Lead Security Analyst

9 Minutes ago • 7 Years + • Cyber Security

Job Summary

Job Description

The Information Security department protects Morningstar information. The Lead Security Analyst will support the application security automation program, integrating static and dynamic security analysis tools into continuous integration processes. This role involves assisting with security remediation, ensuring timely vulnerability resolution, and supporting development teams. The analyst will also verify automated findings, communicate risks, analyze metrics, and provide security advice and training to technical personnel.
Must have:
  • A bachelor’s degree and 7+ years’ experience in a development or software security / penetration testing role
  • Strong understanding of software development and application security fundamentals
  • Experience with common static and dynamic analysis tools (Semgrep, Brightsec, WAF etc.)
  • Strong understanding of security best practices in Java, JavaScript, .NET, PHP and Ruby programming languages
  • Ability to create, manage and maintain Jenkins continuous integration jobs for application security automation
  • Ability to administer common static and dynamic security assessment tools
  • Capability to verify automated application security findings and communicate risks to business units
  • Proficiency in collecting and analyzing application security metrics
  • Aptitude for providing security remediation advice and training to technical personnel
Good to have:
  • Strong understanding of common authentication models (SAML, OAuth, OpenID, etc.) is preferred
  • A software development and application security background is preferred
Perks:
  • Hybrid work environment (remote and in-person collaboration)
  • Opportunity to work remotely
  • Flexible benefits to enhance flexibility as needs change
  • Tools and resources to engage meaningfully with global colleagues

Job Details

The Area: The Information Security department is responsible for setting enterprise security policies and standards that are designed to protect the confidentiality, integrity and availability of Morningstar information. The security team offers guidance and technical expertise in areas like application security, policies and procedures, disaster recovery and compliance/regulation. We analyze emerging security threats and conduct risk and vulnerability assessments to ensure that our information remains secure.

The Role: The Lead Security Analyst will assist in supporting Morningstar’s application security automation program. This individual will help integrate static and dynamic security analysis tools into Morningstar’s continuous integration processes, assist with security remediation activities, ensure that vulnerabilities are being remediated in a timely manner and support development and technical personnel as required. This position is based in our Mumbai location.

Responsibilities

+ Create, manage and maintain Jenkins continuous integration jobs to support application security automation

+ Administer common static and dynamic security assessment tools

+ Verify automated application security findings that result from automated static and dynamic assessments

+ Work directly with internal business units to communicate risks and to help ensure open vulnerabilities are resolved in a timely manner

+ Collect and analyze application security metrics

+ Provide security remediation advice and training to technical personnel

+ Assist with documenting secure coding guidelines and running training programs to assist internal development personnel

+ Provide software security support and remediation guidance to development personnel

Requirements

+ A bachelor’s degree and 7+ years’ experience in a development or software security / penetration testing role

+ We’re looking for someone who enjoys breaking code, solving puzzles, and diagnosing problems

+ Excellent communication skills and a strong understanding of software development and application security fundamentals

+ Candidates should be interested in keeping up with the latest security trends, as well as enjoy performing code / architecture reviews and penetration test activities

+ Experience with common static and dynamic analysis tools (Semgrep, Brightsec, WAF etc.)

+ A strong understanding of security best practices in Java, JavaScript, .NET, PHP and Ruby programming languages

+ Strong understanding of common authentication models (SAML, OAuth, OpenID, etc.) is preferred

+ A software development and application security background is preferred

Morningstar is an equal opportunity employer.

Morningstar’s hybrid work environment gives you the opportunity to work remotely and collaborate in-person each week. We’ve found that we’re at our best when we’re purposely together on a regular basis, at least three days each week. A range of other benefits are also available to enhance flexibility as needs change. No matter where you are, you’ll have tools and resources to engage meaningfully with your global colleagues.

I10_MstarIndiaPvtLtd Morningstar India Private Ltd. (Delhi) Legal Entity

Similar Jobs

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

Similar Skill Jobs

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

Jobs in Mumbai, Maharashtra, India

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

Cyber Security Jobs

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

About The Company

Mumbai, Maharashtra, India (Hybrid)

Shenzhen, Guangdong Province, China (On-Site)

Denmark (Remote)

Mumbai, Maharashtra, India (Hybrid)

Toronto, Ontario, Canada (Hybrid)

Shenzhen, Guangdong Province, China (Hybrid)

Toronto, Ontario, Canada (Hybrid)

Toronto, Ontario, Canada (Hybrid)

Sydney, New South Wales, Australia (On-Site)

Mumbai, Maharashtra, India (Hybrid)

View All Jobs

Get notified when new jobs are added by Morning Star

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug
Contact Us
hello@outscal.com
Made in INDIA 💛💙