Senior Specialist I - Product Security & Privacy

1 Month ago • 7-12 Years

Job Summary

Job Description

This role focuses on ensuring security and privacy are integrated into the product development lifecycle. The Senior Specialist will work with architects and engineering teams to review designs and specifications for security considerations. Responsibilities include performing security testing, analyzing applications for risks, and creating test cases. They will also guide development teams in fixing vulnerabilities and may involve experience with security automation and various testing tools and methodologies. This role ensures a secure software development lifecycle.
Must have:
  • Experience in Application Security Testing (7-12 years).
  • Understanding of common code review methods and standards.
  • Experience with static analysis tools.
  • Knowledge of standard Secure Development Life Cycle practices.
  • Experience with Kubernetes, Amazon Elastic Kubernetes Service (Amazon EKS) security testing is a plus.
  • Experience in tools like Burp Suite Pro, HP Webinspect/IBM Appscan/Acunetix and open source tools like burp, OWASP ZAP, CSRF tester etc, Burp Suite
  • Experience with Open Web Application Security Project (OWASP) standards, Open Source Security Testing Methodology Manual (OSSTMM) methodologies
  • Knowledge in cloud & Big data application security testing
Good to have:
  • Experience in Security automation framework development or scripting language is a plus.
  • Sufficient understanding or exposure to testing application on below technology will be helpful: REST API, Web Application, Kubernetes, Amazon Elastic Kubernetes Service (Amazon EKS), Encryption, Data storage for SQL, Oracle etc., AWS
  • Good to have CEH certification
  • Good to have source code review experience
  • Good to know Python coding and Security Automation

Job Details

Job Title

Senior Specialist I - Product Security & Privacy

Job Description

This role, embedded in to product development life cycle will ensure- Secured by Design, Privacy by Design and Threat modelling aspects are carried out as part of Secured Software Development Life Cycle. 

Individuals in this role will engage with Architects, Technical leads and R&D Engineering & Development teams to ensure the security and privacy considerations are considered well in advance during the product development cycle. They will review the High-level design, Low-level design and System specification documentation for security consideration and sign them off before the development happens.

They also collaborate with architects to arrive at appropriate security solutions balancing the security risks and the business impact.

This role, embedded in to product development life cycle will ensure- Secured by Design, Privacy by Design and Threat modelling aspects are carried out as part of Secured Software Development Life Cycle. 

Individuals in this role will engage with Architects, Technical leads and R&D Engineering & Development teams to ensure the security and privacy considerations are considered well in advance during the product development cycle. They will review the High-level design, Low-level design and System specification documentation for security consideration and sign them off before the development happens.

They also collaborate with architects to arrive at appropriate security solutions balancing the security risks and the business impact.

Specific job responsibilities include:

  • This is individual contributor role. As part of the larger Security and Privacy team, the Application Security Engineer.
  • Perform comprehensive Dynamic Application security Testing (DAST)
  • Understand and analyses the applications from security point of view.
  • Understand the application security risks and Threat modelling of applications.
  • Good to have source code review experience.
  • Create and execute the corresponding security test cases to verify that the mitigations are properly implemented in the application.
  • Able to guide and support development teams to fix the security vulnerabilities in the code.
  • Good to know Python coding and Security Automation .

Technical skills and experience:

  • Preferred Experience:

  • 7 - 12 years of work experience in Application Security Testing
  • Understanding and familiarity with common code review methods and standards.
  • Experience with static analysis tools (e.g., Git hub advance security, IBM Appscan Source, HP Fortify, Synopsys BlackDuck)
  • Experience in Security automation framework development or scripting language is a plus.
  • Knowledge of standard Secure Development Life Cycle practices.
  • Experience with Kubernetes, Amazon Elastic Kubernetes Service (Amazon EKS) security testing is a plus.
  • Research and pilot new services / technologies to support secure software development
  • Experience in tools like Burp Suite Pro, HP Webinspect/IBM Appscan/Acunetix and open source tools like burp, OWASP ZAP, CSRF tester etc, Burp Suite
  • Experience with Open Web Application Security Project (OWASP) standards, Open Source Security Testing Methodology Manual (OSSTMM) methodologies
  • Knowledge in cloud & Big data application security testing
  • Sufficient understanding or exposure to testing application on below technology will be helpful
    REST API
    Web Application
  • Kubernetes, Amazon Elastic Kubernetes Service (Amazon EKS)
    Encryption
    Data storage for SQL, Oracle etc.
    AWS

Education

• Bachelor  degree in technical stream required ( BE, ME, MS, MCA)

• Degree or concentration in Computer Science, Information Systems, Information Security or similar preferred.

Good to have CEH certification

#LI-PHILIN
#LI-Onsite
#LI-EU

Similar Jobs

zeta - Engineering Manager - Cloud Security (DevSecOps)

zeta

Bengaluru, Karnataka, India (On-Site)
7 Months ago
Barracuda Networks Inc - Software Development Engineer in Test

Barracuda Networks Inc

Koramangala, Karnataka, India (Hybrid)
5 Months ago
Zscaler - Staff Application Security Engineer

Zscaler

Bengaluru, Karnataka, India (Hybrid)
2 Weeks ago
PhonePe - Product Security Engineer (App Security)

PhonePe

Bengaluru, Karnataka, India (On-Site)
2 Weeks ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

PwC - Senior Associate DevOps

PwC

Hyderabad, Telangana, India (On-Site)
2 Days ago
Clear Watery Analytics - Application Security Engineer

Clear Watery Analytics

Noida, Uttar Pradesh, India (On-Site)
3 Weeks ago
Barracuda Networks Inc - Software Development Engineer in Test

Barracuda Networks Inc

Koramangala, Karnataka, India (Hybrid)
5 Months ago
Philips - Specialist I - Product Security and Privacy

Philips

Bengaluru, Karnataka, India (On-Site)
2 Days ago
Glean - Application Security Engineer

Glean

Palo Alto, California, United States (Hybrid)
2 Weeks ago
PhonePe - Product Security Engineer (App Security)

PhonePe

Bengaluru, Karnataka, India (On-Site)
2 Weeks ago
Universal Music - Application Security Engineer

Universal Music

Santa Monica, California, United States (Remote)
1 Month ago
zeta - Engineering Manager - Cloud Security (DevSecOps)

zeta

Bengaluru, Karnataka, India (On-Site)
7 Months ago
Loyalty Juggernaut - Product Security Engineer

Loyalty Juggernaut

Hyderabad, Telangana, India (On-Site)
1 Week ago

Get notifed when new similar jobs are uploaded

Jobs in Bengaluru, Karnataka, India

PwC - Senior Manager | D365 SCM

PwC

Kolkata, West Bengal, India (On-Site)
7 Months ago
Capgemini - Senior Software Engineer

Capgemini

Mumbai, Maharashtra, India (On-Site)
2 Days ago
Framestore - CREATURE FX TD

Framestore

Mumbai, Maharashtra, India (On-Site)
1 Year ago
Lakshya Digital - Manager - HR operations

Lakshya Digital

Gurugram, Haryana, India (On-Site)
2 Months ago
Sprinkler - Senior Implementation Consultant

Sprinkler

Gurugram, Haryana, India (On-Site)
1 Month ago
Capgemini - Chatbot

Capgemini

Chennai, Tamil Nadu, India (On-Site)
3 Weeks ago
NCR Voyix - Information Security Engineer III

NCR Voyix

Gurugram, Haryana, India (On-Site)
1 Week ago
Capgemini - Cyber Security Engineer

Capgemini

Noida, Uttar Pradesh, India (On-Site)
2 Weeks ago
Adyen - Engineering Manager (Team Lead) - Authentication & Tokenization

Adyen

Bengaluru, Karnataka, India (On-Site)
2 Weeks ago
Demandbase - Senior Software Engineer (Backend)

Demandbase

Hyderabad, Telangana, India (On-Site)
2 Weeks ago

Get notifed when new similar jobs are uploaded

Similar Category Jobs

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

About The Company

At Philips, we believe that every human matters. As a global health-tech leader, we focus on improving people’s health and wellbeing through meaningful innovation. The people who work here share our passion and are motivated to bring this purpose to life.For more than 130 years, we have been creating technologies and innovations that improve people's lives and support healthcare practitioners. Headquartered in the Netherlands and operating in more than 100 countries globally, we focus our advanced technology and deep clinical and consumer insights on Precision Diagnosis, Image Guided Therapy, Enterprise Informatics, Monitoring/ Connected Care, Sleep & Respiratory Care and Personal Health.Together, we deliver better care for more people because we believe that every human matters.

Varginha, State Of Minas Gerais, Brazil (On-Site)

Pune, Maharashtra, India (Hybrid)

Paris, Île-de-France, France (On-Site)

Haifa, Haifa District, Israel (On-Site)

Chennai, Tamil Nadu, India (On-Site)

Chennai, Tamil Nadu, India (On-Site)

View All Jobs

Get notified when new jobs are added by Philips

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug