Job Description:
Define and execute the Application Security strategy aligned with enterprise cybersecurity objectives.
Establish, maintain and continuously improve Secure Software Development Lifecycle processes.
Develop application security policies, standards, control baselines, patterns and guidance.
Lead security reviews for new applications, platforms, modernization programs and digital initiatives.
Drive security-by-design and privacy-by-design principles across software development programs.
API Security Program
Develop and implement enterprise API security standards, architecture patterns and minimum control
requirements.
Assess REST, SOAP, GraphQL and microservices based APIs for security risks.
Identify and mitigate OWASP API Security risks, including Broken Object Level Authorization, authentication
and authorization weaknesses, excessive data exposure, rate limiting gaps and API abuse.
Collaborate with API gateway, integration, identity and platform teams to implement preventive and detective
controls.
Security Architecture & Design Review
Conduct security architecture reviews, design assessments and threat modeling exercises.
Review cloud native, containerized, mobile, web and OT connected applications.
Validate controls for authentication, authorization, OAuth 2.0, OpenID Connect, SAML, JWT, PKI, certificate
management, encryption, secrets management, logging and monitoring.
DevSecOps Integration || MS
Embed security testing and policy gates into CI/CD pipelines.
Manage and optimize SAST, DAST, IAST, Software Composition Analysis, container scanning, secrets
scanning, and Infrastructure-as-Code security testing.
Partner with engineering teams to triage, prioritize and remediate vulnerabilities.
Vulnerability Management & Testing
Lead application and API vulnerability assessments and coordinate penetration testing and red team
activities.