VI
Security Consultant - Application Security
VARITE INDIA PRIVATE LIMITED
🇮🇳 India
On-site
11 months ago
- Stripe
- SQL
- AI
- SAST
- DAST
- DevSecOps
- Devops
- Threat Modeling
- CI/CD
- Vulnerability Management
- Penetration Testing
- Jira
- ServiceNow
- Risk Management
- OWASP
- NIST
- ISO 27001
- SonarQube
- Burp Suite
- GitHub
- Jenkins
- GitLab CI
- Azure DevOps
- GitHub Actions
- AWS
- Azure
- GCP
- IaC
- Terraform
- CloudFormation
- PCI DSS
- GDPR
- HIPAA
11 months ago
About The Client:
An American multinational technology corporation headquartered in Armonk, New York, it is present in over 175 countries. It specializes in computer hardware, middleware, and software and provides hosting and consulting services in areas ranging from mainframe computers to nanotechnology. As one of the world's oldest and largest technology companies, the Client has been responsible for several technological innovations, including the automated teller machine (ATM), dynamic random-access memory (DRAM), the floppy disk, the hard disk drive, the magnetic stripe card, the relational database, the SQL programming language, and the UPC barcode. The company has made inroads in advanced computer chips, quantum computing, artificial intelligence, and data infrastructure.
About The Job:
- This role demands a strong understanding of secure architecture, software security testing (SAST, DAST, SCA, PT), threat moClienting, and modern DevSecOps practices.
- You will work closely with developers, DevOps engineers, and product teams to ensure the security of our software ecosystem.
Application Security Program Ownership
- Perform Threat Modeling and architecture security reviews for new and existing applications.
- Conduct and guide secure code reviews, ensuring adherence to security best practices.
- Collaborate with development teams to embed security across the SDLC.
- Automate and integrate SAST, DAST, SCA tools into CI/CD pipelines.
- Define and implement security gates to enforce policies within DevOps workflows.
- Continuously evaluate and improve tooling and automation strategies.
- Perform or coordinate penetration testing and manage remediation with engineering teams.
- Track and manage vulnerabilities using tools such as Jira, ServiceNow, etc.
- Ensure alignment with security frameworks such as OWASP ASVS, NIST, ISO 27001, or CIS.
- Participate in risk assessments and mitigation strategies for applications and services.
- Conduct security training and awareness sessions for engineering teams.
- Partner with DevOps and SREs to maintain secure deployment environments.
- RTH - Y, Total Yrs of Exp - 3+ Yrs
- Relv Yrs of Exp - 3+ Yrs
- Bachelor’s or Master’s degree in Computer Science, Information Security, or related field.
- 5+ years of hands-on experience in application security and DevSecOps.
- Deep knowledge of SAST, DAST, SCA, and container security tools (e.g., Checkmarx, SonarQube, Veracode, Fortify, Burp Suite, GitHub Advanced Security, etc.).
- Strong understanding of secure software development practices, SDLC, and CI/CD pipelines (e.g., Jenkins, GitLab CI, Azure DevOps, GitHub Actions).
- Familiarity with cloud-native architectures (AWS, Azure, GCP) and infrastructure-as-code security (Terraform, CloudFormation, etc.).
- Expertise in threat modeling tools and methodologies (e.g., STRIDE, PASTA).
- Experience with manual and automated penetration testing techniques.
- Knowledge of security standards and regulations (e.g., OWASP Top 10, PCI DSS, GDPR, HIPAA).
- Bachelor’s or Master’s degree in Computer Science, Information Security, or related field.
- 8+ years of hands-on experience in application security and DevSecOps.
- Deep knowledge of SAST, DAST, SCA, and container security tools (e.g., Checkmarx, SonarQube, Veracode, Fortify, Burp Suite, GitHub Advanced Security, etc.).
- Strong understanding of secure software development practices, SDLC, and CI/CD pipelines (e.g., Jenkins, GitLab CI, Azure DevOps, GitHub Actions).
- Familiarity with cloud-native architectures (AWS, Azure, GCP) and infrastructure-as-code security (Terraform, CloudFormation, etc.).
- Expertise in threat modeling tools and methodologies (e.g., STRIDE, PASTA).
- Experience with manual and automated penetration testing techniques.
- Knowledge of security standards and regulations (e.g., OWASP Top 10, PCI DSS, GDPR, HIPAA).
How to Apply:Interested candidates are encouraged to respond/submit their updated resumes, and for additional job opportunities, please visit Jobs In India – VARITE.
Unlock Rewards: Refer Candidates and Earn.
If you're not available or interested in this opportunity, please pass this along to anyone in your network who might be a good fit and interested in our open positions. VARITE offers a Candidate Referral program, where you'll receive a one-time referral bonus based on the following scale if the referred candidate completes a three-month assignment with VARITE.
Experience Level Bonus Referral:
| 0-2 years | INR 5,000 |
| 2-6 years | INR 7,500 |
| 6+ years | INR 10,000 |
About VARITE: VARITE is a global staffing and IT consulting company providing technical consulting and team augmentation services to Fortune 500 Companies in USA, UK, CANADA and INDIA. VARITE is currently a primary and direct vendor to the leading corporations in the verticals of Networking, Cloud Infrastructure, Hardware and Software, Digital Marketing and Media Solutions, Clinical Diagnostics, Utilities, Gaming and Entertainment, and Financial Services.
Equal Opportunity Employer:
VARITE is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, marital status, veteran status, or disability status.
Security Consultant - Application Security · VARITE INDIA PRIVATE LIMITED