, continuously develop, and maintain secure Software Security Development Lifecycle processes and software maturity model.
  • Perform threat modeling, secure design, and source code review.
  • Conduct security assessments, security testing and validation of vulnerability scan results.
  • Assist teams in reproducing, triaging, and addressing application security vulnerabilities.
  • Incorporate security tools/tasks to automate product development and deployment.
  • Develop, implement, and automate defensive controls, creating and tuning tools and rules to detect and address malicious activity.Responsible for integration of security controls into SDLC.
  • Establish supply chain security process and ensure 3rd party software meet the standards.
  • Facilitate injection, integration, and compliance for Static Application Security Testing (SAST), Container Security Scanning & Open-Source Security Analysis during development phase.
  • Facilitate injection, integration, and compliance for Dynamic Application Security Testing (DAST)
  • Contribute to triaging, addressing security issues and tracking remediation.
  • Own and manage Secure SDLC tooling.
  • Develop and customize security tools used by security teams and developers.
  • Work closely with development teams to build security directly into their SDLCs.
  • Provide remediation guidance to programmers and management.
  • Support bug bounty program
  • Support the preparation of security releases
  • Mentor and train development teams on secure coding standards and techniques. Develop Secure Coding Program.
  • Constantly innovate at the pace of the adversary using latest techniques.

EDUCATIONAL REQUIREMENTS:

  • Bachelor's degree in computer science, Information Systems, or equivalent combination of education and experience
  • Certifications in the field of Information Security (at least one of the following: CISSP, CEH, GIAC CPEN, OSCP, OSWE, CWAPT, GWAPT, GWEB)

EXPERIENCE REQUIRED:

  • A minimum of 3 to 5 years of experience.

GENERAL KNOWLEDGE, SKILLS & ABILITIES:

  • In-depth knowledge of web and mobile security vulnerabilities, attack vectors and mitigation techniques
  • Experience with multiple programming languages (Java, JavaScript, Go, Python, Ruby, Objective-C, C#, PHP) with hands on level coding experience with at least one scripting and one objected oriented programming language.
  • Fluent with security testing with SAST, SCA, DAST, IAST, Fuzz and penetration testing tools
  • Understanding of application security standards such as OWASP ASVS/Top 10 and CWE 25
  • Ability to discover and patch SQLi, XSS, CSRF, SSRF, authentication and authorization flaws, and other web-based security vulnerabilities (OWASP Top 10 and beyond).
  • Knowledge of common authentication technologies including OAuth, SAML, CAs, OTP/TOTP.
  • Knowledge of DevSecOps to maintain security in CI/CD pipeline.
  • Solid experience with security tools like Semgrep, CheckMarx, VeraCode, BurpSuite, Snyk, Nessus
  • Familiar with tools like Git, Jenkins, CircleCI, Maven, Ant, Gradle, Nexus, SonarQube, Artifactory, Chef, Splunk
  • Experience writing custom rules for static analysis tools.
  • Experience with API Security, IaC, Containerization, RASP, IAST
  • Experience with micro services, container deployment and service orchestration
  • Strong knowledge of cryptography, API security, and secret management
  • Ability to clearly and effectively communicate concerns and issues to the management and engineers.
  • Experience with Cloud (AWS, Azure, GCP) Security
  • Experience writing tools to automate tasks and integrate systems using scripting languages like Go, Python and REST APIs.
  • Experience in delivering and educating development groups in Secure Coding
  • Expertise with common vulnerabilities and attack vectors.
  • Experience integrating security tools into developer pipelines.
  • DevOps experience managing deployment and configuration.

General skills include:

  • Strong critical thinking and analytical skills
  • Ability to approach problem solving in a constructive and collaborative way that does not require absolute security.
  • The ability to communicate complicated technical issues and risks to programmers, network engineers and managers.
  • Strong leadership, project, and team-building skills
  • Exceptional communication skills with diverse audiences; the ability to be an application security subject matter expert who can explain relevant topics to general audiences.
#J-18808-Ljbffr
  • Software Engineer II

    3 weeks ago


    Hyderabad City Taluka, Pakistan JP Morgan Chase Full time

    We have an exciting and rewarding opportunity for you to take your software engineering career to the next level.As a Software Engineer II at JPMorgan Chase within the Consumer Banking-Trust & Security, you serve as a seasoned member of an agile team to design and deliver trusted market-leading technology products in a secure, stable, and scalable way. You...


  • Hyderabad City Taluka, Pakistan JP Morgan Chase Full time

    You're ready to gain the skills and experience needed to grow within your role and advance your career — and we have the perfect software engineering opportunity for you.As a Software Engineer II at JPMorgan Chase within the Corporate Technology , you are part of an agile team that works to enhance, design, and deliver the software components of the firm's...


  • Hyderabad City Taluka, Pakistan Backbase Full time

    The job in shortNo day at Backbase is the same, and even more so for our security engineers. We all know that security and banking need to go hand in hand and with hackers and tech evolving by the day, you'll need to stay on your toes and ahead of the game.Your core responsibility is to guide and support the developer teams in delivering and deploying secure...


  • Hyderabad City Taluka, Pakistan JP Morgan Chase Full time

    Organization DescriptionOur Consumer & Community Banking division serves our Chase customers through a range of financial services, including personal banking, credit cards, mortgages, auto financing, investment advice, small business loans, and payment processing. We're proud to lead the U.S. in credit card sales and deposit growth and have the most-used...

  • Software Engineer II

    4 weeks ago


    Hyderabad City Taluka, Pakistan JP Morgan Chase Full time

    You're ready to gain the skills and experience needed to grow within your role and advance your career — and we have the perfect software engineering opportunity for you.As a Software Engineer II at JPMorgan Chase within the Workforce Technology Team, specifically as a part of the Employee Platforms Team, you will be integral to our agile team,...


  • Hyderabad City Taluka, Pakistan Backbase Full time

    Principal AI Application Security EngineerThe job in short: keep millions of users and their banking data safe and secure.No day at Backbase is the same, and even more so for our security engineers. We all know that security and banking need to go hand in hand, and with hackers and tech evolving daily, you'll need to stay on your toes and ahead of the...

  • Software Engineer II

    2 weeks ago


    Hyderabad City Taluka, Pakistan FANATICS INC Full time

    PurposeAs a Software Engineer II, you will contribute to the development and integration of Fanatics' Warehouse Execution System (WES) and Warehouse Control System (WCS). You will collaborate with senior engineers to build, test, and deploy software that drives warehouse automation, material flow, and fulfillment orchestration.Key ResponsibilitiesAssist in...

  • Engr II Network

    2 weeks ago


    Hyderabad City Taluka, Pakistan FANATICS INC Full time

    Position Summary:We are seeking an experienced Network Infrastructure Delivery Engineer II to support the implementation and maintenance of critical network infrastructure. This role will be responsible for deploying and managing network systems, supporting upgrades, troubleshooting, and ensuring optimal performance and security. The ideal candidate will...

  • Software Engineer II

    2 weeks ago


    Hyderabad City Taluka, Pakistan Warner Bros. Discovery, Inc. Full time

    Welcome to Warner Bros. Discovery… the stuff dreams are made of.Who We Are…When we say, "the stuff dreams are made of," we're not just referring to the world of wizards, dragons and superheroes, or even to the wonders of Planet Earth. Behind WBD's vast portfolio of iconic content and beloved brands, are the storytellers bringing our characters to life,...


  • Hyderabad City Taluka, Pakistan beBeeSecurity Full time 600,000 - 800,000

    About Our TeamWe're a group of pioneers in banking tech, always looking for ways to innovate and improve. We believe that security and banking go hand in hand, and we need someone to help us stay ahead of the game.As a Senior Application Security Engineer, you'll be part of our team of security experts who work together to ensure that our software is secure...