Senior Application Security Engineer
JumioIndia2w ago
Job description
About the role
In this pivotal role, you will be responsible for constructing secure cloud infrastructures and providing essential security engineering support to internal development teams. Your expertise will play a crucial part in safeguarding the organization from cyber threats by embedding security measures throughout the software development lifecycle, ensuring that security is a fundamental aspect of our processes.
Key facts
What you'll do
- Collaborate closely with infrastructure and engineering teams to identify and remediate security vulnerabilities within cloud environments and development workflows.
- Integrate security measures starting from the initial threat modeling phase and continuing through to the decommissioning of systems.
- Conduct thorough manual penetration tests on APIs and web applications to identify potential security weaknesses.
- Execute comprehensive source code audits and reviews, particularly during significant application updates, to ensure security compliance.
- Provide guidance to engineering teams on how to effectively address vulnerabilities and prioritize risks based on their potential impact.
- Oversee the management of security risk mitigation strategies across both internal and external teams, ensuring a cohesive approach to security.
- Implement security services utilizing infrastructure as code methodologies, promoting the adoption of security as code practices across the organization.
- Carry out regular configuration reviews and security assessments of cloud environments to maintain a robust security posture.
- Develop bespoke security automation tools and spearhead various security initiatives to enhance overall security measures.
- Scale DevSecOps methodologies and seamlessly integrate security tools into existing development workflows to foster a culture of security awareness.
Requirements
- A minimum of 10 years of experience in security engineering, with a strong emphasis on cloud and application security.
- Expertise in Linux environments and familiarity with cloud platforms such as AWS and GCP, including their networking and security frameworks.
- In-depth knowledge of AWS services like EC2, ECS, Lambda, and RDS, as well as the Well-Architected Framework principles.
- Proven experience with containerization technologies, specifically Docker and Kubernetes, for deploying secure applications.
- A solid background in implementing secure infrastructure as code practices to enhance security measures.
- Practical experience in conducting penetration testing for web applications and APIs, identifying vulnerabilities effectively.
- A thorough understanding of the Common Weakness Enumeration (CWE) 25 and the OWASP Top 10 security risks.
- Familiarity with security testing tools such as SAST, DAST, IAST, and SCA, and their application in security assessments.
- Experience in threat modeling to identify and mitigate potential security risks proactively.
- Excellent communication skills, with the ability to articulate security risks and recommendations to technical teams effectively.
Nice to have
- Experience in mobile application penetration testing, expanding your skill set in security assessments.
- Proficiency in Python or other scripting languages to develop security tools and automate processes.
- Familiarity with the application of artificial intelligence and large language models (LLMs) to streamline security workflows.
- Knowledge of continuous integration and continuous deployment (CI/CD) tools such as Jenkins, GitHub Actions, or AWS DevOps for integrating security into development pipelines.
- A Bachelor's or Master's degree in Computer Science or a related field to support your technical expertise.
- Relevant security certifications such as OSCP, CREST, OSWE, CEPT, CMWAPT, GPEN, PentTest+, or AWS Security/Associate level certifications to validate your skills.
Skills & tools
- Proficient in Linux, AWS, GCP, Docker, Kubernetes, and Python.
- Experienced with security testing tools including SAST, DAST, IAST, SCA, and CI/CD tools.
Practical notes
- Jumio is committed to upholding values such as Integrity, Diversity, Empowerment, Accountability, and Leading Innovation in all aspects of its operations.
- The company is proud to be an equal opportunity employer, fostering an inclusive environment for all employees.
- Any personal information shared during the application process will be managed in accordance with the Jumio Applicant Privacy Notice. For inquiries related to data privacy, please reach out to privacy@jumio.com.