DL
Application Security
Diverse Lynx India
Location not stated
2 months ago
- AWS Cloud
- AWS
- Azure
- GCP
- SAST
- DAST
- Jira
- Confluence
- Risk Management
- Snyk
- Prisma
- Threat Modeling
2 months ago
Experience: 6-8 Years
Role Descriptions:
Cloud AWS/Azure/GCP Vulnerability Identification: Identify security weaknesses and vulnerabilities in source code and running applications using methods such as SAST| DAST| and SCA.
Security Requirement Validation: Determine if solutions meet security policies| procedures| and specific group security requirements.
Review approved/baselined Group Security requirements and security control requirements for the initiative
Confirm with stakeholders how each applicable control has been met including control status| applicability and evidence availability
Collect and record evidence design artefacts| screenshots| walkthrough outputs| compliance statements| test results| configuration extracts| BAU process confirmations
Liaise with stakeholders project teams| Group Security representatives| architects| engineering teams| service owners and support teams for clarification| supporting information and sign-off
Validate evidence sufficiency confirm compliance or identify gaps requiring further action
Assess testing evidence across functional| static/conformance and dynamic/security testing types
Maintain traceability between controls| evidence| defects| risks| dispensations and outcomes in Jira/ALM/Confluence
Raise and track non-conformances| evidence gaps and security risks before go-live
Support the TPOR cross-referencing all requirements to evidence or defects/risks
Risk Management: Ensure risks associated with non-conformance are highlighted to stakeholders prior to project go-live and verify that appropriate mitigation plans exist for high-severity risks.
Testing Execution: Perform dynamic testing (validation) for functional behavior and static verification (manual or automated reviews) of documents like design specifications.
Reporting: Produce detailed Test Plans and Test Outcome Reports that cross-reference all security requirements to documentation or identified defects.
Tooling & Maintenance: Assist with the maintenance of ALM/Jira to record results and defects| and utilize tools such as Snyk| Prisma| and Sonar Qube.Key Activities in Scope
Testing security requirements related to access| authorization| authentication| audit & logging| and session management.
Collating evidence of the use of secure development methods and practices.
Validating that functional tests proposed by Project Test Managers meet group security requirements.
Participating in code reviews and supporting threat modeling at the application level.
Application Security · Diverse Lynx India